Summary
- European data sovereignty is shifting beyond compliance towards practical questions about physical data location, legal jurisdiction, ownership, and operational control.
- European initiatives including Gaia-X and IPCEI-CIS are intended to strengthen sovereign cloud capacity while hyperscalers also invest in EU-based infrastructure.
- Storrar argues that organisations should demand precise answers from infrastructure providers about data location, governing law, security controls, access models, and support.
Terry Storrar, managing director, Leaseweb UK
Data sovereignty has, undeniably, become a current and pressing business issue. No longer an abstract concept, organisations are recognising the very practical benefits of knowing exactly where data is stored, which country’s laws govern this and how data can be best protected.
Although this impacts businesses across the world, there is currently no greater forum of activity to address this than in Europe, where sovereignty-designed initiatives are gaining traction in response to geopolitical pressures. For organisations, asking the right questions about data residency, ownership and governance and taking practical action goes far deeper than a tick box compliance exercise.
Data sovereignty efforts gaining momentum
In 2018, GDPR legislation arguably cast the scene for change in Europe, as this provided more stringent guidelines on data use and how this could be shared outside the European Union. When combined with the US CLOUD Act, that allowed US authorities to request data from American cloud providers no matter where the geographic location of data, this spurred debate about foreign rights to the region’s data.
Today’s economic and political tensions have further fuelled concerns, with organisations wanting clarity, control and security over where their data is located. Although there is not yet a standard, compulsory compliance requirement for data sovereignty, there is an increasing sense of urgency in Europe to reduce reliance on US hyperscalers and to establish viable, secure alternatives for the region’s data.
Investing into Europe’s sovereign future
This direction is supported by a number of strategic European Union initiatives that aim to prepare and strengthen the region’s digital independence in coming years. For example, the EU released its Gaia-X Trust Framework at the end of 2025. This modelled how sovereign data can be stored, shared, and be audit-ready under EU law. This is another prompt for organisations to fully assess that their data location and hosting arrangements are crystal clear and in line with the latest recommendations.
With global cloud infrastructure services growing at their fastest in eight years in the second quarter of 2026, programmes like the EU’s Important Projects of Common European Interest on Cloud Infrastructure and Services (IPCEI-CIS) are a highly relevant and significant investment into building Europe’s own sovereign cloud infrastructure and services.
Numerous organisations are already involved in this effort to build a sovereign European cloud campus. The initiative aims to provide cloud services that fall under Europe’s legal and regulatory frameworks. Rather than mandating compliance, this will offer a choice for companies who want to protect their sensitive data from foreign intervention.
Mindful that European cloud services offer the certainty, transparency and control they cannot guarantee, US hyperscalers are also investing into EU-based infrastructure to quell concerns from business customers, governments and regulators. With AWS, Microsoft Azure and Google Cloud controlling 65% of the European cloud market, the cooperation of hyperscalers on how to manage Europe’s data will be crucial towards progress.
The impact on Europe’s IT ecosystem
Although a degree of continued reliance on hyperscalers is inevitable, Europe’s ultimate goal to establish digital independence is influencing strategic IT decisions across procurement, partner selection, architecture design and policy stance on data sovereignty.
As businesses of every size scrutinise this issue, specialist European cloud providers are prepared to play a fundamental role in data sovereignty. These providers can offer infrastructure designed with data provenance at its heart, locally governed data centres, EU-compliant operations and support that protects data from cross-border exposure. Increasingly providers are also able to guarantee that data stored in a specific country is governed by the country’s laws it is present in. So even within Europe’s borders, UK-based data is not subject to laws in The Netherlands, and data located in France is not governed by German regulations.
As adoption of more localised cloud services increases, organisations need to be sure of an infrastructure partner that can competently direct this process. As a priority, any provider should be able to give precise answers as to exactly where data is physically stored, as well as offer sovereign security controls, access models, support structures and accurate reporting. Vague best practice policies and stating that data is “EU hosted” are no longer sufficient.
Without doubt, European data sovereignty will have a profound impact on business operations, no matter whether this is for a multi-national enterprise or an SME. The initial foundations are already laid, with the current spotlight on the very practical concern of data location and residency. With Gartner calling on CIOs and IT leaders to create and protect their organisation’s digital sovereignty, they can at least forge ahead knowing that they have the support of European governments and cloud experts to pursue this.
| About the author | |
|---|---|
| Terry Storrar is managing director of Leaseweb UK. | |












