Data protection
Data sovereignty is not a contract problem, it is a location problem
A European data center is a statement about geography. It is not a statement about who can legally reach the data.

“Our data is in Frankfurt” is the most common sentence in data protection discussions about cloud services. It is accurate and it does not answer the question actually being asked. What matters is not where the disks are but which law the provider is subject to.
The contradiction that cannot be resolved
The US CLOUD Act of 2018 obliges providers subject to US law to hand over data in their possession or under their control — regardless of where that data is stored. A European subsidiary with a European data center does not change that as long as the parent company is subject to the law.
Article 48 GDPR says the opposite. An order from a third-country court is only a permissible basis for a transfer if it rests on an international agreement, such as a mutual legal assistance treaty. The CLOUD Act deliberately bypasses such treaties.
The European Data Protection Board concluded that providers subject to EU law cannot lawfully base disclosure and transfer to US authorities on such orders.
A provider is therefore caught between two legal orders: obliged to disclose under US law, obliged to refuse under EU law. That conflict cannot be resolved contractually, because a contract does not override a statute.
A data processing agreement governs what the provider may do. It does not govern what a court can order them to do.
What this means in practice — and what it does not
Two exaggerations are common here, in both directions. One: US authorities routinely read corporate data out of European data centers. There is no evidence for that, and the number of orders is small relative to the number of customers.
The other: the conflict is theoretical and practically irrelevant. That misses the situation too, because what matters for signing off a project is not probability but whether a residual risk can be documented and owned. That is precisely where projects fail.
What the market figures show
The Bitkom Cloud Report 2026 — a representative survey of 603 German companies with 20 or more employees — shows this is not a fringe concern:
| Finding | Share |
|---|---|
| consider Germany too dependent on US cloud providers | 85% |
| buy cloud services from the US | 71% |
| would prefer US providers | 8% |
| would prefer German providers | 91% |
| actually use a German provider | 53% |
The most telling line is the gap between 71 and 8 percent. A large majority uses something it does not prefer. That is not an expression of satisfaction but of missing alternatives with comparable functionality.
Location control versus contractual construction
When a warehouse runs on your own infrastructure the question shifts. There is no provider with possession or control of the data, and therefore no addressee for a disclosure order outside your own legal jurisdiction. Access is bounded by technology and jurisdiction rather than by a contract.
That is not a marketing point but an observation about structure. It has a price: operations, staff and responsibility for security and availability then sit in-house. Anyone unwilling or unable to pay that price has good reasons to use a service provider — but should then name the residual risk rather than contract it away.
The question that helps
In sign-off discussions one question has proved useful to me: which authority can order the disclosure of this data without our organization finding out? With your own infrastructure the answer is a German authority with an order served on you. With a provider under third-country law the answer is longer.
The question helps because it can be answered without percentages and without litigation. It describes who holds control — and that is the core of data sovereignty.
Sources
Every figure in this article is sourced. Where no defensible source exists, no figure is given.