Data Residency vs Data Sovereignty: The Distinction That Costs Money

Axel Grubba, September 08, 2026
Start selling digital products with Crevio
Crevio E-Commerce Platforms logo
Crevio
Sponsored
5.0
(1)
Free plan available
Crevio is an AI-powered platform that runs your business while you sleep. Describe what you want to se... Learn more about Crevio
Get an AI summary of this post on:

These two terms get used interchangeably in hosting marketing, and they mean different things. The difference is one sentence:

Data residency is a fact about storage. Data sovereignty is a fact about jurisdiction.

A German data centre operated by a US company gives you residency. It does not give you sovereignty. Whether that gap matters to you is the actual decision, and most articles on this topic never get to it.

Why the gap exists: the CLOUD Act

The Clarifying Lawful Overseas Use of Data Act, enacted 23 March 2018, amended the US Stored Communications Act so that US law enforcement can compel a US-based provider to produce electronic data stored anywhere in the world — regardless of where the servers are or what nationality the data subject holds.

So the provider’s incorporation, not the disk’s postcode, determines who can compel disclosure.

Three things about it are commonly overstated, and getting them right matters:

It requires judicial process. A warrant request goes to an independent judge for approval, and the data sought must be relevant and material to an ongoing criminal investigation. It is not a self-service portal. What it isn’t is European judicial process — no EU court reviews it, and the data subject is not a party to it.

The provider can push back. Providers have the right to challenge these orders where complying would conflict with local law. That right is real and it gets used.

And EU law points the other way. GDPR Article 48 says a foreign court judgment or administrative decision requiring disclosure of personal data is only recognisable or enforceable if it rests on an international agreement in force, such as a mutual legal assistance treaty. The European Data Protection Board’s position is that providers subject to EU law cannot lawfully base disclosure to the US on a CLOUD Act request alone.

So the honest description isn’t “US law overrides GDPR.” It’s that a US-incorporated provider holding EU data sits between two legal systems that give it contradictory instructions, and the resolution is unsettled. That legal uncertainty is the risk — not a guarantee of disclosure. It’s also precisely why the sovereignty question exists rather than being a marketing invention.

The four quadrants

Two independent variables — where the data sits, and who the provider is — give four positions, and the two off-diagonal ones are where people get surprised.

Four-quadrant diagram plotting hosting providers by whether data is stored in the EU and whether the provider is EU-incorporated. Named providers are placed in each quadrant

Residency + sovereignty (top left). An EU-incorporated company storing your data in the EU. Hetzner Online GmbH, IONOS SE, Hostinger International Ltd, OVHcloud, Scaleway, Contabo, nazwa.pl, dhosting. No CLOUD Act exposure, because there’s no US entity in the chain to compel.

Residency without sovereignty (bottom left). The big one, and the one sold as “EU hosting.” AWS’s, Google’s, Azure’s, DigitalOcean’s and Vultr’s European regions all put your bytes in Europe and leave the controlling entity in the United States. Your data is in Frankfurt and your provider is subject to US compulsory process. That’s not a defect being hidden — it’s just a different thing from what the phrase implies.

Sovereignty without residency (top right). The forgotten quadrant. Hetzner is a German GmbH and it will happily sell you a server in Ashburn, Virginia — it has US regions in Ashburn and Hillsboro. Buying from an EU company does not put your data in the EU. You still have to pick the region.

Neither (bottom right). A non-EU provider storing outside the EU, which is where most of the internet runs and is completely fine for most workloads.

The brand that spans two quadrants

The clearest illustration we found is a single company. When we checked the legal imprints:

  • ionos.de names IONOS SE — the German entity
  • ionos.com names IONOS INC. — a US entity

Same brand, same German data centres, two different jurisdictions depending on which domain you bought from. Nothing is concealed — an imprint is a legal disclosure and both are published. But it means the sovereignty question is answered by your invoice rather than by the provider’s nationality as you understand it, and almost nobody checks.

The general rule that follows: read the entity name on your contract. Not the brand, not the domain, not the data centre map.

What this means for a DPIA

If you’re documenting a transfer assessment, the quadrant changes what you have to write.

Top left — EU entity, EU data. No third-country transfer for the hosting layer. This is the shortest possible assessment.

Bottom left — non-EU entity, EU data. This is the case that needs actual work. There’s no transfer in the storage sense, but there is a potential onward disclosure route to a third country’s authorities, and that’s what you’re assessing. In practice you’d document the provider’s transparency reporting and challenge record, the technical measures below, and your legal basis. This is where “but the data never leaves Frankfurt” is not a complete answer, and an auditor who knows the CLOUD Act will say so.

