Data Residency vs Data Sovereignty

Short answer

Data residency is where data physically sits. Data sovereignty is who can reach it — which laws, which operators, which personnel, which keys. Residency is a prerequisite for sovereignty but does not guarantee it.

The distinction in one example

Store Australian health data in an AWS Sydney region and the data is resident in Australia. But AWS is a US company: US legal process can compel Amazon, US-based personnel may hold privileged access, and the platform is US-proprietary technology. Whether that matters is a sovereignty question — and the answer differs for a private clinic versus a defence agency.

This is why GetSovereign models sovereignty as seven dimensions rather than a boolean: an Australian region satisfies the data dimension while leaving legal, personnel and technology dimensions dependent on the provider's structure.

Residency is a floor, not a ceiling

Regulations mostly operate at the residency level:

  • GDPR does not require EU localisation — it regulates transfers and requires protection anywhere data goes.
  • Australian APP 8 requires accountability for overseas disclosure, not prohibition.
  • India's RBI rules require payment data stored in India — a residency rule.
  • Sovereignty — who can compel, who administers, whose law applies — is where government, defence and critical-infrastructure requirements go beyond residency.

When sovereignty goes beyond residency

RequirementResidency aloneFull sovereignty
Data in countryYesYes
No offshore sub-processorsOften unverifiedContractually enforced
Keys held by customerOptionalRequired
Admin by national personnelNoYes
Immunity from foreign lawNoBy structure (e.g. SecNumCloud)

How to evaluate a provider

  1. Residency: which regions exist, and does data stay put unless replicated? (See provider region tables, e.g. AWS, Oracle.)
  2. Legal: where is the contracting entity and the parent? (OVHcloud = EU; AUCloud = Australia.)
  3. Control: customer-managed keys, restricted admin, audit logs.
  4. Personnel: can support and admin be restricted to in-jurisdiction staff? (Open Telekom Cloud, AUCloud.)
  5. Verification: which claims are Verified vs Provider claimed?

Related