What is data sovereignty, and why does it matter for your photos?

What is data sovereignty, and why does it matter for your photos?

Data sovereignty appears in almost every privacy policy and marketing page you read. Cloud providers reference it. Governments use it in legislation. Startups build entire brands around it. But when you ask three people what it means, you tend to get four different answers.

That is a problem, because the term does carry a specific meaning, and the difference between the technical definition and the marketing version is the difference between real protection and a legal loophole.

What data sovereignty actually means

Data sovereignty is the principle that data is subject to the laws of the country in which it is physically located. If your photos are stored on servers in Germany, German law applies to them. If they are stored in Ireland, Irish law applies. And because Ireland and Germany are both EU member states, EU regulations such as the GDPR govern how the data can be collected, processed, and shared.

The concept sounds straightforward. In practice, it is complicated by three things that most privacy pages do not spell out.

The three layers of sovereignty

To understand whether a service actually offers data sovereignty, you need to look at three separate questions.

Where does the data physically live? This is the layer most people focus on. If a service says “data stored in the EU”, it usually means their servers sit in an EU data centre. This is necessary, but not sufficient.

Who operates the infrastructure? The physical server may sit in Frankfurt, but if it is operated by a US cloud provider, the operator is bound by US law. When the US government issues a request, the operator responds, regardless of where the machine happens to be.

Where is the company incorporated? This is the layer that determines which laws the company itself must follow. A company incorporated in California is subject to US law, including the CLOUD Act, no matter where its servers or its customers are located.

For data sovereignty to hold, all three layers need to align. The server must be in the relevant jurisdiction, the operator must be subject to that jurisdiction’s law, and the company must not be legally compelled to comply with a foreign government’s requests.

Why “stored in the EU” is not enough

The gap between the marketing claim and the legal reality became clear with a 2020 court ruling known as Schrems II. The Court of Justice of the European Union found that the transfer of personal data from the EU to the US did not adequately protect Europeans from US surveillance laws, even when the data itself never crossed the Atlantic.

The court’s reasoning was direct. If a US company holds the data, US law reaches it, wherever the servers are. Storage location alone does not determine which laws apply.

This is why “hosted in the EU” is a common phrase and a weak claim. It only addresses the first of the three layers. Without the other two, the protection it implies does not hold.

What the CLOUD Act changes

The US CLOUD Act was passed in 2018. It gives US authorities the power to compel US-based companies to hand over data they hold or control, regardless of where that data is physically stored.

This means a US cloud provider operating servers in the Netherlands can be legally required to hand over data stored on those servers to US authorities. The Dutch government does not need to be informed. The affected user does not need to be notified. The data protection guarantees of the GDPR do not override the request.

The GDPR limits what companies do with your data on their own initiative. The CLOUD Act permits a specific external actor to override that. Both laws are in force at the same time, and they point in opposite directions.

Our colleague has written a more detailed explanation of how the CLOUD Act works and what it means for photo storage.

What EU data sovereignty actually requires

For a service to offer genuine EU data sovereignty, three conditions have to be met.

The data must be stored on servers located inside the EU. The infrastructure operator must be subject to EU law. The company that owns the service must be incorporated in the EU and free of US parent-company control.

When all three are true, the service is governed by EU law, and only EU law. A US government request has no legal path to the data.

When any one of these is missing, the sovereignty claim is partial. It may still offer improvements over other options, but it does not offer the protection that the phrase implies.

Why this matters for your photos

Photos are one of the most personal categories of data you upload anywhere. They contain your face, the faces of the people close to you, the places you go, and the timestamps of your daily life. The metadata article covers exactly how much information a single photo file carries.

When you choose where to store that library, the sovereignty question is not abstract. It determines who can compel access to those photos, under which legal framework, and with what recourse.

What PixelUnion does

PixelUnion is incorporated in the EU. Our servers are located in the EU. Our infrastructure is operated under EU law. There is no US parent company, and no legal path by which the CLOUD Act reaches our customers’ data.

This is not a marketing decision. It is a structural decision about what “stored in the EU” needs to mean if the phrase is to be honest.

The GDPR article covers the rights the regulation gives you and how they apply in practice. Data sovereignty is the underlying condition that makes those rights enforceable in the first place.


Want to see how EU sovereignty translates into a working alternative to US-based services? Our colleague has put together a practical guide on switching away from Big Tech entirely, with concrete alternatives for every service.