Sovereignty
The CLOUD Act and your data warehouse: why an EU region is not EU jurisdiction
Choosing the Frankfurt region does not put your analytics outside US legal reach. Here is what actually determines jurisdiction, and the five questions that settle it for any vendor.
Most teams that set out to “make our data platform GDPR-safe” solve it by picking an EU
region. Frankfurt instead of Virginia, Amsterdam instead of Oregon. The data is physically
in Europe, the console says eu-central-1, and the ticket gets closed.
That solves data residency. It does not touch jurisdiction, and the two are not the same thing. Jurisdiction is the question your DPO, your DORA filing, and increasingly your procurement team are actually asking.
What the CLOUD Act does
The Clarifying Lawful Overseas Use of Data Act (2018) settled a question US courts had been arguing about for years: can US authorities compel a US provider to hand over data stored abroad? The answer it gave was yes. A provider subject to US jurisdiction must produce data in its “possession, custody, or control” regardless of which country the disk is in.
The operative word is provider, not server. The trigger is the company’s legal personality — where it is incorporated, who ultimately controls it — and not the coordinates of the building. Moving the bytes to Frankfurt changes the postal address of the hardware. It does not change who the company is.
This is why the “sovereign region” offerings from the large US platforms are a narrower promise than they sound. They are real engineering — separate entities, EU-resident staff, isolated control planes — and they meaningfully raise the bar. But the parent company remains a US person, and the corporate group remains within reach.
In 2025, Microsoft’s French subsidiary was asked at a French Senate hearing whether it could guarantee that data belonging to French public-sector customers would never be transferred to US authorities. It could not give that guarantee. That exchange did more to move European procurement than any white paper, because it came from the vendor rather than from a competitor.
Why analytics is the sharpest case
There is a reason sovereignty arguments land harder on the warehouse than on, say, the CDN.
Your analytical store is where the joins happen. Individually innocuous tables become, after a few joins, a rich behavioural picture of identifiable people — customers, employees, patients, citizens. The warehouse is also where the history lives: you deliberately keep years of it, long after the operational systems have forgotten.
So when you assess transfer risk under Schrems II, the warehouse is the worst-case system by construction. It holds the most linkable data, for the longest time, in the most queryable form.
There is a second wrinkle specific to cloud data platforms: the control plane. A warehouse is not just storage. It is metadata, query plans, credentials, audit trails, and the orchestration that starts and stops compute. Storage can be pinned to a region far more easily than a control plane can, and a control plane that runs elsewhere still sees table names, column names, query text, and usage patterns. When you evaluate a platform, ask where the control plane runs — not just where the data sits. Vendors answer the storage question readily and the control-plane question reluctantly, which tells you something.
Five questions that actually settle it
Residency questions get you brochure answers. These get you facts:
- Which legal entity signs the contract, and where is it incorporated? Not “which region”, not “which data centre” — which company. Then: who owns that company, all the way up?
- Where does the control plane run? Metadata, query text, credentials, audit logs. Get it in writing, per subsystem.
- Who can access the data in the course of support? Name the countries the support staff sit in and the countries of any subprocessors. A German data centre staffed by an on-call rota in Seattle is a transfer.
- What happens on a lawful foreign order? Not “we would resist” — what is the documented process, is there a transparency report, and can the vendor state plainly that it is not subject to the order in the first place?
- What is the exit? Open formats, documented export, no egress penalty. Sovereignty that you cannot leave is just a different lock-in. The EU Data Act’s cloud-switching provisions exist precisely because this was the weak point.
If a vendor answers question 1 with a region name, you have learned the answer to question 1.
What sovereignty is not
Sovereignty is not a compliance certificate. No architecture makes you GDPR compliant. GDPR obligations sit with the controller — that is you. What a sovereign architecture does is remove one specific, well-documented category of transfer risk from your assessment, and give you tools (audit logs, a Record of Processing Activities, a residency attestation) to evidence the rest. It shortens the assessment; it does not replace it.
Sovereignty is not automatically better software. A European vendor that loses your data is worse than a US vendor that does not. Jurisdiction is one axis on the scorecard, alongside durability, performance, and whether the company will still exist in five years. Airbus, whose 2026 cloud tender made protection from extraterritorial law an explicitly scored criterion, scored it alongside technical capability rather than instead of it. That is the right shape.
Where this is going
The direction of travel is not subtle. Gartner puts worldwide sovereign cloud spending at around $80 billion in 2026, with European sovereign IaaS growing about 83% year over year. The European Commission awarded a €180 million sovereign cloud framework in April 2026 and published a Cloud Sovereignty Framework with graded SEAL levels, which means buyers now have a shared vocabulary instead of each writing their own definition. DORA is in force for financial entities, and it asks pointed questions about concentration risk in third-party providers.
None of that will displace the hyperscalers at an aggregate level, and anyone telling you otherwise is selling something. What it does is make the sovereignty question a normal line item in procurement rather than an ideological one — and for a warehouse, it is a line item with an unusually clear answer.
Molinia is an EU-sovereign OLAP platform. Warehouse compute runs in Amsterdam on Leafcloud; the control plane runs on EU-owned infrastructure under EU jurisdiction. This article is written for practitioners and is not legal advice — talk to counsel about your own transfer assessment.