Do You Know Who Can Access Your ‘EU Region’ Data?

Most teams that pick an “EU Region” can’t answer that. They know where their data sits. They don’t know which government can force their provider to hand it over.

TL;DR

Choosing an “EU Region” tells you where your servers sit, not which legal system can reach your data. That gap sits at the center of the EU data sovereignty debate. It’s also why Leaseweb’s own Co-CEO joined 24 other industry leaders in warning EU regulators about it.

We’re writing about this because of the confusion it constantly causes with prospective customers: treating “EU Region” as a compliance answer when it’s really just about location. What needs protecting, and whether you already know where it lives, matters more than which region you pick.

Imagine a foreign government serves your primary cloud vendor with a warrant tomorrow morning. Would you know today which of your workloads would actually be at risk?


The gap between location and EU data sovereignty

Under the US CLOUD Act, US law enforcement can compel a US-headquartered provider to hand over data in its possession, custody, or control. That holds regardless of where the data physically sits, as long as a US court issues the warrant [1].

The law exists because of a real dispute. In 2018, Microsoft argued a US warrant shouldn’t reach emails stored on a server in Ireland. Congress settled the question before the Supreme Court could. It made clear that physical location doesn’t put data outside US legal reach if the provider itself is a US company [2].

That’s the mechanism sitting underneath every “EU Region” checkbox on a non-European cloud platform. The data center is real. The physical location is real, too. But the corporate entity that operates it, and the legal system it answers to, hasn’t necessarily changed.

Most coverage stops there. It treats jurisdiction as a probability question: how many EU regions have this problem, how likely is enforcement, how worried should you really be. We believe that framing undersells it. This isn’t a percentage.

A US-incorporated parent company operates every AWS, Azure, or Google Cloud region branded “EU” or “sovereign.” That means the CLOUD Act applies to all of them, not just some. There’s no version of “our EU region is different” that changes which country the parent company answers to. It’s a property of the corporate structure, and it’s the same for all of them.


Not just an industry warning

Major hyperscalers have leaned into this in recent months, launching regions explicitly branded as “sovereign” or “European,” physically isolated within EU borders. The industry has a name for the risk this creates.

On March 17, 2026, 25 CEOs of European cloud and digital service providers sent a joint letter to the European Commission’s Executive Vice-President for Tech Sovereignty. Coordinated through Cloud Infrastructure Services Providers in Europe (CISPE), the letter warned about “sovereignty-washing.” That’s the incoming Cloud and AI Development Act (CADA) letting providers apply the sovereign label more loosely than the legal reality supports [3]. Svenja de Vos, Leaseweb’s own Co-CEO, is one of the 25 signatories [3a]. This isn’t a claim we’re citing secondhand. It’s a position our own leadership put their name to.

It isn’t an isolated position at Leaseweb, either. In a Computable.nl interview, Jan Willem des Tombe, Leaseweb’s Global Strategic Relations Director, made nearly the same argument in a different context. He said the common assumption, that physical server location measures sovereignty, overlooks what actually determines it: ownership, legal structure, governance, and contractual terms.

He also pushed back on a claim some vendors make, and one we’ve avoided making here: that 100% autonomy is achievable. In practice, he said, there’s almost always a non-European link somewhere in the chain [7]. Two Leaseweb executives made the same argument independently, in two separate public statements this year. That’s a stronger signal than either argument alone.


What the EU itself is trying to fix

CADA aims to address exactly that concern, though it’s worth being precise about where things stand. The European Commission adopted its CADA proposal on June 3, 2026 [4]. Parliament and the Council haven’t enacted it yet, and it still needs their negotiation before it takes effect.

It proposes four tiers of “Union assurance levels.” Public sector procurement would then depend on how much genuine sovereignty a provider can demonstrate, not just where its data centers sit [5].

Separately, a small group of AI researchers and think-tank contributors published a widely discussed scenario in June 2026, “Europe 2031” [6]. It argues that Europe’s failure to build independent computing infrastructure could leave the region dependent on foreign powers within years. It’s a story-like warning rather than a formal research study, a thought experiment rather than a forecast. But it’s the kind of thought experiment that has shaped real conversations in Brussels this year.


What structural sovereignty looks like

Selecting an EU Region on a non-European platform checks the box on server location. It doesn’t necessarily satisfy a legal team asking whether a foreign warrant could reach that data. That gap is often where AI roadmaps stall: a compliance review that can’t get a straight answer about jurisdiction, not the technology itself.

Choosing a provider that’s governed entirely from within the EU gives your legal team a clearer question to answer. That’s usually where roadmaps start moving faster.

Leaseweb has operated as separate, distinct national entities since 1997, with our global headquarters in Amsterdam governing that structure. We also contribute to broader efforts like the European Cloud Campus, an EU-backed initiative to build sovereign European cloud infrastructure. The distinction that matters isn’t which country hosts the hardware. It’s which legal jurisdiction the entity that operates it answers to. That’s what determines which court can compel a provider to hand over your data, and under what law.

This isn’t just Leaseweb’s own framing. AFAS Software, a Dutch enterprise software company, processes payroll for roughly 3.8 million employees every month through its ERP and HR platform. It hosts that platform, AFAS Online, with Leaseweb. Doing so keeps data and infrastructure within Europe and under European law, with no dependency on parties outside the EEA [8]. AFAS stated jurisdiction, not just location, as a condition of doing business with a hosting partner.

Sovereignty claims that hold up on a marketing page but not under a legal team’s actual question are just branding. That’s the distinction worth insisting on before you sign, not after.


Where this leaves you

Imagine a foreign government serves your primary cloud vendor with a warrant. Some of what you run wouldn’t matter, such as a marketing site or public documentation. Some of it would matter enormously: customer data, training data with real competitive value, or anything regulated.

The question worth sitting with isn’t whether to move everything. It’s whether you already know which category each workload falls into. And whether the entity handling it answers to a jurisdiction you chose on purpose, or one you inherited by default.

It’s the same infrastructure decision either way, made deliberately or made by default.

For more on how sovereignty and resilience work together in practice, see our related article on data sovereignty and resilience.

Here’s where to start.

Explore Sovereignty at Leaseweb

Leave a Reply

Your email address will not be published. Required fields are marked *