Your government data sits in a datacenter inside your borders. Here is why that protects you less than you think, and what actually does.
Joseph Paquin, MBA, CISSP, CGRC, PMP
On June 10, 2025, a Microsoft France executive sat before a French Senate commission of inquiry and was asked a direct question: could he guarantee that data belonging to the French government, held under national procurement contracts, would never be transmitted to the United States government?
His answer, under oath, was “No, I cannot guarantee it.” He added, and this is the part worth sitting with: “When we are obliged to provide them, we provide them.”
To his credit, he also said it had never happened. But “it has not happened yet” is a fact about the past. It is not a control.
I spent the last several months working through the peer-reviewed literature on digital sovereignty for a white paper aimed at state government technology leaders. That testimony is the single most useful thing I found. Not because it is scandalous, but because it is a clear, sworn answer to a question most public-sector buyers have never actually put to their vendors, and because it matches what the academic literature has been saying for five years, delivered by someone with every incentive to say otherwise.
The mechanism is corporate nationality, not geography
The Clarifying Lawful Overseas Use of Data Act of 2018 asserts jurisdiction over data in the “possession, custody, or control” of United States–headquartered providers, regardless of where that data physically sits. As Rojszczak laid out in Computer Law & Security Review, the test attaches to the provider’s corporate nationality. In-region storage by a US-controlled entity does not remove the data from US legal process, because the thing being compelled is the company, not the building.
This is why the residency conversation goes wrong. Data residency is a real control. It does useful work for latency, for certain regulatory regimes, for reducing the number of parties who touch a system. It is simply not a jurisdictional control, and it is routinely sold as one.
Chander made the sharper version of this argument in the Journal of International Economic Law shortly after the European Court of Justice invalidated Privacy Shield. Localization, he argued, cannot cure the defect the court identified, because that defect lay in the absence of proportionality limits and effective redress in US surveillance law, not in where the bits were stored. He went further, and this part should give pause to anyone drafting an in-state data residency mandate: localization requirements may increase aggregate surveillance exposure, by multiplying the number of jurisdictions holding local compulsion powers over the same records.
A European Parliament study published in late 2025 reached the same conclusion in blunter language. Data localization alone, it found, does not resolve exposure, because data stored in Europe by US companies remains subject to US jurisdiction. On vendor “sovereign cloud” offerings specifically, it observed that while infrastructure may be localized, ownership and legal accountability remain non-European, a pattern the experts it interviewed called sovereigntywashing.
The technical controls are better than the marketing and weaker than the claim
The standard vendor answer to all of this is a stack of technical controls: customer-managed keys, hold-your-own-key architectures, confidential computing, sovereign regions operated by local entities. These are not nothing. Some of them are genuinely impressive engineering.
But the peer-reviewed assessment is more skeptical than the datasheet. Sardar and Fetzer, reviewing confidential computing in Cybersecurity, found that the Confidential Computing Consortium’s own definitions conflict across its publications, that comparative security claims are made without stated threat models, and, most importantly, that side-channel attacks typically fall outside commercial trusted execution environment threat models.
That is not theoretical. CIPHERLEAKS (USENIX Security 2021) extracted private keys from constant-time RSA and ECDSA through a ciphertext side channel against AMD SEV. TDXdown (ACM CCS 2024) defeated Intel TDX’s single-stepping countermeasure on current Xeon Scalable processors. BadRAM (IEEE S&P 2025) showed that a cheap memory-aliasing setup with brief physical access compromises AMD SEV-SNP’s integrity guarantees and its attestation.
The through-line is that the privileged hypervisor remains inside the threat model. For a government buyer, that means the provider remains inside the threat model, which is precisely the party the sovereignty control was purchased to exclude.
Two things changed that make this urgent
I would not be writing this if the risk profile had held still.
Artificial intelligence. Production AI services now ingest government text by default, and the extraction literature has moved from research models to commercial ones. Nasr and colleagues, at ICLR 2025, recovered 27,171 unique verbatim-memorized training examples from an aligned, commercially hosted model for roughly two hundred dollars in queries. Separately, Staab and colleagues showed that large language models infer personal attributes from ordinary, non-identifying text at up to 85% top-one accuracy, and concluded that text anonymization and model alignment are currently ineffective as mitigations. If your agency’s mitigation is “we redact identifiers before submission,” that mitigation has been tested and it does not hold.
