Skip to content
Woman with a laptop walking past the server racks of a data centre
Knowledge base

Data sovereignty: where is your data, really?

Tom Frohn Co-founder of Optilise
3 min read

Data sovereignty means your organisation decides which laws your data falls under, who can reach it and what happens to it, regardless of the data centre where that data physically sits. Suppliers usually answer a different question: which country the servers are in. But a copy of your entire business can sit near Amsterdam and still fall under US law, because the supplier is American.

Until a few years ago that was a detail for the IT department. Now that digital access can be cut off overnight by a decision in another country, it is a board question. And nowhere does that question get sharper than in your BI environment, because that is where a copy of everything comes together.

What is data sovereignty?

The term is used in three ways, and suppliers profit from that.

  • Data residency is the physical location: the data centre where your data sits.
  • Data sovereignty is legal control: which law applies, who can compel access and who decides what may be done with it.
  • Digital sovereignty is the wider picture: also the software, the computing power and the suppliers you can no longer do without.

Residency you can buy. Sovereignty you have to organise. A Dutch data centre answers the first question, not the second.

Executives in discussion around a conference table in a modern boardroom

Why data sovereignty is now a board-level question

Three developments have moved the question into the boardroom.

The first is the CLOUD Act, a US law from March 2018 that gives US authorities the power to request data from US providers wherever in the world that data is stored.

The second is that it did not stay theoretical: sanctions have shown that an account or an entire environment can be blocked from the outside, without you having done anything wrong.

The third comes from Europe itself: the GDPR, NIS2 and the Data Act, in application since 12 September 2025, which gives you the right to switch cloud providers without obstacles. That right is only worth something if you know what you would have to move.

Hand writing a checklist in a notebook next to a laptop showing a diagram of connected systems

Where is your data, really?

Sound familiar? Revenue sits in the accounting package, the pipeline in the CRM, hours in a planning tool and the budget in an Excel file on someone’s OneDrive. As soon as two of those sources contradict each other, the meeting is about which number is right instead of what to do about it. That same fragmentation makes “where is our data” almost impossible to answer: in seven places, with five suppliers, under at least two legal systems.

For a Dutch SME:

  • Accounting and HR in AFAS or Exact Online: Dutch suppliers, data centres in the Netherlands or the EU.
  • CRM and marketing in HubSpot, Salesforce or Pipedrive: often US companies, even with the EU region ticked.
  • Documents and email in Microsoft 365: storage in Europe, supplier in the United States.
  • Reporting in Power BI, where a copy of all of the above comes together.

That last line is the point: each source system holds a part of your business, your BI environment holds all of it at once. Anyone who takes data sovereignty seriously therefore starts not with the servers, but with the layer where the copies live.

Employee reviewing charts on a monitor and taking notes

What does data sovereignty mean for Power BI and Microsoft Fabric?

In its default setting, Import, Power BI takes a copy of your source data and stores it in a semantic model in the home region of your Microsoft tenant, fixed on the day the tenant was created. You find that region in Power BI under Help and then About, next to “Your data is stored in”. For Dutch organisations it usually says West Europe, an Azure region physically located in the Netherlands.

Who chose that region back then, nobody usually remembers. More often than not it was the administrator who set up the Microsoft 365 subscription, somewhere between the printer and lunch, and they have since moved on to another employer.

On top of that sits the EU Data Boundary: Microsoft’s commitment that customer data from Microsoft 365, Azure and the Power Platform stays within the EU, apart from a limited number of documented exceptions. That settles residency, not jurisdiction: Microsoft remains a US company and therefore falls under the CLOUD Act. The EU Data Boundary is a promise about location, not immunity.

What you do decide yourself: which sources you import, who administers the tenant, and whether confidential reports carry a sensitivity label that travels with them on export. Those are choices, not Microsoft settings.

The dependency nobody counts: your BI partner

For many SMEs the biggest sovereignty risk is not in Redmond but closer to home. A BI agency builds your reports, and the workspace, the data model and sometimes the licences stay in that agency’s environment. You get a link. They keep the keys. With every report that gets added, your dependency on that one party grows, and you only notice when you want to switch.

That is the same question as the one about the US cloud, only much easier to solve: the environment sits in your own tenant, at least two of your own people are administrators, and the source files are in your keeping. How to settle that is in our piece on Power BI licensing, and it is the reason our approach deliberately hands management over to your own team.

Do you have to leave the US cloud?

For most SMEs: no. There are three responses, and two of them are wrong. Doing nothing leaves you unprotected. Moving everything to a European stack costs functionality, money and years, for a risk that does not exist for the bulk of your data. The third is the only one that works: decide per type of data how sensitive it is, and then choose where it may sit and who may reach it. That classification is the first chapter of your data strategy, not an appendix to the cloud contract.

There is one group this does not apply to. If you work for defence, parts of government or a sector with legal sovereignty requirements, a European stack is not a choice but a condition, and then we are not the right partner for you. We build on Microsoft, and we would rather say so up front than halfway through.


Do you know today which law the copy of your business data in your BI environment falls under, or are you assuming it is probably fine? Get in touch and we will walk through the inventory together.

Frequently asked questions

What is data sovereignty?

Data sovereignty means your organisation decides which laws your data falls under, who can reach it and what may happen to it. The physical location of the servers is only one part of that. Just as decisive is which company delivers the service and which legal system that company answers to.

What is the difference between data residency and data sovereignty?

Data residency is where your data is physically stored, for instance a data centre near Amsterdam. Data sovereignty is about who has legal control over that data. Data can sit in the Netherlands and still fall under foreign law if the supplier is based abroad.

What is digital sovereignty?

Digital sovereignty is the broader term: not only control over your data, but also over the software, the computing power and the suppliers you depend on. Data sovereignty is one part of it. For most organisations, data is the part where the question first becomes concrete.

Is my data sovereign if it sits in a Dutch data centre?

Not automatically. If the supplier of the service is a US company, the US government can demand access to that data under the CLOUD Act of 2018, even when it is stored in the Netherlands. Location is a precondition, not a guarantee.

What is the CLOUD Act?

The Clarifying Lawful Overseas Use of Data Act is a US law from March 2018. It allows US law enforcement to request data from US providers regardless of where in the world that data is stored. It is the main reason a European storage location alone is not enough.

Where is my Power BI data stored?

In the home region of your Microsoft tenant, which was fixed when the tenant was created. You find it in Power BI under Help and then About, next to "Your data is stored in". For Dutch organisations that is usually West Europe, an Azure region physically located in the Netherlands.

Do I have to leave Microsoft or the US cloud?

For most SMEs, no. What you do need is to know which data is genuinely sensitive and to place it deliberately, instead of treating everything the same. Only organisations with legal sovereignty requirements, such as defence or parts of government, have a European stack as the logical choice.

Back to the knowledge base Back to top

Do you want to grow with data?

Curious about what we can do for you? We are happy to show you how data can help your organization grow.

Tom Frohn, Optilise
Get in touch