Skip to content
MCP server built inHow that works
All articles

Data protection

Data sovereignty is not a contract problem, it is a location problem

A European data center is a statement about geography. It is not a statement about who can legally reach the data.

Daniel Alisch
Daniel AlischCo-Founder lavalake · July 8, 2026 · 3 min

“Our data is in Frankfurt” is the most common sentence in data protection discussions about cloud services. It is accurate and it does not answer the question actually being asked. What matters is not where the disks are but which law the provider is subject to.

The contradiction that cannot be resolved

The US CLOUD Act of 2018 obliges providers subject to US law to hand over data in their possession or under their control — regardless of where that data is stored. A European subsidiary with a European data center does not change that as long as the parent company is subject to the law.

Article 48 GDPR says the opposite. An order from a third-country court is only a permissible basis for a transfer if it rests on an international agreement, such as a mutual legal assistance treaty. The CLOUD Act deliberately bypasses such treaties.

The European Data Protection Board concluded that providers subject to EU law cannot lawfully base disclosure and transfer to US authorities on such orders.
Joint assessment by the EDPB and EDPS on the CLOUD Act, as summarized by activeMind.legal

A provider is therefore caught between two legal orders: obliged to disclose under US law, obliged to refuse under EU law. That conflict cannot be resolved contractually, because a contract does not override a statute.

A data processing agreement governs what the provider may do. It does not govern what a court can order them to do.

What this means in practice — and what it does not

Two exaggerations are common here, in both directions. One: US authorities routinely read corporate data out of European data centers. There is no evidence for that, and the number of orders is small relative to the number of customers.

The other: the conflict is theoretical and practically irrelevant. That misses the situation too, because what matters for signing off a project is not probability but whether a residual risk can be documented and owned. That is precisely where projects fail.

What the market figures show

The Bitkom Cloud Report 2026 — a representative survey of 603 German companies with 20 or more employees — shows this is not a fringe concern:

FindingShare
consider Germany too dependent on US cloud providers85%
buy cloud services from the US71%
would prefer US providers8%
would prefer German providers91%
actually use a German provider53%

The most telling line is the gap between 71 and 8 percent. A large majority uses something it does not prefer. That is not an expression of satisfaction but of missing alternatives with comparable functionality.

Location control versus contractual construction

When a warehouse runs on your own infrastructure the question shifts. There is no provider with possession or control of the data, and therefore no addressee for a disclosure order outside your own legal jurisdiction. Access is bounded by technology and jurisdiction rather than by a contract.

That is not a marketing point but an observation about structure. It has a price: operations, staff and responsibility for security and availability then sit in-house. Anyone unwilling or unable to pay that price has good reasons to use a service provider — but should then name the residual risk rather than contract it away.

The question that helps

In sign-off discussions one question has proved useful to me: which authority can order the disclosure of this data without our organization finding out? With your own infrastructure the answer is a German authority with an order served on you. With a provider under third-country law the answer is longer.

The question helps because it can be answered without percentages and without litigation. It describes who holds control — and that is the core of data sovereignty.

Sources

Every figure in this article is sourced. Where no defensible source exists, no figure is given.

  1. Article 48 GDPR — transfers or disclosures not authorised by Union law
  2. Bitkom Cloud Report 2026 — press release (German)
  3. US CLOUD Act and the GDPR — overview by activeMind.legal
  4. CLOUD Act vs GDPR — analysis by Exoscale

Related