Top right — EU entity, non-EU data. A genuine third-country transfer, needing a transfer mechanism like adequacy or standard contractual clauses. Being an EU supplier doesn’t exempt it.

Bottom right — neither. Ordinary third-country transfer analysis, and for many destinations there’s now an adequacy decision doing the work. The UK is one: the Commission renewed UK adequacy in December 2025 to 2031, so EU-to-UK flows need no separate mechanism.

The tiering most companies actually need

Full sovereignty for everything is expensive and usually unnecessary. The pragmatic split:

Buy sovereignty when the requirement is external and written down. Public-sector procurement, regulated financial or health data, a customer’s security questionnaire, or a sector rule. This is nearly always a contract or a regulation naming the supplier’s jurisdiction, not your own risk assessment — and when it applies, the shortlist is the top-left quadrant and nothing else.

Buy residency plus encryption for everything else, which is most workloads. Two measures do the heavy lifting:

  • Encrypt at rest with keys you hold, outside the provider’s control. A provider compelled to produce ciphertext it cannot decrypt is in a materially different position from one holding your plaintext. This is the single highest-value technical measure in the whole discussion.
  • Minimise what you store. Data you never collected cannot be disclosed. Unglamorous and effective.

One case where neither measure helps, because you’re the one sending the data. If you run an AI agent, its job is to read your files and post the contents to a model API — so the transfer is outbound and deliberate, not a compulsion risk. We worked through which model providers offer EU-resident inference, and found one major provider with no EU endpoint on its first-party API at all.

And know which rule actually binds you before paying for either. Across four country guides we kept finding the cited rule wasn’t the operative one. In Canada, British Columbia repealed its residency requirement in 2021 and Quebec’s Law 25 asks for an assessment rather than localisation — only Nova Scotia public bodies face a hard rule. In India, the DPDP Act takes a negative-list approach with no restricted countries notified, while the central bank’s payment-data directive is absolute. In the UK, the post-Brexit transfer problem was resolved by an adequacy renewal.

The pattern: the rule people quote is often not the rule that applies, and it’s usually looser than assumed in one place and stricter in another. Establish which sentence in which instrument obliges you, before you buy a premium for it.

Where to buy sovereignty if you need it

Hetzner — the cleanest answer in the top-left quadrant: Hetzner Online GmbH, registered at the Ansbach registration office under HRB 6089, with German data centres and no US parent in the ownership chain. €19.99 for 4GB on the CPX line, plus €0.50/month for an IPv4 address. Remember it also sells US regions — pick a German location if residency is the point. We measured its Nuremberg facility answering a German probe in 0.60ms.

IONOS — also genuinely European and the best value per core we’ve found, at four vCores and 4GB for around £9 or $11. Buy from the German or your local European site rather than the .com if sovereignty is your requirement, for the reason above, and check the entity on your invoice.

nazwa.pl — a Polish provider with Polish infrastructure, worth knowing if you want an EU entity outside the German-French duopoly, or if your users are in Central Europe.

dhosting — another Polish option in the same quadrant, similarly useful for EU-entity requirements with regional proximity.

Hostinger — the value choice with European data centres at $11.99 renewal for 4GB, and it does belong in the top-left quadrant: its privacy policy states that Hostinger International Ltd is based in Cyprus, an EU member state. The caveat is different from an entity one — that same policy discloses servers outside the EEA in the US, Brazil, Singapore and Indonesia, so choosing an EU region is a step you take deliberately. We went through its disclosures in detail.

How we checked this

The CLOUD Act description is from published legal analysis read on 17 August 2026: that the Act was enacted 23 March 2018 and amended the Stored Communications Act to allow US law enforcement, via warrant, subpoena or court order, to reach data held by US-based providers outside the United States where it is relevant and material to an ongoing criminal investigation; that warrant applications go to an independent judge; and that providers may challenge orders conflicting with local law. GDPR Article 48’s requirement that foreign judgments and administrative decisions be grounded in an international agreement such as an MLAT, and the European Data Protection Board’s position that EU-law-subject providers cannot lawfully base disclosure to the US on such requests alone, come from the same body of commentary.

We have read law firm and institutional analysis rather than the statute, the Regulation and the EDPB’s assessment in full. We are not lawyers and this is not legal advice — least of all the DPIA section, which describes the shape of the analysis rather than telling you what to write.

