A server in Frankfurt sounds like data sovereignty - but it is only half the truth. In 2026, digital sovereignty has moved from an abstract IT topic to a concrete business risk for operators of online shops: in an industry survey, 45 percent of professionals name sovereignty as the most important trend for 2026 - ahead of artificial intelligence (EuroCloud). At the same time, 85 percent of companies consider Germany too dependent on US cloud providers (Bitkom Cloud Report 2026). This article explains why the location of a data center alone does not establish data sovereignty, what the new EU Cloud Sovereignty Framework with its eight objectives and five levels requires, and how you can demonstrably run your shop's customer, order and payment data in a sovereign way.

Why Data Sovereignty Becomes a Business Topic in 2026

The shift has become measurable within just a few years. While in 2025 78 percent of companies believed Germany was too dependent on US cloud providers, the figure has now risen to 85 percent (Bitkom Cloud Report 2026). Everyday practice looks different, though: 71 percent of companies currently use US offerings, while only 8 percent would actually prefer this origin (Bitkom Cloud Report 2026). This gap between usage and preference is the real driver behind the trend - and it affects online shops in particular, because they process personal customer and payment data in large volumes and in real time.

Willingness to pay is rising too. 37 percent of companies would today choose a cloud solution that processes data exclusively in Germany and protects it from foreign access - even if that means higher costs or fewer features; a year earlier it was only 27 percent (Bitkom Cloud Report 2026). Behind this development lies less a matter of technical fashion than concrete regulation and geopolitics: the EU Data Act has been applicable since September 2025 and obliges cloud providers to implement safeguards against unlawful third-country access to data stored in the EU (EU Data Act). For shop operators this means: the question of where data resides and who may access it is no longer optional but part of due diligence.

For sales, data sovereignty has also become a selling point. Business customers increasingly ask during procurement where order and contract data are processed, and in B2B e-commerce corresponding evidence now regularly appears in tenders and supplier questionnaires. A shop that can credibly demonstrate that customer data remains under European control gains trust - while a blanket server location in Germany no longer suffices as the sole argument.

Sovereignty beats AI as the top trend

In a survey among cloud professionals, 45 percent named digital sovereignty as the most important trend for 2026 - roughly twice as many as those who placed artificial intelligence in the top spot (EuroCloud). The cited causes are stricter requirements such as the NIS2 implementation act and the EU Data Act, along with geopolitical uncertainty. For online shops this shifts priorities: data sovereignty moves from an afterthought to a selection criterion for hosting and infrastructure.

Data Residency Is Not Data Sovereignty

At the core, two terms are confused. Data residency describes the physical location where data is stored - for example in a data center in Frankfurt. Data sovereignty, by contrast, describes which law the data and the provider are subject to and who can compel access in an emergency. The two do not automatically coincide. A US provider can store data in Frankfurt and still be obliged to hand it over to US authorities. The server location alone therefore says little about actual control.

CriterionData residencyData sovereignty
Key questionWhere does the data sit?Who controls the data?
EvidenceLocation of the data centerJurisdiction of provider and operation
Protection from foreign accessLimitedGoal of the concept
Significance on its ownLowDecisive

For an online shop, this distinction has tangible consequences. If order and customer data end up with a provider subject to US law, a residual access risk remains - even when the contract and server location point to Europe. Conversely, genuine data sovereignty does not mean isolation: data may still flow and be processed, just within a jurisdiction where European fundamental rights and the GDPR set the tone. In practice this means not only asking about the location, but examining the ownership and control structure of the provider.

How far residency and sovereignty can diverge was shown by a hearing before the French Senate on 10 June 2025. Asked whether he could rule out that data of French citizens would be passed to US authorities without explicit authorization, the responsible manager of a large US provider stated under oath that he could not assure it (French Senate). This explicitly also concerned data held in European data centers under an offering marketed as sovereign (heise). The statement made clear that contractual assurances and an EU location do not dissolve the access risk as long as the provider is subject to US law.

US CLOUD Act and GDPR: The Conflict of Objectives

The reason lies in the US CLOUD Act of 2018. It obliges US providers to hand over stored data on order - regardless of where in the world that data physically resides (US CLOUD Act). What matters is not the server location but whether the company is subject to US jurisdiction. This is exactly where the conflict with European law arises: under Article 48 of the GDPR, disclosure orders from third countries are in principle only permissible if an international agreement such as a mutual legal assistance treaty applies (GDPR Art. 48). The CLOUD Act bypasses this route - placing operators in a legal dilemma.

