Quick answer · the 30-second read
Data residency is where your data is stored. Data sovereignty is which country’s laws can reach it. They are not the same thing, and one does not guarantee the other. A US-owned company can store your documents in Germany. That gives you German residency. It does not put the data beyond the reach of US law, because US law follows the company rather than the server. Most buyers ask about residency when the thing they actually care about is sovereignty.
Key facts
|
What is data residency?
Data residency means the country where your files are kept. Cloud services store your files on servers, and those servers sit in real buildings in real countries. If your signed contracts are kept on a server in Frankfurt, your data residency is Germany.
This is a simple fact you can check. Most suppliers publish it, and many let you pick a country when you open an account. To see how the main e-signature platforms handle this, read Where do e-signature platforms store your data, and can you choose the region?
What is data sovereignty?
Data sovereignty is the question of which country’s laws apply to your data, and which governments can compel someone to hand it over.
This depends less on where the data sits than on who holds it. A company is subject to the laws of the country it is based in. If that company can access your data, its home government has a route to your data, wherever the server happens to be.
Why is this difference important?
Because a supplier can answer your question honestly and still not tell you what you needed to know.
Imagine a US e-signature company that offers to keep your files in Germany. Your files really are in Germany, and German and EU privacy law really does apply to them. But the company itself is a US company, so it has to follow US law as well.
A US law called the CLOUD Act, passed in 2018, says this plainly. If a US company is ordered to hand over data it holds, it must do so, whether that data is in the US or not. The rule follows the company, not the server.
So the German server answers the question about where your files are kept. It does not put them out of reach of the US courts. Both of those things are true at the same time, which is why people mix the two ideas up.
Is it legal to use a US supplier for UK or EU data?
Yes, in general, and most organisations do.
Personal data can move from the EU to the US under the EU-US Data Privacy Framework, adopted by the European Commission in July 2023. US companies self-certify to the framework, and transfers to certified companies are permitted without extra paperwork.
The framework is valid law today. It is also the third attempt at this arrangement. Safe Harbor was struck down by the EU courts in 2015 and Privacy Shield in 2020. The current framework survived its first challenge when the EU General Court dismissed the case brought by French MP Philippe Latombe on 3 September 2025. That judgment has been appealed to the Court of Justice, and the appeal is still pending.
The practical position for a buyer is that using a US supplier is lawful, but the legal basis has been rebuilt twice in ten years and is under challenge again. Organisations that cannot tolerate that uncertainty are the ones asking sovereignty questions.
Who actually needs to worry about sovereignty?
Most businesses do not. For ordinary commercial contracts, residency and a proper data processing agreement are enough.
However, there are exceptions. Public sector bodies and their suppliers often work to procurement rules that specify where data is held and who can access it. Regulated sectors such as defence, health and financial services may have sector rules of their own. Legal and professional firms holding privileged material may need to show that no foreign government has a route to it. And any organisation with a contractual promise to a client about data location will need to check that promise against the sovereignty question, not just the residency answer.
What should you ask a supplier?
- Ask where the data is stored, and where the backups are stored. These are often different countries.
- Ask who owns the company and where it is incorporated, because that determines which government can compel disclosure.
- Ask whether any support staff, subcontractors or subprocessors outside your chosen region can access your data.
- Ask what happens if the supplier receives a foreign legal demand for your data, and whether it will tell you.
- Ask who holds the encryption keys. If the supplier holds them, it can decrypt your data on request. If you hold them, it cannot.
Sources
- CLOUD Act 2018, codified at 18 U.S.C. § 2713
- CLOUD Act, Public Law 115-141, Division V
- European Commission adequacy decision on the EU-US Data Privacy Framework (adopted 10 July 2023)
- Case T-553/23 Latombe v Commission, judgment of the General Court, 3 September 2025
- Case C-703/25 P Latombe v Commission, appeal lodged 31 October 2025
- Information Commissioner’s Office, international data transfer guidance