Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Technology · 1 min read

Data trustee

In shortA European operator between you and the US vendor. Works when the vendor is genuinely out.

The model is always the same: a US vendor licenses its technology to a European company. That company runs it in its own data centres, with its own staff, under its own contract. The vendor supplies software and updates — and is meant to have no access to customer data.

Known examples: Delos Cloud (SAP running Microsoft technology), the earlier Microsoft Cloud Deutschland under T-Systems, and several hyperscaler offerings with local partners.

What it depends on

Three questions decide it, and all three are technical rather than legal.

Can the vendor technically reach in? If remote maintenance, telemetry or a support access path exists, then yes — and the CLOUD Act reaches through it. See US CLOUD Act.

Who holds the keys? Does key management sit with the trustee or with the vendor? Only in the first case is the vendor genuinely out. See Key control (BYOK and HYOK).

Who can switch it off? Licences, updates and certificates still come from the vendor. Under an export control or a sanction, operations end — not immediately, but at the next renewal. That is the difference between data protection and availability, and trustee models solve only the first.

What it is good for

For organisations that need one specific piece of software and must stop data flowing out, it is a real improvement on buying direct. It answers "who sees our data?" — and it does not answer "what if we stop being supplied tomorrow?".

Anyone who needs both answered ends up at technology that keeps running without the vendor. See Sovereign cloud.

Sources

See also

Related terms