An EU subsidiary does not protect automatically

A common misconception: a European subsidiary or a locally marketed sovereignty label solves the problem. If the parent company is subject to US law, a US order can compel the disclosure of data hosted in Europe - contract clauses experience shows change nothing. Resilient data sovereignty only arises when provider, operation and jurisdiction are consistently European. Anyone who really wants to secure customer data therefore examines the entire chain rather than just the location of the data center.

The EU Cloud Sovereignty Framework: Eight Objectives, Five Levels

To make sovereignty measurable, the European Commission has introduced the EU Cloud Sovereignty Framework. It assesses providers against eight sovereignty objectives and a five-level scale called SEAL (Sovereignty Effectiveness Assurance Level) from 0 to 4 (European Commission). Instead of a blanket sovereignty seal, this produces a differentiated profile: for each of the eight objectives a separate level is assigned, weighted and combined into an overall score that is used above all in public procurement.

  • SOV-1 - Strategic sovereignty (weight 15 percent): ownership, governance and alignment with European industrial policy.
  • SOV-2 - Legal sovereignty (10 percent): applicability of EU law and protection from foreign legal claims.
  • SOV-3 - Operational sovereignty (10 percent): independent operation without dependence on third countries.
  • SOV-4 - Technological sovereignty (15 percent): control over the key technologies deployed.
  • SOV-5 - Supply chain sovereignty (20 percent, the highest weight): independence of the supplier chain (European Commission).
  • SOV-6 - Data sovereignty (15 percent): protection of data from unauthorized access.
  • SOV-7 - Personnel sovereignty (10 percent): EU-based, controllable operating staff.
  • SOV-8 - Environmental sustainability (5 percent, the lowest weight): energy-efficient infrastructure and transparency.

The five levels form a ladder from foreign to full EU control. SEAL-0 stands for no sovereignty, meaning control outside the EU. SEAL-1 means jurisdictional sovereignty, SEAL-2 data sovereignty, SEAL-3 digital resilience and SEAL-4 full digital sovereignty with end-to-end EU control (European Commission). Important for operators: if a provider falls below the required minimum level on just one of the eight objectives, it is excluded from the corresponding tender. A single weak point can therefore tip the entire assessment.

For a typical shop, a pragmatic target picture can be derived from this. Anyone serving mainly end customers often gets far with a solid rating on the objectives for legal sovereignty and data sovereignty, because here the protection of personal data is in the foreground. Anyone supplying public clients or regulated industries, by contrast, should check early which minimum levels are required in tenders - and set their own infrastructure correspondingly higher. The framework is thus less a hurdle than a map showing where improvement is needed and where a viable level has already been reached.

From seal to evidence

The framework replaces the blanket promise with a verifiable profile. For shop operators this is an opportunity: anyone who aligns their hosting with the eight objectives can present clients and auditors with concrete levels instead of vague assurances. That creates a demonstrable advantage in B2B sales, especially when public clients or large corporations require proof of sovereignty.

Which Shop Data Deserves the Most Protection

Not all data in a shop deserves the same level of protection. The most critical are personal data and payment data, because here, in addition to data sovereignty, the GDPR and industry-specific requirements also apply. Anyone keeping an eye on the new EU payment rules PSD3 and PSR quickly sees that payment and authentication data must be treated with particular care. The following classification helps to grade the protection needs per data category realistically - and to align the infrastructure accordingly.

Data categoryProtection needRecommendation
Customer and account dataHighEU jurisdiction, access control
Order and payment dataVery highEU hosting, encryption
Product catalog and mediaMediumKeep location transparent
Analytics and tracking dataHighCookie-free, EU-run measurement

The protection need determines the effort. Order and payment data belong on EU-based infrastructure with strict access control and encryption, while a public product catalog is less sensitive - here it is often enough to document the location transparently. Analytics belong here too: cookie-free measurement operated in Europe avoids data export to third countries from the outset. And because a shop rarely stands alone, connected systems such as inventory management or payment services must be included in the same sovereignty concept via the integrations.

Data sovereignty is only one building block of the growing compliance requirements on shops. From the end of 2026, for example, product liability for software tightens, and data protection too demands a demonstrable handling of personal data. Anyone who thinks infrastructure, law and evidence together saves double the effort later - and reduces the risk of failing an audit or a tender.

The starting point is therefore an honest inventory of data flows. Data often leaves the EU at points that barely stand out in everyday operation: embedded fonts, map or analytics services, a payment form or a support tool. Each of these building blocks can carry customer or usage data into a third country without it being visible in the shop. Anyone who documents these transitions and gradually replaces them with European alternatives shrinks both the attack surface and the legal gray area at once.

