Where data is physically stored is only one part of the sovereignty question. Nicole Reader, Head of Technology Solutions & Delivery at The Bunker, explores why corporate ownership, legal jurisdiction and access rights matter just as much.
When data sovereignty comes up in boardrooms – and it is coming up increasingly often – the instinctive response from many organisations is to ask where their data is. Which country? Which region? Which data centre postcode?
That is understandable. However, it is not the only question organisations should be asking.
Data location and data sovereignty are not the same thing. Conflating the two is not just a semantic error; it can also be a strategic one, leaving UK businesses exposed in ways they may not fully appreciate until a problem arises.
The terms are not interchangeable
Data residency refers to where data is physically stored. Data sovereignty refers to who holds the legal authority to govern and access that data. Geography and jurisdiction are related, but they are not identical, and the gap between them has become a significant operational risk.
The clearest example is the US CLOUD Act. Enacted in 2018, this legislation gives US authorities the ability to compel US-headquartered technology companies to produce data, regardless of where it is physically located. If a provider is a US-incorporated entity, the data it holds may therefore be subject to US legal authority even if it never leaves a UK data centre.
For organisations subject to UK GDPR, this can create a direct tension: a US warrant compelling disclosure may conflict with UK data protection requirements, potentially exposing businesses to regulatory action and fines of up to 4% of global annual turnover.
Data sovereignty is rapidly climbing the list of strategic priorities. According to recent research, 73% of UK IT leaders now cite it as a key concern, up from 61% just a year earlier. What often lags behind is a clear understanding of what sovereignty actually requires.
The comfortable assumption
Many organisations have assumed that selecting a provider with a UK presence, or a UK region option, is sufficient to ensure UK control. That assumption may not always hold.
Legal jurisdiction over data is not determined solely by the physical location of the infrastructure. The provider’s corporate structure, contractual arrangements and cross-border processing activities can also be relevant. A data centre in London operated by a company headquartered in Seattle may provide UK residency, but that does not necessarily amount to UK sovereignty.
According to the UK Government’s Business Data Survey 2025–26, 86% of UK businesses handle digitised data, while 31% rely primarily on public cloud for storage. Yet many boards may not have mapped the legal and jurisdictional implications of those choices with the same rigour they apply to financial risk.
How cloud convenience created a sovereignty blind spot
The result is a landscape in which data has been distributed widely, often for sensible operational reasons, but without a holistic understanding of the sovereignty implications.
Research shows that 96% of UK IT leaders recognise the need to retain access to their data, while 85% cite compliance with multi-jurisdictional regulations as a priority concern. Yet intent and action remain disconnected: 66% would consider switching cloud providers to regain control, but only 15% have done so – a 51-point gap between stated priority and action.
The instinct to bring data back onshore, particularly in government, defence and regulated sectors, is understandable. But domestic hosting does not automatically resolve the sovereignty question.
Local does not necessarily mean secure. If data is brought back onshore but is not properly segregated, monitored and protected, the sovereignty objective may still be undermined. Geographic control without operational security offers limited benefit. For most organisations, wholesale repatriation is also unlikely to be either practical or advisable.
What boards need to be asking
Data sovereignty is no longer solely a technical matter for IT teams to manage. It is also a board-level risk question. Directors need to understand where critical data is stored, where it is processed and which legal regimes may be able to assert authority over it.
Every organisation should be putting direct questions to its providers: under what circumstances could a foreign authority compel you to hand over our data? Who has access to our environment, and how is that access controlled and segregated? What does our exit look like, and how is data returned and deleted at the end of the contract?
These are not adversarial questions. They are part of effective governance and due diligence.
A more mature conversation
The goal is not to retreat from cloud services or global platforms; it is to engage with them on informed terms. The right infrastructure strategy will depend on the sensitivity of the data, the applicable regulatory framework and the organisation’s risk appetite.
For many organisations, this may result in a hybrid approach, with different workloads and datasets treated according to their individual requirements rather than being governed by a single infrastructure policy.
Many UK businesses may have distributed more control over their data than they realised, while relatively few will have stress-tested those decisions against today’s geopolitical and regulatory realities. Addressing that starts with asking the right question: not only where is our data, but who can control and access it?

