What is data sovereignty?

Data sovereignty is the principle that data is subject to the laws of the country where it is held and of the countries whose laws bind the companies that operate it, and that its owner keeps control over who accesses it, where it goes and how it leaves.

Written by Ugo Balducci. Last updated

Data sovereignty means two things at once. Your data answers to the laws of the country where it is stored, and to the laws of every country that can give orders to the companies running it. And you, not your provider, decide who reads it, where it goes and how it leaves. Where the data sits is only the first half of the answer; who operates it, and whether you can walk away with it, is the second.

For the Swiss view of the same question, with the nLPD, the GDPR and a checklist of questions to put to a provider, read the Swiss buyer’s guide to data sovereignty.

What data sovereignty means

Data sovereignty is about control and law. It asks two questions: which legal systems can reach your data, and who decides what happens to it. The first depends on where the data sits and on the companies that operate the servers, the software and the network around it. The second depends on your contracts, your access rules and whether you can take the data elsewhere.

In practice, the word breaks down into four checks:

  1. Location. In which country are the machines, the backups and the logs?
  2. Jurisdiction. Under whose law does each company in the data path operate, and which authorities can order it to disclose data?
  3. Control. Who holds the encryption keys, who can log in, and who approves a change?
  4. Portability. Can the data and the software move to another provider or to your own servers without the current provider’s goodwill?

It is wider than data residency. Data can sit in a Swiss datacentre and still be reachable by a foreign authority if the operator answers to that authority, as the CLOUD Act shows for US providers. It can also sit in the right country and still be hard to move if it lives in a proprietary format, which is vendor lock-in.

Data sovereignty, data residency and data localisation

The three terms are often used as if they meant the same thing. They answer different questions.

Data residency Data localisation Data sovereignty
What it is Where data is stored and processed A legal rule that data stay inside a country Which laws reach the data, and who controls it
Who sets it You, a contract or a policy A legislator or regulator Your choice of operator, contract and software
Main question In which country is every copy? Is storage abroad allowed at all? Who can be compelled, and can you leave?
Covers the operator’s nationality No Rarely Yes
Covers the right to leave No No Yes

Residency is a fact about location. Localisation is a legal obligation about location: some countries require certain categories of data, or a copy of them, to stay within their borders. Switzerland has no general localisation rule; the Swiss data protection act allows data to go abroad under conditions, and sector rules add their own limits. Sovereignty includes residency, and goes on to ask who operates the data and whether you keep the means to move it.

The laws involved

No single law defines data sovereignty. It is the sum of the rules that decide where data may go and who can demand it. For a Swiss or European organisation, these are the ones that come up most often.

  • The Swiss Federal Act on Data Protection. The revised FADP (SR 235.1), known as the nLPD in French, has applied since 1 September 2023. It lets you entrust processing to a processor under article 9 and allows disclosure abroad under article 16 to countries the Federal Council lists as adequate, or with safeguards such as standard contractual clauses.
  • The EU General Data Protection Regulation. The GDPR applies to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour there. Its Chapter V governs transfers out of the EU. The European Commission has recognised Switzerland as adequate since its 2000 decision.
  • The US CLOUD Act. The Clarifying Lawful Overseas Use of Data Act of 2018 lets US authorities require a provider under US jurisdiction to disclose data in its possession, custody or control, wherever it is stored (18 U.S.C. § 2713).
  • Section 702 of FISA. Section 702 of the US Foreign Intelligence Surveillance Act lets US intelligence agencies compel US electronic communication service providers to assist in targeting people who are not US persons and are outside the United States.
  • The Swiss-US Data Privacy Framework. Recognised by the Federal Council from 15 September 2024, it lets personal data flow to US companies certified under the Data Privacy Framework without further safeguards. It governs transfers; it does not change the reach of the CLOUD Act or FISA.
  • Secrecy and sector rules. Professional secrecy under article 321 of the Swiss Criminal Code, banking secrecy under article 47 of the Banking Act, FINMA’s outsourcing expectations, set out in its circulars, and cantonal rules for public bodies all weigh who operates the data, not only where it sits.

The Federal Data Protection and Information Commissioner supervises the Swiss rules and publishes guidance on disclosure abroad. This page is general information, not legal advice.

Examples

Three situations show how the parts fit together.

  • Resident but not sovereign. A Swiss organisation keeps its files in a Zurich region of a US-owned cloud. The data is resident in Switzerland. Because the provider answers to US courts, a CLOUD Act order can still reach it, so the organisation has residency without full sovereignty.
  • Sovereign location, weak exit. A Swiss provider hosts a proprietary application in Geneva. Location and jurisdiction are both Swiss, but the data comes out only as an export the vendor designed, and the software cannot run anywhere else. Leaving means a migration project, so control is limited.
  • Sovereign on all four checks. An open-source application runs on dedicated machines in Switzerland, operated by a Swiss company, with the keys, the access log and the exit plan written into the contract. The data is resident, the operator is outside direct foreign reach, and the same software can run on your own servers tomorrow.

Why it matters when choosing where software runs

When you pick a SaaS product or a cloud platform, you also pick its owner, its sub-processors and its governing law. For a public body, a hospital, a law firm or an international organisation, that choice decides whether you can meet your own legal and contractual duties. A sovereignty review looks at the whole path: the operator, the hosting provider, the edge network, the identity provider, error reporting and any AI service in the loop.

How Pilae handles it

Pilae SA is a Swiss company in Lausanne with no US parent, operating under Swiss law. Your apps run on your premises, on dedicated machines in any of 12 Pilae Cloud regions, six of them in Switzerland and the EU, in a hybrid of both, or air-gapped. The worldwide regions exist for teams that need them, but a workload placed in a US region is stored in the US and subject to US law on data held there. Every app in the catalogue is open source or source-available, so your data stays in formats other tools can read.

Every plan includes the standard DPA, with advance notice of any sub-processor change, audit rights, an audit trail you can export to your SIEM, and a written exit plan. We show you where US companies still sit in the data path and how to keep them out; the details are on the jurisdiction page.

Common questions

Is data stored in Switzerland automatically sovereign?

No. Storage in Switzerland settles residency. If the operator, or a company that controls it, answers to a foreign authority, that authority can still order it to hand the data over. Sovereignty also needs the right operator and a way to leave.

Is data sovereignty the same as data residency?

No. Residency is where the data is. Sovereignty covers residency and adds jurisdiction, control and portability.

Does Swiss law require data to stay in Switzerland?

Not in general. The FADP allows disclosure abroad to adequate countries, which include the EU and EEA states, and elsewhere with safeguards. Professional secrecy, banking rules, cantonal law or a client contract can narrow that for specific data.

Does encryption make data sovereign?

It helps when you hold the keys and the provider cannot read the data. If the provider manages the keys, it can be ordered to decrypt, so encryption narrows the exposure without removing the question of who operates the service.

Related on this site

Tell us what you need to run.

Thirty minutes with an engineer, a written plan and a fixed price for the first workload.