
Data Residency: Data Location Is Not the Same as Data Sovereignty
Data residency determines where data is stored (data location) and who can access it (data sovereignty). In an increasingly cloud-based IT landscape, the focus extends beyond business and personal data to include endpoint management data and metadata. Deciding where to store data while balancing efficiency, regulatory compliance, and risk management has become a strategic priority.
Data Residency – At a Glance
- In cloud environments, storage locations for endpoint data and metadata are becoming key IT priorities, alongside those for business and personal data.
- Local storage, especially in the EU, increases legal certainty and trust, but does not provide complete protection against unauthorized access.
- Data sovereignty is becoming crucial for companies because controlling access to data is often more important than where it’s stored.
- For business-critical systems, local or EU-based data residency is recommended to ensure digital sovereignty and operational autonomy.
Diplomatic packages cross international borders without being subject to inspection because they are governed solely by the laws of the sender’s country. Companies
engaged in international business would like comparable protection for their most sensitive data.
However, no such protections exist in the digital world. Instead, for many companies, the question is one of data residency — that is, the physical location of stored data
and who owns it. This has become increasingly important in recent years as businesses have moved IT processes to the cloud to improve efficiency.
What is data residency?
Data residency refers to where data is physically stored and to the legal frameworks that determine which laws, regulations, and government access rights apply to it regardless of where a company is based. For many businesses, data residency is a key factor in digital sovereignty, particularly in cloud-based IT environments.
Data Residency and Dependence on Cloud Providers
In recent years, rising geopolitical instability has led many decision-makers to question whether they have become overly dependent on cloud services hosted in other countries. According to Cisco's 2025 Data Privacy
Benchmark Study, which surveyed more than 2,600 security and privacy professionals across 12 countries, 90% of organizations view local data storage as inherently safer.
Two risk-management concerns are at the forefront:
- How well is proprietary business data stored in the cloud protected from access by competitors or foreign government agencies?
- Will access to cloud resources be jeopardized during periods of geopolitical conflict?
The International Criminal Court (ICC) in the Hague’s indictment of Israeli Prime Minister Benjamin Netanyahu for Israeli military actions in Gaza illustrates the risks.
The U.S. government, led by Netanyahu’s ally Donald Trump, responded to the indictment by blocking the ICC’s chief prosecutor and judges from accessing US-based email, travel,
payment, and other cloud services from any location worldwide.
While the ICC is more exposed to international political pressures, the case demonstrated that businesses and other organizations should pay meticulous attention to where corporate
data is stored and to whether they can continue operating effectively if access to that data is denied.

Arguments in favor of data residency in the EU
Even without political turmoil, there are good reasons for companies to opt for local data residency. For EU-based organizations, that would be a location within the EU:
- Network latency: Data often needs to be stored near its source to ensure low-latency processing. For example, AI-driven video surveillance in a factory requires fast access to data for timely incident responses.
- Regulations: The GDPR prohibits the transfer of personal data to third countries that do not provide a comparable level of data protection. The 2020 Schrems II ruling by the European Court of Justice established that business contracts require a case-by-case assessment of whether U.S. law provides equivalent data protections. Depending on the industry, this creates a de facto obligation to process data within the EU, e.g., patient data in healthcare.
- Trust: Hyperscalers store European customers’ data within the EU and claim to prevent unauthorized access through technical measures and local partnerships. However, they are also subject to the US CLOUD (Clarifying Lawful Overseas Use of Data) Act and other laws that allow U.S. authorities to access data hosted by US cloud service providers regardless of its location and to prohibit cloud operators from informing their customers. As a result. some companies use “canary files” to detect unauthorized access and opt for trusted local providers instead.
Don’t overlook IT management data
Data residency concerns extend beyond trade secrets and personal data. Following Edward Snowden’s 2013 revelations about government surveillance of digital systems, IT leaders realized that
data residency also applies to data and metadata from unified endpoint management (UEM) and other IT management systems. IT admin tools provide access to systems that store
highly sensitive business, engineering, and product information. Even network metadata can yield a trove of valuable intelligence for government and private espionage organizations.
The implication for IT teams is clear: Choose the location of your digital assets strategically and always maintain control of data from UEM and other IT systems.
There’s no reason not to use cloud-based tools for day-to-day management of Windows clients. However, business-critical endpoints such as executive laptops or Linux servers used in
research departments should be managed with data residency in mind, ideally using an on-premises solution, a trusted local MSP, or an established partner based in the EU for
European organizations.
Data Residency and Digital Sovereignty: Access Over Location
The basic operating principle for IT admins used to be my server, my data, my control. Today, however, data is constantly on the move without the protections of diplomatic immunity. This
poses new challenges for business leaders regarding data control, security, and sovereignty.
With the right tools, administrators can consistently apply data hygiene processes to ensure data
integrity and currency, and sound data residency practices that keep stored and in-transit data always in view. Ideally, this view includes metadata from endpoint management systems. In
this context, UEM systems that support simultaneous, parallel operation across cloud-based and on-premises environments are especially valuable.
IT teams that want to retain sovereignty over their most sensitive data should also carefully choose both the storage location and the legal framework that apply to that
data. What matters most is not where the data is stored but who is authorized to access it.
Best Practice Guide: Securing Digital Sovereignty
Many companies face the challenge of managing increasing dependencies on international technology providers while meeting compliance requirements.
Our Best Practice Guide offers strategies to strengthen digital independence, minimize risks in a targeted manner, and future-proof your IT infrastructure.
Download the “Digital Sovereignty” Best Practice Guide now


