Data residency
Where your data physically sits. It is a necessary question and a long way from a sufficient one, because location is a weak proxy for control.
A Dutch data centre operated by a US-headquartered provider is still reachable under US law, so residency answers where the data is and leaves open who can compel access to it.
Data residency is the most over-trusted idea in the field. It is easy to verify, easy to put in a brochure and it feels like an answer. It usually is not one.
Residency tells you where the bytes rest. Sovereignty asks who can act on them. The two come apart the moment the operator of a facility, or its parent company, sits under a different legal regime than the flag on the building. Where your data sits and who can reach it are separate questions, and only the second one is about control.
This is not theoretical. A census of Dutch mental-healthcare record systems found that many run on, or point to, US hyperscaler clouds, even where the marketing implied a domestic home. The lesson generalises: treat residency as one input among several, and never mistake it for proof of control.
Common misconceptions
Our data is in an EU data centre, so it is sovereign.
Residency fixes the postcode. Who operates the facility, whose law reaches the operator, who holds the keys and whether you could leave are all separate questions, and they are the ones that decide control.
A hyperscaler EU region removes foreign legal exposure.
Jurisdiction follows the corporate control chain, not the map. An EU region of a US-parented provider can still fall under extraterritorial law.