A correction to this article’s brief. It framed the central claim as a US provider being compelled to produce Frankfurt-held data “without notifying the data subject and without an EU court order.” The second half is right and the framing understates the picture: a CLOUD Act warrant does require independent judicial approval in the US, providers do have a right to challenge, and GDPR Article 48 with the EDPB’s reading pulls in the opposite direction. The accurate statement is that the provider is caught between conflicting obligations and the outcome is legally unsettled — which is a better reason to care about sovereignty than a claim of unchecked access would be.

The entity placements come from providers’ own published legal notices where we read them: Hetzner Online GmbH with the Ansbach registration office and HRB 6089; IONOS SE on the German imprint and IONOS INC. on the .com imprint; Cloudzy AI Information Technology L.L.C. in Dubai; 20i registered in England and Wales, company number 09775671. That Cloudways is a DigitalOcean company is stated on DigitalOcean’s own product listing, and that Vultr’s address space belongs to The Constant Company, LLC is from ARIN whois. The remaining placements — AWS, Google Cloud, Azure, Linode/Akamai, Namecheap as US entities, OVHcloud and Scaleway as French, Contabo as German, nazwa.pl and dhosting as Polish — rest on those companies’ well-established public corporate identity rather than imprints we read for this article.

One provider is deliberately absent from the diagram. We could not establish UltaHost’s incorporating entity from its own legal pages, and placing a real company in the wrong jurisdiction quadrant would be a worse error than leaving a gap. It’s named in the text with that caveat instead. Hostinger was originally omitted for the same reason and we have since resolved it — its privacy policy states that Hostinger International Ltd is based in Cyprus, so it belongs in the EU-entity column; the diagram note reflects that correction.

What we did not do: review any provider’s transparency reports, count CLOUD Act requests received or challenged, examine anyone’s standard contractual clauses or data processing agreements, or test whether encryption-at-rest arrangements would in fact defeat a production order. The encryption recommendation is a widely-held view about relative exposure, not a legal conclusion we can stand behind for your situation.

The host links above are affiliate links. The article’s central practical advice — that most workloads need residency plus encryption rather than full sovereignty — argues against the premium products in this category, and the encryption and data-minimisation measures we rate most highly cost nothing and earn us nothing.

FAQ

What is the difference between data residency and data sovereignty?

Residency is where your data is physically stored. Sovereignty is which country’s legal system can compel access to it. A US company’s German data centre gives you residency without sovereignty.

Does storing data in the EU protect it from US authorities?

Not by itself. The CLOUD Act reaches data held by US-based providers wherever it’s stored, so an EU data centre operated by a US company remains within reach of US compulsory process. The provider’s incorporation is the variable, not the server’s location.

Does the CLOUD Act override GDPR?

Not cleanly. A CLOUD Act order requires US judicial approval, and GDPR Article 48 makes foreign disclosure orders enforceable only via an international agreement — with the EDPB’s view being that EU-law-subject providers cannot lawfully comply on that basis alone. The provider is caught between the two, and the conflict is unresolved rather than settled in either direction.

Do I need data sovereignty or just data residency?

Sovereignty when an external requirement names the supplier’s jurisdiction — public-sector procurement, regulated data, a customer contract. Residency plus encryption with keys you control is sufficient for most other workloads.

Is an EU provider always storing data in the EU?

No. Hetzner is a German company with data centres in Virginia and Oregon, and OVHcloud has Canadian regions. Choosing an EU supplier and choosing an EU region are two separate decisions.

How do I find out which entity my hosting contract is with?

Read the invoice and the legal imprint on the site you bought from. One provider in our comparison contracts through a German entity on its .de site and a US entity on its .com, with the same data centres behind both.

Does encryption solve the CLOUD Act problem?

It changes the exposure materially rather than solving it: a provider compelled to produce data it cannot decrypt is in a different position from one holding plaintext. That requires you to hold the keys outside the provider’s control, and it’s the highest-value technical measure available here.

Founder & Software Review Editor
Axel Grubba is the founder of Findstack, a B2B software comparison platform, with his background spanning management consulting and venture capital where he invested in software. Recently, Axel has developed a passion for coding and enjoys traveling when he is not building and improving Findstack.
Business Software Reviews SaaS Product Evaluation CRM Software
Subscribe, get software deals straight to your inbox.
Join 8,000+ other entrepreneurs staying up-to-date on all the latest deals.
Zero spam. Unsubscribe at any time.