Setting Up Sovereign Hosting for Your Shop

Sovereignty cannot be stuck on afterwards; it belongs in the architecture. In XICTRON's cloud consulting we therefore start with a stocktake: which data categories arise, which jurisdiction does the current infrastructure fall under, and where does data leave the EU unnoticed? From the answers a target picture emerges along the eight sovereignty objectives - with clear levels instead of vague assurances. In addition, we define in the consulting which data category has which protection need.

EU-based infrastructure

Operation on providers and in data centers subject to European law - so that data residency and data sovereignty coincide rather than drift apart.

Access control and encryption

Role-based rights, encryption of sensitive order and payment data and traceable logs - matched to the protection need per category.

Evidence per framework

We align the hosting with the SEAL levels and document the evidence that clients and auditors expect.

Sovereignty without loss of speed

A lean setup operated in Europe can be kept fast - data sovereignty and quick loading times are not mutually exclusive.

In implementation, a step-by-step approach has proven itself. Instead of switching everything at once, we prioritize the most sensitive data categories - order and payment data - and follow up with less critical areas. That keeps operations stable while data sovereignty grows level by level. Each stage is documented so that in the end not only the technology is right, but the evidence for clients, the data protection authority and internal audit is available too.

That sovereignty and performance go together is shown by a look at operations: a cleanly configured server with a current PHP version and OPcache tuning delivers short response times, entirely independent of jurisdiction. What matters is to think both together from the start rather than playing performance off against data sovereignty.

  • Data categories and their protection needs are recorded and documented
  • Infrastructure and providers are consistently subject to European law
  • Sensitive order and payment data are encrypted and access-protected
  • Connected systems and analytics are included in the sovereignty concept
  • The classification follows the eight objectives and SEAL levels of the framework
  • Evidence for tenders and audits is available and up to date

Whether stricter regulation, critical customers or the risk of foreign access: the pressure to act on data sovereignty is rising noticeably, and a server location in Germany alone no longer carries far as an argument. Anyone who demonstrably brings their shop's customer, order and payment data under European control reduces legal risks and at the same time gains a credible trust argument. Talk to our team to assess your shop's data sovereignty along the EU Cloud Sovereignty Framework and to set it up sovereignly step by step.

Sources

This article draws on the EuroCloud trend survey 2026 (sovereignty as top trend), the Bitkom Cloud Report 2026 (dependence on US providers, usage and preferences), the European Commission's EU Cloud Sovereignty Framework (eight sovereignty objectives, five SEAL levels and weightings), the US CLOUD Act and Article 48 GDPR on the conflict over government access, the hearing before the French Senate (June 2025, reported among others by heise) and the EU Data Act (applicable since September 2025). The figures cited can change over time and serve as guidance; this article does not replace individual legal or security advice. As of August 2026.

No. The location of a data center (data residency) says nothing about which law the provider is subject to (data sovereignty). A US provider can store data in Frankfurt and still be obliged to hand it over under the US CLOUD Act - regardless of the server location (US CLOUD Act). Resilient data sovereignty only arises when provider, operation and jurisdiction are consistently European.

It is an assessment framework from the European Commission that classifies cloud providers against eight sovereignty objectives and a five-level SEAL scale from 0 to 4 (European Commission). For each objective a separate level is assigned and weighted; the result feeds above all into public procurement. If a provider falls below the required minimum level on one objective, it is excluded from the respective tender.

Directly affected are US providers, not your shop. Indirectly, however, yes: if you process customer or payment data with a US provider, that data can be subject to access under the CLOUD Act - which can collide with Article 48 GDPR (GDPR Art. 48). For due diligence it therefore matters which jurisdiction your service providers are subject to.

As a rule, not reliably. If the parent company is subject to US law, a US order can compel disclosure even with a European location. In a hearing before the French Senate in June 2025, a provider representative stated under oath that he could not rule out such access (French Senate). Contract clauses and local labels typically do not solve the underlying problem.

Not necessarily. While 37 percent of companies state they would accept higher costs or fewer features for sovereignty (Bitkom Cloud Report 2026), a leanly configured setup operated in Europe can be kept fast and economical. Data sovereignty and short loading times are not mutually exclusive - what matters is a clean architecture.

We record your shop's data categories, examine the jurisdiction of the current infrastructure and align hosting and access controls with the eight objectives of the EU Cloud Sovereignty Framework. Sensitive order and payment data are operated EU-based, encrypted and access-protected, and we document the evidence for tenders and audits. This typically makes data sovereignty a demonstrable part of ongoing operations (project experience).