Skip to content
Call, 0511 – 47 55 58 11

Digital sovereignty and dependence

A data centre in the EU does not answer the question. What decides it is who can reach the data and which law that access follows.

In debate, sovereignty often works as a statement of belief. In law it is a set of distinct questions that can be answered separately and that carry different weight.

Four levels worth keeping apart

  • LawWhich law binds the provider and its group? A duty to disclose under foreign law cannot be contracted away.
  • AccessWho can actually work in clear text? Administrators, support, sub-processors. The place of storage says nothing about that.
  • OperationWho operates, updates and monitors? An operating model that does not work without the provider creates dependence whatever the contract says.
  • ExitHow hard would a change be? Data formats, interfaces, migration effort and notice periods decide whether an alternative is real.

What helps and what merely reassures

Effective

  • Key control on your side, with no way for the provider to work in clear text
  • Remote access limited, logged and released case by case
  • A contractual right to return of the data in a documented format, within a deadline
  • Open interfaces and standards, so an alternative stays technically possible

Hardly effective

  • An EU data centre while the group remains tied to a third country
  • Assurances not to follow foreign law that the provider could not keep
  • Encryption whose keys sit with the provider
  • Statements of commitment to sovereignty with no matching clause in the contract

Where it differs from data protection

Sovereignty and data protection overlap without being the same thing. Third country transfers are a data protection question with instruments of their own, set out under third country transfers. The question of sovereignty also arises where no personal data is involved at all, for instance with design data or source code.

Translated into procurement

Sovereignty as a requirement?

We translate the ambition into criteria and clauses that hold in the contract.

Sharpen the requirements

Frequently asked questions

Is it not enough that the data sits in the EU?

The place of storage is only one factor among several. Where the provider or its parent is subject to the law of a third country, a duty to hand data over may exist there regardless of where the data physically sits. Remote access from support comes on top. The two have to be looked at separately.

Does encryption solve it?

Only where the provider does not hold the keys and cannot technically obtain them. Encryption whose keys sit with the provider, or are processed in its environment, moves the problem rather than removing it. The decisive question is who can work in clear text, and when.

What is the most important contractual point?

The exit. Whoever gets their data back in a common format within a reasonable time has a negotiating position. Whoever has not settled that negotiates every price rise from the weaker side. The point belongs in the contract before it is needed, not afterwards.

Related