Your Data Is in London. So Whose Law Applies to It?
Sovereignty gets asked as a location question, and location is the easy part. Where the servers sit and which courts can compel disclosure are two different things, and only one of them appears on a procurement checklist.
Every organisation can now tell you which country its data is held in. Rather fewer can tell you which country’s courts could order it handed over — or what the provider would be permitted to say if that happened.
Those are different questions, and only one of them appears on a procurement checklist.
1. It Gets Asked as a Location Question
Where is the data held? It is a fair question, it is the one most regulations ask, and it has a clean answer.
A region is selected, a contract records it, an auditor confirms it. The organisation ticks the box and moves on to the next control.
None of that is wrong. It is simply the part of the problem that was already straightforward.
2. Location Is the Straightforward Half
Physical location was solved years ago. Every major provider offers regions in Britain and across Europe, and selecting one is a configuration choice rather than a negotiation.
Because it is straightforward, it has absorbed most of the attention. Conversations about sovereignty tend to conclude once somebody confirms the servers are in London or Frankfurt.
Which leaves the harder half untouched — and, in most conversations, unmentioned.
3. Residency Is Not Sovereignty
A provider incorporated in the United States remains subject to United States law wherever its buildings happen to be. The CLOUD Act allows American authorities to compel disclosure of data held by such a provider — anywhere in the world.
A London region operated by a US-incorporated company therefore gives an organisation residency. It does not, on its own, give it sovereignty.
Residency tells you where the servers are. Sovereignty tells you whose courts can reach them — and only one of those has ever appeared in a business case.
4. Somebody Has Started Pricing the Difference
This stopped being theoretical in April, when the European Commission awarded a contract worth €180 million to supply sovereign cloud to EU institutions.
It went to four European providers rather than to the established hyperscalers. Whatever else that was, it was a large buyer concluding that jurisdiction is a product attribute — and pricing it accordingly.
Public procurement tends to move first on questions like this, dragging regulated industry behind it. Supply chains follow after that, usually through contract clauses rather than conviction.
5. Britain Has Taken a Different View, Deliberately
The UK debate has been noticeably more muted, and it is worth being fair about why.
There is no British policy preventing public sector organisations from storing or processing data in any particular country, and localisation requirements here remain less common than across the Channel. That is a considered position rather than an oversight — it keeps the market open, and avoids paying a premium for a risk that may never arrive.
It also leaves the decision with each organisation rather than with government. That is a heavier responsibility than most have noticed they are carrying.
6. The Harder Question Is Whether You Could Leave
Jurisdiction only starts to matter when something changes. Politics shift, a provider is acquired, a legal test is decided differently from how everyone assumed it would be.
At that point the question is not where the data is. It is whether it could be moved — in a usable form, within a sensible period, without rebuilding everything that reads from it.
Very few organisations have tested that. The ones that have generally found it took considerably longer than the contract had implied.
7. What Is Worth Establishing
None of this needs a legal opinion to start with. Four questions get most organisations a long way:
- which legal entity holds your contract, and where it is incorporated
- what the provider must tell you if it receives a disclosure order
- how you would extract the data, in what format, and how long it would take
- what breaks the day after you move it, and who would fix that
The last turns an abstract concern into something somebody can cost, which is when it starts getting attention.
8. Say What You Are Actually Buying
Some organisations genuinely need jurisdictional protection, and should pay for it. Others are buying reassurance — paying a premium to relabel a risk they had already decided to accept.
Both are defensible. What is not defensible is not knowing which of the two has been bought — which is where a good many sovereignty programmes currently sit.
The word appears in contracts far more often than the underlying question has been answered.
Final Thought
Sovereignty has largely been treated as a compliance exercise, which turns it into a question about geography with a yes or no answer.
It is better understood as a question about dependency. Who could compel your provider, what would follow if they did, and what it would cost to be somewhere else by the end of the year.