Contact

Blog

Your data is in Europe. But who controls it?

author: Hans de Bal

6–8 minutes
Silhouettes of an audience looking at a glowing digital government icon, labelled Digital Government and Data Sovereignty.

In June 2025, a French senator asked a simple question during a hearing on public procurement. He wanted to know whether Microsoft could guarantee that French citizen data would never be handed over to US authorities without France’s approval. Microsoft France’s own legal director answered honestly: “No, I cannot guarantee it.”

It’s the kind of answer that travels. Within weeks, procurement teams and legal departments across Europe were quoting it back at each other. Storing your data in a European data centre doesn’t automatically put it under European control. If the company running that data centre is American, US law, specifically the US Cloud Act (which lets US authorities compel an American company to hand over data it holds, wherever in the world that data physically sits), can still reach in.

Why this suddenly matters

Until recently, “digital sovereignty” sat firmly in policy circles, a topic for people who write regulation rather than people who run a business. That’s changed fast. Tension between Europe and the US keeps escalating, sanctions have become a live possibility instead of a theoretical one, and it’s dawned on plenty of European organisations just how dependent they’ve become on a handful of American tech providers. Regulation is catching up too. The EU Data Act has been in force since September 2025, and it requires cloud providers to build in safeguards against exactly this kind of unauthorised access. Brussels has bigger plans still in the works, aimed at making sovereignty a real requirement for public sector and critical infrastructure work rather than a nice-to-have.


So this is no longer an abstract debate. It’s turning into a concrete question your organisation will be asked, whether by a regulator, an auditor, or a customer filling in a procurement form: who can actually get to our data, and under whose law?

Four questions worth asking about any system you rely on

Most people reduce digital sovereignty to one question, where does the data sit. It’s a real question, but it’s only one layer of it.

Start with the hardware. Whose is it, in whose building, and would it keep working if the connection back to a foreign parent company got cut? IT teams rarely check this one, because the servers are usually humming along fine right up until the day they aren’t. That’s infrastructure sovereignty. You get there through options like private cloud deployments, national partner cloud models where a local company operates the infrastructure under local law, and having a genuine, tested way to exit or restore your systems elsewhere if you ever needed to.

See how AMEXIO approaches this: our European Cloud, hosted entirely in France under European law.

The test that actually matters: would your systems keep running if the link back to a foreign head office got cut tomorrow, or would everything quietly grind to a halt?

Then there’s a more unsettling question. Who holds the encryption keys, and could your provider read your content even if it never should? That’s technology sovereignty, and it matters even when everything else checks out, because a provider that can read the data can still be compelled to hand it over. It comes down to proper key management, and in its strongest form, an approach called Double Key Encryption. Two separate keys unlock the data here, one held by the cloud provider, and one held only by your own organisation. Without your key, nobody reads the content, not even the provider itself. It’s one of the few controls that takes trust out of the equation entirely.

Who actually runs and administers the system day to day, and from which country? A system can be hosted in Belgium, with the people managing it reporting into a headquarters somewhere else entirely. This is operational sovereignty. Put access controls in place. Add approval workflows. Log who touches the system and when. Then “we trust our provider” stops being an assumption. You can actually check it.

And who can legally demand access to the data itself, and from where? That’s data sovereignty, the one everyone talks about first. You get there with clear residency commitments, meaning a contractual guarantee about where data is stored and processed, backed up by technical enforcement such as Microsoft’s EU Data Boundary that keeps it there in practice rather than only on paper.

Very few organisations have a clean answer across all four. That isn’t a reason to panic. It’s a reason to find out where you actually stand.

What the big cloud providers are doing about it

To be fair to the large providers, they haven’t ignored this. They’ve invested heavily in what they call sovereign cloud: European data boundaries, European oversight boards, local operational teams, and increasingly, the option to run workloads in a way that doesn’t depend on a live connection back to the US at all.

That’s real progress, worth acknowledging. But it doesn’t fully solve the problem. As long as the parent company is American, it remains subject to American law, and no amount of local infrastructure changes that basic fact. Think of it less as sovereignty solved, and more as sovereignty risk reduced. Useful, but not the same thing.

What you can do about it, starting now

None of this needs a five-year transformation programme. Pick your most sensitive systems and ask a simple question about each one: who operates it, and which country does that vendor answer to? Almost nobody has actually traced that chain before. The exercise itself tends to hand you a short, clear list of what to fix first.

Not every file deserves the same worry. A customer contract or an HR record carries real risk if it leaks or disappears. A meeting note usually doesn’t. Sort by what would actually hurt, and the priorities set themselves.

Before buying anything new, check what’s already sitting in your contract. The EU Data Boundary or confidential computing might already be part of your Microsoft 365 or Azure agreement, just switched off. And the EU Data Act isn’t coming, it’s already active, so it’s worth checking today where you stand against it.

The longer game

Beyond those quick wins lies a bigger architectural question: does every workload need to sit on the same platform? For most organisations, no. General purpose platforms remain fine for everyday work, while transactional data (data that drives your processes but isn’t actively collaborated on: invoices, payslips, signed contracts) or data that can be legally archived may deserve a genuinely European alternative, one where the company, the operations, and the infrastructure all sit under European jurisdiction.

And if we’re honest, part of the reason so many organisations haven’t done this yet isn’t technical, it’s human: we’d rather avoid a little short-term discomfort now than protect our long-term self-determination later.

AMEXIO PERSPECTIVE  We see sovereignty questions land on our desk in the public sector most often, but the four questions above apply to any regulated organisation. The pattern is always the same: teams that can answer the residency question confidently usually can’t answer the key-management or operational question at all. It’s rarely one gap. It’s a chain nobody has traced end to end.

None of this needs to happen overnight. But it starts with a question every decision maker can actually answer, once they take the time to look: for your most important data, who could be compelled to hand it over, and under whose law? It’s the same question that made a Microsoft lawyer say, on the record, “No, I cannot guarantee it.” Most vendors will never be asked that plainly. Your organisation can still ask it of itself.

AMEXIO colleagues at a table, Trefdag Vlaanderen Digitaal 2026, 22 October, Flanders Expo Gent, stand 8.

Catch AMEXIO at the Trefdag Vlaanderen Digitaal stand, this year’s theme is “Soeverein in een verbonden wereld”. Want the fuller story behind sovereignty and public sector data? Read what one citizen’s digital journey reveals about the future of government

Hans de Bal, Senior Solutions Consultant at AMEXIO Content Science, with a link to his LinkedIn profile