Data Sovereignty: What It Is and Why It Matters
Last week, Zoho held its Partner Inspire conference on 15 and 16 June 2026, and one theme ran through the sessions more than any other: data sovereignty. Zoho positioned it not as a compliance checkbox but as what its own materials called a foundational architecture, built around European data centres, a business model that does not monetise customer data, independent private ownership, and full control of its own technology stack.
That is a confident pitch, and worth unpacking on its own terms rather than taking at face value. Data sovereignty has become a genuine boardroom topic in the last two years, not a buzzword invented for a partner conference. If you run a UK or Irish business on any cloud platform, from CRM to email to file storage, the question of whose laws actually govern your data is worth understanding properly, whichever vendor you use.
Data Sovereignty vs Data Residency vs Data Protection
These three terms get used interchangeably, but they describe different things. Understanding the distinction matters because a vendor can tick one box and not the others.
| Term | What it actually covers | Common gap |
|---|---|---|
| Data residency | The physical or geographic location where your data is stored | Servers can sit in the EU while the parent company remains subject to another country's laws |
| Data protection | The rules governing how personal data is collected, used, and secured, such as UK GDPR | Protection rules do not by themselves stop a foreign government compelling access to a vendor |
| Data sovereignty | Which country's laws actually have authority over your data and the vendor holding it, regardless of server location | Often the least visible of the three, and the one most businesses never ask about |
A vendor can offer strong data residency and solid GDPR-aligned data protection while still being legally exposed to a foreign jurisdiction's reach through its corporate ownership or headquarters. That gap is the specific problem data sovereignty is meant to address.
Why This Conversation Has Moved Up the Agenda
Data sovereignty was a niche topic in public-sector procurement a few years ago. It is now a mainstream one, driven by a small number of specific, reported events that made the abstract risk feel concrete.
Whose Laws Actually Apply to Your Vendor
US law gives American authorities potential access to data held by US-headquartered vendors, regardless of where the underlying servers physically sit. That single fact is the crux of the sovereignty debate: a European data centre does not automatically place data outside the reach of a foreign government if the company operating it is subject to that government's jurisdiction.
The Microsoft and ICC Case
The clearest recent example cited in industry coverage involved the International Criminal Court. Following a US executive order in February 2025, the ICC's chief prosecutor reportedly lost access to his Microsoft email account. The ICC later moved away from Microsoft entirely, adopting the open-source openDesk platform instead. I have not independently verified every detail of this reporting myself, so if you plan to cite it publicly, it is worth checking the original coverage from outlets such as The Register, Computer Weekly, and Irish Legal News directly. The episode is widely credited with sharpening European concern about what some commentators call a vendor "kill switch," the idea that a US tech provider could be compelled to cut off services to a specific customer or country with little recourse for that customer.
Europe's Regulatory Response
That concern has since shown up in policy. The European Commission has been developing a Tech Sovereignty Package, including a proposed Cloud and AI Development Act intended to keep sensitive public-sector data away from vendors seen as subject to foreign government reach. France and Germany also launched a joint task force on digital sovereignty in late 2025. None of this is settled law yet, and the detail is still moving, so treat the specifics as developing rather than final.
A server in Europe does not automatically put your data beyond the reach of a foreign government. Ownership and jurisdiction matter as much as geography.
Where Sovereignty Shows Up in Real Decisions
Public bodies and regulated industries increasingly need to demonstrate which jurisdiction governs their vendor before a contract is signed, not after.
A privately held vendor with no external pressure to sell or relocate carries different risk than one owned by a company facing shareholder or political pressure.
A data processing agreement that only states where servers sit does not answer whether a foreign court or executive order could compel access.
If a critical system could be disrupted by a foreign government action against its vendor, that risk belongs on the same continuity register as any other.
Four Questions to Ask About Your Own Data Sovereignty
Confirm the actual data centre region for each core system, rather than assuming it matches where your account was registered.
A vendor's country of incorporation determines which government can, in principle, compel it to act, independent of where its servers sit.
Publicly listed companies face shareholder and takeover pressure that privately held vendors do not, which can change data handling decisions over time.
A vendor running on a third-party hyperscaler inherits that hyperscaler's jurisdiction exposure as well as its own.
What This Means for UK and Irish Businesses
The UK sits in an interesting position in this debate. On 19 December 2025, the European Commission renewed its UK data adequacy decisions for a further six years, to 27 December 2031, confirming that personal data can keep flowing freely between the EEA and the UK. That is a genuinely reassuring, verified development for any UK business handling EU customer data. It addresses data protection adequacy, though, not the separate question of vendor jurisdiction that sovereignty debates are really about.
Zoho's Partner Inspire positioning leaned heavily on its European data centres, its privately held ownership, and the fact that it does not run an advertising business built on customer data. Those are genuine, checkable claims, and worth verifying against Zoho's own published privacy and GDPR documentation rather than taking a conference slide as the final word. The broader lesson from the conference applies regardless of which vendor you use: ask where your data sits, ask who governs your vendor, and treat the answer as part of your risk register, not a one-off compliance tick.
If you would like a straightforward, jargon-free look at where your current systems actually sit on data residency, vendor jurisdiction, and ownership, we are happy to talk it through with you.