Meanwhile, NASCIO’s 2025 survey found 82% of states reporting daily employee use of generative AI, up from 53% a year earlier, against 25% with dedicated funding to govern it. The same survey found 92% of states relying on contractual terms to monitor third-party compliance and 22% conducting regular audits. A seventy-point gap between the control you claim and the control you verify is not a governance program.
Quantum computing. This argument is usually made badly. Someone asserts a date, everyone discounts it, nothing happens. The correct framing is Mosca’s inequality: take how long a record must stay confidential, add how long migration takes, and compare the sum to how long until a cryptographically relevant quantum computer exists. If the first two exceed the third, the record is exposed today, because an adversary collects ciphertext now and decrypts later.
Government is where this bites hardest, because retention is set by law and measured in decades. Court records, vital records, and capital case files carry horizons of fifty years, seventy-five years, or permanent. Against a permanent record, the inequality does not require any particular arrival date to be correct. The deadlines are no longer speculative either: NIST’s draft transition schedule deprecates today’s public-key cryptography after 2030 and disallows it after 2035.
Now the part that will cost me some readers
Everything above sounds like a case for pulling workloads out of hyperscale cloud and running them yourself. It is not, and I want to be direct about why, because I think this is where the sovereignty conversation most often goes off a cliff.
There is no peer-reviewed evidence that repatriation improves security outcomes. I searched for it specifically. The literature contains abundant work on migration to cloud and essentially nothing on reverse migration with measured cost or security outcomes; every retrievable source making repatriation claims was vendor or consultancy content. That absence cuts both ways: nobody has demonstrated the benefit, and practitioner confidence on this point rests on nothing.
The capacity evidence runs the other way. The 2024 Deloitte-NASCIO cybersecurity study found four states funding cybersecurity at 1% or less of their IT budget against a federal norm of 10–12%, median state CISO tenure of twenty-three months, and, decisively, 75% of states already outsourcing centralized security operations. Repatriation asks states to reverse a capability decision they made deliberately, for reasons that have not changed.
On quantum specifically, the hyperscalers are ahead of us, not behind. This is the finding that should most trouble anyone arguing for disaggregation. A measurement study accepted to the ACM Internet Measurement Conference examined more than two billion TLS handshakes across a million domains and found that 93.92% of observed post-quantum deployment came from infrastructure-provider-managed configurations, against 4.58% from owner-managed domains. Government services reached 38% adoption. Owner-managed domains across all categories stayed below 10%. A government organization that moves off a managed platform edge in the name of sovereignty statistically relocates itself into the cohort that has not migrated.
And Europe already ran the ambitious experiment. Gaia-X, launched to build a European federated cloud, structurally incorporated the same hyperscalers it was designed to displace; Baur’s analysis concludes it delivered “compliance by design” rather than independence. The EU’s cloud certification scheme stalled on precisely the sovereignty provisions that gave it purpose. European providers’ share of their own market fell to roughly 13% during the push.
What actually works
Sovereignty is a property of controls, contracts, and cryptographic custody, not of geography or ownership. That is not a rhetorical softening; it is what the evidence supports, and it has the practical advantage of being purchasable by an organization with no intention of building a datacenter.
The most useful artifact to come out of the European effort is a sentence. The European Commission’s Cloud Sovereignty Framework defines sovereign key management as the condition in which only the customer, not the provider, has effective control over cryptographic access. That is testable. It is auditable. It costs nothing to require. And it is the difference between a vendor telling you their cloud is sovereign and a vendor telling you who holds the keys.
Here is what I would do with it.
Start with two things that need no new authority.
Run a cryptographic inventory scoped by retention horizon. Identify every system holding records with a mandated retention period beyond fifteen years, and document the algorithms protecting them in transit, at rest, and in backup. Federal agencies have done this annually since 2022 under OMB M-23-02. Most states and most private organizations with long-lived records have never done it once. The UK’s National Cyber Security Centre allocates three years to discovery alone, with a 2028 deadline, which means this is a now problem, not a 2030 problem.
Attach a sovereignty schedule to your next renewal. Not a renegotiation. A schedule, applied at the natural contract event, requiring written answers to eight questions before signature:
- Jurisdiction. Which legal authorities can compel production of our data from you, your parent, your subsidiaries, or your subprocessors? What notice do we get, and what is your practice when notice is legally barred?
- Key custody. Do we hold key material such that only we have effective control over cryptographic access?
