Data sovereignty vs data residency: what's the difference
Data residency is where data is physically stored. Data sovereignty is whose laws govern access to it. They usually move together, but not always: a company can store data on servers physically located in the EU while remaining subject to a foreign country's legal process over that same data, if the company itself, or its parent, falls under that country's jurisdiction. This is a general explanation, not legal advice; a specific situation should be checked with counsel.
Data residency: a geography question
Data residency answers one question: which country or region is the server rack physically in. An "EU data residency" claim from a vendor is a statement about server location, typically backed by naming a specific data center region. It's checkable and usually accurate as far as it goes. What it doesn't answer is who can be legally compelled to hand that data over, because that's a separate question about the operating company, not the building.
Data sovereignty: a jurisdiction question
Data sovereignty answers a different question: whose laws actually reach the data, in practice, regardless of where it physically sits. A company is subject to the laws of the country it's incorporated in and, often, the country its parent company is incorporated in, and those laws can assert authority over data the company controls no matter where that data is stored. This is why data residency and data sovereignty can diverge: physical location is one fact, legal reach is another, and a vendor satisfying the first hasn't necessarily satisfied the second.
The CLOUD Act example
The most commonly cited case of this divergence involves the US CLOUD Act, which is generally understood to let US legal process reach data controlled by a US company (or one with a US parent) even when that data is stored outside the US, including in the EU. So a company can advertise "EU data residency" accurately, meaning the servers are in Frankfurt or Dublin, while still being a US-headquartered or US-parented entity whose data can be subject to a US legal order regardless of that physical location. Whether that exposure matters for a given company's risk tolerance, and how it interacts with EU data protection law specifically, is a legal question, not a technical one; this is informational context, not a substitute for advice from counsel. Our longer piece on EU data residency and the GDPR transfer framework covers the Schrems II line of cases that put this exact issue on the table for AI vendors.
Two independent checks, not one
It helps to treat residency and sovereignty as two separate checkboxes rather than one combined claim. Residency is satisfied by confirming, usually from a vendor's own documentation or a data processing agreement, which specific region the data is physically stored and processed in. Sovereignty is satisfied by confirming where the operating entity, and any parent company, is incorporated, and whether that jurisdiction (or a jurisdiction the parent is subject to) asserts legal reach over data the company controls regardless of physical location. A vendor can pass the first check and fail the second, and the second is generally the harder one to verify, because it requires looking past the region name on a pricing page to the corporate structure behind it.
Why the distinction is worth asking about directly
Because "EU region" and "EU data residency" answer the geography question and stop there, a company evaluating an AI vendor for data protection reasons should ask a second, separate question: is the operating entity itself, including any parent company, incorporated somewhere with no claim of extraterritorial reach over the data. That's the sovereignty question, and it can only be answered by looking at corporate structure, not server location. GPUwerk's infrastructure sits physically in EU-Central and is operated by PRINT IT! SE, an EU-incorporated Societas Europaea with no US parent in the ownership chain, which is what closes both questions at once; details are on the private LLM hosting page.