Frankfurt hosting isn't sovereignty
A datacenter in Germany sounds safe. But the US CLOUD Act doesn't care about geography - only ownership. What digital sovereignty really means, and how to test for it.
"We host in Frankfurt" is the most reassuring sentence in European cloud sales. It's also the most misleading. Data residency - the physical location of your bytes - is routinely confused with data sovereignty - whose law governs those bytes. They are entirely different things, and the difference can cost your company a fine, a breach of trust, or an entire market.
For regulated industries - healthcare, finance, defense, public administration - this confusion isn't academic. It's the difference between an audit you pass and one you fail.
What the CLOUD Act actually says
The US Clarifying Lawful Overseas Use of Data Act of 2018 sets out a simple, far-reaching rule: US providers must produce data they own, hold, or control on a lawful order - regardless of where in the world that data is stored. What matters is not the location of the server, but the nationality of the company that controls it.
In plain terms: if a US company (or a subsidiary under US control) runs your datacenter in Frankfurt, the parent can be compelled to hand over your data - potentially without you ever knowing. The German flag on the building changes none of this.
Geography is a distraction
The marketing trick works because "stored in the EU" can be both true and meaningless. A US hyperscaler can honestly say your data never leaves Frankfurt while still being legally obliged to surrender it on a US order. Both statements are true at the same time.
- Data residency: where the bytes physically sit. Easy to satisfy, easy to market.
- Data sovereignty: whose laws govern the bytes. Hard to satisfy, rarely marketed honestly.
- Operational sovereignty: who maintains, patches, and can access the system if pushed.
Real sovereignty requires all three layers to sit inside the EU/EEA. If even one falls outside - a US parent, or a non-EU support team with root access - the chain is broken.
Sovereignty is decided not by where the disk sits, but by the jurisdiction of the company that operates it.
The questions that actually matter
Before you trust a provider with sensitive data, don't ask "where is my data?" Ask these instead:
- Which legal entity ultimately owns the operating company, and in which country does it sit?
- Can a non-EU court or authority compel the disclosure of my data?
- Who has technical access to the machines - and in which jurisdiction is that staff?
- Can my prompts, documents, or embeddings feed the training of someone else's models?
- How hard would it be to leave and take everything with me?
What sovereignty looks like in practice
Real sovereignty means operations, staff, and ownership fully inside the EU/EEA, with no parent subject to foreign law. Then extraterritorial access can't be compelled - there is simply no lever for a foreign court to pull.
VANAFTER is built exactly that way. We are an EU company operating EU datacenters in Munich, Brno, and Košice. There is no US holding company, no non-EU corporate parent, and no support team outside the union with quiet root access. If someone wants your data, they need a European legal route - and your cooperation.
A checklist before you sign
- Get the provider's ultimate ownership chain in writing.
- Require a commitment that no non-EU entity can compel access.
- Confirm whether your data is ever used for model training - and contractually rule it out.
- Read the exit clause: EU Data Act portability, with no penalty fees.
Hosting in Frankfurt is a fine start. But it's an address, not a guarantee. Ask the right question - who holds the keys - and most "sovereign" clouds answer it for you.
Ready to own your AI compute?
Browse servers →