Skip to main content
Legal Guide

What is the difference between data residency and data sovereignty?

Data residency is where your files are stored, while data sovereignty determines which country's laws apply and which governments can access them.

A server rack behind a glass wall, seen from an office corridor.

AI-generated image

Quick answer · the 30-second read

Data residency is where your data is stored. Data sovereignty is which country’s laws can reach it. They are not the same thing, and one does not guarantee the other. A US-owned company can store your documents in Germany. That gives you German residency. It does not put the data beyond the reach of US law, because US law follows the company rather than the server. Most buyers ask about residency when the thing they actually care about is sovereignty.

 

Key facts

  • Data residency means the country where your files are kept.
  • Data sovereignty means which country’s laws apply to your files and who can order them to be handed over.
  • The US CLOUD Act 2018 says US companies must hand over data they hold when ordered to, wherever in the world it is kept.
  • Picking a European server from an American company changes where your files are kept. It does not change the fact that the company must follow US law.
  • The EU-US Data Privacy Framework has allowed personal data to move from Europe to approved US companies since July 2023.
  • The two earlier versions of that agreement were thrown out by European courts, in 2015 and 2020.
  • The current agreement was challenged in court and survived on 3 September 2025. That decision has been appealed.

What is data residency?

Data residency means the country where your files are kept. Cloud services store your files on servers, and those servers sit in real buildings in real countries. If your signed contracts are kept on a server in Frankfurt, your data residency is Germany.

This is a simple fact you can check. Most suppliers publish it, and many let you pick a country when you open an account. To see how the main e-signature platforms handle this, read Where do e-signature platforms store your data, and can you choose the region?

What is data sovereignty?

Data sovereignty is the question of which country’s laws apply to your data, and which governments can compel someone to hand it over.

This depends less on where the data sits than on who holds it. A company is subject to the laws of the country it is based in. If that company can access your data, its home government has a route to your data, wherever the server happens to be.

Why is this difference important?

Because a supplier can answer your question honestly and still not tell you what you needed to know.

Imagine a US e-signature company that offers to keep your files in Germany. Your files really are in Germany, and German and EU privacy law really does apply to them. But the company itself is a US company, so it has to follow US law as well.

A US law called the CLOUD Act, passed in 2018, says this plainly. If a US company is ordered to hand over data it holds, it must do so, whether that data is in the US or not. The rule follows the company, not the server.

So the German server answers the question about where your files are kept. It does not put them out of reach of the US courts. Both of those things are true at the same time, which is why people mix the two ideas up.

Yes, in general, and most organisations do.

Personal data can move from the EU to the US under the EU-US Data Privacy Framework, adopted by the European Commission in July 2023. US companies self-certify to the framework, and transfers to certified companies are permitted without extra paperwork.

The framework is valid law today. It is also the third attempt at this arrangement. Safe Harbor was struck down by the EU courts in 2015 and Privacy Shield in 2020. The current framework survived its first challenge when the EU General Court dismissed the case brought by French MP Philippe Latombe on 3 September 2025. That judgment has been appealed to the Court of Justice, and the appeal is still pending.

The practical position for a buyer is that using a US supplier is lawful, but the legal basis has been rebuilt twice in ten years and is under challenge again. Organisations that cannot tolerate that uncertainty are the ones asking sovereignty questions.

Who actually needs to worry about sovereignty?

Most businesses do not. For ordinary commercial contracts, residency and a proper data processing agreement are enough.

However, there are exceptions. Public sector bodies and their suppliers often work to procurement rules that specify where data is held and who can access it. Regulated sectors such as defence, health and financial services may have sector rules of their own. Legal and professional firms holding privileged material may need to show that no foreign government has a route to it. And any organisation with a contractual promise to a client about data location will need to check that promise against the sovereignty question, not just the residency answer.

What should you ask a supplier?

  • Ask where the data is stored, and where the backups are stored. These are often different countries.
  • Ask who owns the company and where it is incorporated, because that determines which government can compel disclosure.
  • Ask whether any support staff, subcontractors or subprocessors outside your chosen region can access your data.
  • Ask what happens if the supplier receives a foreign legal demand for your data, and whether it will tell you.
  • Ask who holds the encryption keys. If the supplier holds them, it can decrypt your data on request. If you hold them, it cannot.