Data sovereignty: your data in the EU, not outside your control
Sovereign data in the EU, with no access under the US CLOUD Act. We run our private cloud in a data centre located in the Czech Republic, under the jurisdiction of an EU member state.
Book a consultationWhat data sovereignty actually means
Data sovereignty answers one practical question: who holds real control over your data, and under which law is access to it decided. That is not the same as where the server happens to stand.
Where the data physically sits
Data residency describes the geographic location of storage only. It tells you that your data is in Frankfurt, Amsterdam or Prague. It says nothing about who can be legally compelled to hand the data over, or under which legal system such an order is assessed.
Whose law applies to the data
Data sovereignty covers the provider's jurisdiction, its ownership structure and the law governing the contract. Only this combination determines who has real access to your data and which non European rules can reach the provider.
Why data location alone is not enough
Companies often ask whether it is enough that a provider runs a data centre inside the European Union. The answer is factual: under the GDPR the location of the server is not what matters, what matters is whether third country law reaches the provider. A data centre in the EU does not protect you if the operator is owned by a US parent company.
The GDPR applies identically across the EU
The GDPR is a regulation, a directly applicable act with the same wording in every member state. Processing data in the Czech Republic is processing inside the European Union. It is not a transfer to a third country, so no standard contractual clauses and no supplementary measures under Schrems II are required.
A Czech limited company is not subject to the US CLOUD Act
Your Technology is a Czech limited company incorporated under Czech law with no US parent. The US CLOUD Act applies to providers subject to United States jurisdiction. The European arms of the US hyperscalers (Microsoft, Amazon Web Services, Google) are subsidiaries of US corporations, so that jurisdiction reaches them even when the data physically sits in a data centre inside the European Union. What decides the question is control over the provider, not the location of the server.
A contract governed by the law of an EU member state
The service agreement, the SLA and the data processing agreement under Article 28 GDPR are governed by the law of an EU member state, and jurisdiction stays inside the EU. You enforce your claims in a European legal environment, not through a foreign entity of a global group.
Often a lower total cost at the same compliance level
Operating costs in the Czech Republic are typically lower than at comparable providers in Western Europe, while the legal framework is identical. You usually pay less for the same level of GDPR protection, without compromising on jurisdiction.
- Data in a data centre inside the EU
- The operator is a subsidiary of a US corporation
- Subject to the US CLOUD Act even with data stored in the EU
- Contract terms follow the rules of the global group
- Data in a data centre in the Czech Republic
- Ownership structure and registered office inside the EU
- Not subject to the US CLOUD Act or FISA 702
- Contract and SLA under the law of an EU member state
How we handle it
We do not simply declare sovereignty, we build it into the architecture of the service. Here is what that looks like in our private cloud in practice.
- Infrastructure operated in the data centre in the Czech Republic
- The data centre meets the Tier III standard (99.98 % availability)
- Data never leaves the European Union, backups and replicas included
- The service is operated by Your Technology, a company under Czech law
- Dedicated resources and full isolation from other customers
- Data centre operational and security standards follow the ISO 27001 and ISO 27017 family
- Access to data only on a contractual basis and through controlled roles
- A data processing agreement under Article 28 GDPR as part of the delivery
- Data export in standard formats at any time during the contract
- Documented deletion of data once the engagement ends
Related legislation, in brief
The four rules that come up most often in any discussion of data sovereignty, and why they are relevant.
GDPR (General Data Protection Regulation)
Sets the rules for processing personal data across the European Union. A transfer to a third country requires a specific legal basis. Processing inside the EU does not need one.
Schrems II
A Court of Justice of the EU ruling that invalidated the Privacy Shield and tightened the conditions for transferring personal data to the United States. It stressed that the real access of third country authorities to data must also be assessed.
US CLOUD Act
Allows US authorities to request data from providers subject to US jurisdiction regardless of the country where the data is stored. The status of the provider is therefore what counts, not the location of the server.
FISA 702
The legal basis for surveillance of communications of persons outside the United States through US electronic communication service providers. It was one of the main grounds for the criticism in the Schrems II ruling.
This summary is provided for general orientation and does not constitute legal advice. Please discuss the specific situation of your organisation with your legal counsel or data protection officer.
What companies ask us most often
Where exactly is our data stored?
Your data is physically stored in the data centre in the Czech Republic, that is, inside the European Union. Backups and any replicas stay in the EU as well. We never move customer data to non European cloud platforms without your explicit consent.
Are you subject to the US CLOUD Act?
No. Your Technology is a limited liability company incorporated under Czech law, with no US parent and no entity subject to United States jurisdiction. The US CLOUD Act reaches providers under US jurisdiction, which is not our case.
Is the Czech Republic enough for GDPR compliance?
Yes. The GDPR is an EU regulation and applies in every member state with the same wording. Processing data in the Czech Republic is processing inside the EU, so it is not a transfer to a third country and no supplementary measures under Schrems II apply.
How is this different from a US provider's data centre in the EU?
The difference is not the location of the data but the jurisdiction of the operator. The European arm of a US hyperscaler is a subsidiary of a US corporation, so the US CLOUD Act reaches it even when the data sits in a data centre inside the EU. With a provider that has no US ties, that legal basis for compelling disclosure simply does not exist.
What if we want to export or delete our data?
We will provide a data export in standard formats at any point during the contract. Once the engagement ends we delete the data according to the agreed procedure, including backups within the agreed retention period, and we document the deletion for you.
Can we audit the operation?
Yes. The scope of audit rights, reporting and cooperation is agreed in the service contract and in the data processing agreement under Article 28 GDPR. We provide evidence on data location, on the roles with access and on operational and security measures.
Want to see what sovereign operations would look like for you?
We will walk through your current environment, the jurisdictional risks and your migration options. No obligation and no marketing talk.
Book a consultation