- Cryptographic horizon. What protects these records in transit, at rest, and in backup, and what is your post-quantum migration schedule?
- AI data flow. What of our data may be processed by AI services, what training and retention rights do you hold, which features are enabled by default, and where does inference compute occur?
- Operational access. Which of your personnel can reach our data, under what geographic and citizenship constraints, with what logging visible to us?
- Exit. What is the measured time and cost to move a defined workload out?
- Supply chain. Which subprocessors, at what tiers, touch our data, and do we have notice and objection rights on change?
- Compliance interlock. How does your answer interact with the regimes already binding on us: CJIS, IRS Publication 1075, HIPAA, FERPA, and the rest?
You do not need every answer to come back favorable. You need them documented, dated, and signed. A vendor that cannot answer these has not been asked, and in my experience most have not been asked.
Then do the two things that take longer.
Publish a post-quantum roadmap on the 2028 / 2031 / 2035 cadence (discovery complete, priority migrations executed, migration complete), and prioritize by retention horizon rather than by system criticality. A low-traffic records archive may outrank a high-traffic public portal.
Test one exit. Not a plan. An actual measured move of one defined workload, with the time and cost written down. The UK Competition and Markets Authority found in 2025 that fewer than 1% of cloud customers switch provider in a year. If you have actually done it once, you hold negotiating information almost nobody else has.
The point
Calcara, analyzing why European cloud policy kept failing at the union level while member states quietly did fine, offers the conclusion I keep coming back to: sovereignty in practice functions as leverage rather than as exit. The organizations that get something out of this are not the ones that leave. They are the ones that can specify, measure, and audit what they are buying, and who therefore have an exit credible enough that they never need to use it.
Data residency is worth having. It is just not the thing you think you bought.
Sources
- Sénat (France), Commission d’enquête sur la commande publique, compte rendu, 10 June 2025
- Rojszczak, M. (2020). CLOUD Act agreements from an EU perspective. Computer Law & Security Review, 38. doi:10.1016/j.clsr.2020.105442
- Chander, A. (2020). Is data localization a solution for Schrems II? Journal of International Economic Law, 23(3). doi:10.1093/jiel/jgaa024
- Gineikyte-Kanclere, V., et al. (2025). European software and cyber dependencies (PE 778.576). European Parliament. PDF
- Sardar, M. U., & Fetzer, C. (2023). Confidential computing and related technologies: A critical review. Cybersecurity, 6. doi:10.1186/s42400-023-00144-1
- Li, M., et al. (2021). CIPHERLEAKS. USENIX Security ’21. Paper
- Wilke, L., Sieck, F., & Eisenbarth, T. (2024). TDXdown. ACM CCS ’24. doi:10.1145/3658644.3690230
- De Meulemeester, J., et al. (2025). BadRAM. IEEE S&P 2025. doi:10.1109/SP61157.2025.00104
- Nasr, M., et al. (2025). Scalable extraction of training data from aligned, production language models. ICLR 2025.
- Staab, R., Vero, M., Balunović, M., & Vechev, M. (2024). Beyond memorization: Violating privacy via inference with large language models. ICLR 2024. OpenReview
- Mosca, M. (2018). Cybersecurity in an era with quantum computers: Will we be ready? IEEE Security & Privacy, 16(5). doi:10.1109/MSP.2018.3761723
- NIST. (2024). Transition to post-quantum cryptography standards (NIST IR 8547 ipd). doi:10.6028/NIST.IR.8547.ipd
- Wickramasinghe, N., Li, F., Jha, S., & Shaghaghi, A. (2026). Mind the gap: Policy vs reality in post-quantum TLS deployment. ACM IMC 2026. arXiv:2607.29005
- Deloitte & NASCIO. (2024). 2024 Deloitte-NASCIO cybersecurity study. Report
- NASCIO. (2025). The 2025 state CIO survey. PDF
- Baur, A. (2026). European ambitions captured by American clouds: Digital sovereignty through Gaia-X? Information, Communication & Society, 29(2). doi:10.1080/1369118X.2025.2516545
- Calcara, A. (2026). European cloud computing policy: Failing in Europe to succeed nationally? West European Politics, 49(4). doi:10.1080/01402382.2025.2491962
- European Commission. (2025). Cloud Sovereignty Framework v1.2.1. PDF
- Competition and Markets Authority. (2025). Cloud services market investigation: Final decision report. PDF