The term "data sovereignty" has become a procurement checkbox: "Is your data stored in the EU?" The answer "yes" satisfies the checkbox. But data stored in the EU is not the same as data sovereign in the EU. Storage location is one attribute; access control, processing jurisdiction, and legal vulnerability are equally important.

Sovereignty is about access, not location. Data stored in a Frankfurt data center is not sovereign if the cloud provider is subject to US jurisdiction under the CLOUD Act, if the encryption keys are managed by a US-registered key management service, or if the administrative console can be accessed from outside the EU without additional authentication. Sovereignty requires that the entity with legal jurisdiction over the data matches the entity that controls access to the data.

The architectural implications. Sovereignty by design means: encryption keys are managed by a jurisdiction-appropriate service; administrative access requires jurisdiction-appropriate authentication; data processing occurs within the jurisdiction; and audit logs are stored within the jurisdiction and are not accessible from outside it without legal process. These are not optional features—they are architectural constraints that affect every component from the database to the monitoring stack.

The EU context. EU procurement directives and national data localization laws increasingly specify not just storage location but processing location and administrative access controls. TED tenders for sensitive data systems—health, defense, financial—specify these requirements explicitly. Organizations that treat sovereignty as a storage location will pass the initial evaluation but fail the technical audit.

The US context. FedRAMP High and CMMC Level 3 impose similar requirements from the US perspective: data must be processed within US borders by US-cleared personnel. Organizations serving both markets need dual-sovereignty architecture—separate infrastructure stacks, separate administrative domains, separate compliance certifications.

Retrofitting sovereignty is expensive because it requires re-architecting systems that were designed without jurisdictional boundaries. Building it from the start adds complexity to the initial design but saves orders of magnitude in compliance costs down the line. The question is not whether to invest in sovereignty—it is whether to invest early in architecture or later in remediation.