Skip to content
← Back to the toolkit
PossessHardwareData

Data residency

Where your data physically sits. It is a necessary question and a long way from a sufficient one, because location is a weak proxy for control.

A Dutch data centre operated by a US-headquartered provider is still reachable under US law, so residency answers where the data is and leaves open who can compel access to it.

Data residency is the most over-trusted idea in the field. It is easy to verify, easy to put in a brochure and it feels like an answer. It usually is not one.

Residency tells you where the bytes rest. Sovereignty asks who can act on them. The two come apart the moment the operator of a facility, or its parent company, sits under a different legal regime than the flag on the building. Where your data sits and who can reach it are separate questions, and only the second one is about control.

This is not theoretical. A census of Dutch mental-healthcare record systems found that many run on, or point to, US hyperscaler clouds, even where the marketing implied a domestic home. The lesson generalises: treat residency as one input among several, and never mistake it for proof of control.

Common misconceptions

Our data is in an EU data centre, so it is sovereign.

Residency fixes the postcode. Who operates the facility, whose law reaches the operator, who holds the keys and whether you could leave are all separate questions, and they are the ones that decide control.

A hyperscaler EU region removes foreign legal exposure.

Jurisdiction follows the corporate control chain, not the map. An EU region of a US-parented provider can still fall under extraterritorial law.

Put this to work

Questions for your vendor

Questions to ask a vendor before you sign

The questions that make a supplier prove data sovereignty, and what a real answer versus an evasive one sounds like. Copy them into an RFP, or read them down a vendor call.

Related concept

Data sovereignty

The practical ability to exercise Possess, Use and Dispose across Data, Software, Hardware and Organisational layers within a defined customer-control scope.

Related concept

The four layers

The three rights apply across Data, Software, Hardware and an Organisational layer described through data compliance and data ethics.

Related article

A Dutch data centre is not (per se) a sovereign one

Vendors reassure mental-healthcare providers that patient records are safe and secure, stored according to NEN7510 and ISO27001 standards. We checked what that means across the EPD market, supplier by supplier. Location is not control.

Related article

What it really means to own your data

You cannot hold legal title to data. But strip ownership to its core and three rights remain: to possess, use, and dispose. Those you can hold, and that is data sovereignty.

Copyright 2026HOIST IT. All Rights Reserved