Blog | Data Expo

Who moves your data?

Written by Data Expo | Aug 6, 2026, 7:50:35 AM

Two questions about the same flow
The first question is technical: can the data get where it needs to go, reliably and on time? This is the plumbing - the pipelines connecting SaaS tools, databases, warehouses, and BI layers. Most teams spend their energy here, and fair enough; a circulatory system that slows, leaks, or clots is an emergency.

The second question is jurisdictional: while the data is in motion, whose laws govern it, and who can compel access to it? This one gets far less attention. But it decides something the first question can't - not whether your data arrives, but who else can reach it along the way.

Most organizations pour their attention into the first question and stay nearly silent on the second. The reason usually comes down to one distinction.

European address, foreign law
Choosing a European data center - and increasingly a European AI model like Mistral - feels like control. It isn't, not fully.

Data residency is about where bytes physically sit. Data sovereignty is about who has the legal authority to reach them. A database hosted in Munich still runs on infrastructure operated by a company that may answer to a foreign legal system.

This stopped being theoretical in June 2025, when Microsoft's French subsidiary confirmed under oath at a French Senate hearing that it could not guarantee data stored in France against access by US authorities. The mechanism is the US CLOUD Act of 2018, which lets US authorities compel US-headquartered providers to hand over data regardless of where in the world the servers are. It has never been formally reconciled with the GDPR or the EU Data Act, which point in the opposite direction. So a European organization on a major US cloud lives with two legal regimes that quietly contradict each other - and only discovers which one wins when a demand actually lands.

And notice where that test almost never gets applied. Organizations audit the jurisdiction of the place their data rests. Far fewer ask the same question about the stretch in between: the connectors, pipelines, and integration tools that hold the data, however briefly, on every hop between systems. 

Data at rest has a custodian you can name. Data en route often has several, and they are rarely all on the same continent.

It's not enough to ask where the blood is stored. You have to ask who has their hand on the artery.

Europe is already answering
In December 2025, Airbus prepared a tender - reported at over €50 million and running up to ten years - to move mission-critical systems to a sovereign European cloud, explicitly citing the reach of the CLOUD Act. Whatever you make of the legal argument, someone has now attached a decade-long budget line to it.

They are not alone in taking it seriously. All EU member states signed a Declaration for European Digital Sovereignty in Berlin in November 2025 - non-binding, but a clear statement of direction. In June 2026 the European Commission proposed a Tech Sovereignty Package that would limit how US cloud providers can be used for sensitive public-sector data in health, finance, and justice.

And the most specific version of the question is already in use, in a procurement document rather than a declaration. The Commission's Cloud Sovereignty Framework scores cloud providers against eight sovereignty objectives for public procurement. One of them, SOV-3, covers the extent to which AI models and data pipelines are, in the framework's words, "developed, trained, hosted, and governed under EU control". Not the warehouse. The pipelines.

Apply that criterion honestly and the data-centre map stops being the answer. 

A warehouse in Frankfurt fed by an integration layer headquartered in California is only as sovereign as the integration layer.

Four questions worth asking
You don't need to be a lawyer to take this seriously. You need to ask better questions about your own bloodstream. A few that any data or business team can put to its stack and its providers:

  • Custody, end to end. Under whose law does each provider in my data flow operate?

  • Who holds the keys. If a foreign authority issues a lawful demand, does my provider hand over readable data, or only encrypted data whose keys I control?

  • Data at rest, data in transit. I know under whose law my data sits. Do I know under whose law it moves?

  • Reversibility. If I needed to re-home a data flow, could I - or is the lock-in deep enough that sovereignty is only theoretical?

Control is what matters
Frameworks will keep changing. SOV-3 is a criterion in a procurement document today, and the instrument around it will be redrafted, renamed, and reweighted. What it asks about will not. Chasing each shift is exhausting and mostly beside the point.

Control is the thing that stays. If data is your organization's lifeblood, then knowing who moves it - and who can reach it while it's in motion - isn't a compliance chore. It's a question about how much of your own vital system you actually govern.

So it's worth asking plainly, before someone else answers it for you: who moves your data?

Sources: European Commission, Cloud Sovereignty Framework; Declaration for European Digital Sovereignty, 18 Nov 2025;EU Tech Sovereignty Package, CNBC, 3 June 2026; Airbus sovereign cloud tender, The Register, Dec 2025.

This blog post is contributed by Dataddo, a modern data integration platform built for the AI era. Dataddo helps organizations securely connect data from a wide range of sources for AI, analytics, and reporting, while maintaining full control over their data and avoiding vendor lock-in. Learn more at www.dataddo.com or visit Dataddo at Data Expo.