Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Technology · 1 min read

Data residency and data sovereignty

In shortA server location is an address. Jurisdiction is an authority.

Almost every procurement document carries the requirement "data stored in Germany". It is well meant, and it protects less than most people assume.

What data residency governs

Data residency says where bits sit on disks. It is easy to verify, easy to confirm and easy to advertise. It helps with latency, with some regulatory requirements, and with the question of whose power grid feeds the data centre.

What it does not govern

It says nothing about who may access those bits. A CLOUD Act order is served on a company, not on a building. An American corporation with a data centre in Frankfurt remains an American corporation. See US CLOUD Act.

It also says nothing about operational remote access. If the on-call rotation sits in Seattle with administrator rights, the data is in Frankfurt and the access is in Washington.

The three questions that matter instead

  1. 01Who holds the keys? Encryption whose key sits with the provider helps against theft, not against an order served on that same provider. See Key control (BYOK and HYOK).
  2. 02Which law does the parent company answer to? Not the subsidiary that signs the contract.
  3. 03Who has administrative remote access, and from which country? This question rarely appears in a tender, and it often answers everything.

A better wording

Instead of "data stored in Germany", require: processing, operations and support exclusively by staff located in the EU; no company outside the EU holding control over the data; and key management with the customer.

That is longer. It is also the difference between an assurance and an assurance that means something.

Sources

See also

Related terms