Article
Whose Cloud Is It Anyway?
Data Sovereignty, Backup, and the Awkward Questions UK IT Leaders Now Have to Ask
A year or two ago, ‘where does our backup data live’ was a box-ticking question, usually answered with a data centre postcode and a nod towards the GDPR clause in the contract. It is no longer that simple. Between EU proposals to restrict US cloud providers for sensitive government workloads, French Senate testimony that unsettled the market, and a steady stream of headlines about the US CLOUD Act, IT and security leaders across UK mid-market businesses are being asked harder questions by their boards, their auditors, and increasingly their customers.
This article sets out, as plainly as we can manage, what has genuinely changed, what the legislation actually says, where the public debate has drifted from fact, and what a sensibly cautious UK business should be doing about it. We have tried to keep the flag-waving out of it. Sovereignty is a risk management question, not a nationality contest.

What has really changed?
Three separate developments have collided to bring this conversation into the boardroom.
- EU Tech Sovereignty Package. In May 2026 the European Commission began circulating proposals that would restrict the use of US cloud providers for the most sensitive public-sector workloads, in areas such as healthcare, finance and the judiciary. This applies to government bodies rather than private businesses, but it signals the direction EU policy is heading, and mid-market suppliers to the public sector should pay attention.
- The EU Data Act. In force since January 2024 and applying since September 2025, Chapter VII requires cloud providers operating in the EU to take reasonable technical, contractual and organisational steps to prevent unlawful third-country government access to data. It does not ban US providers. It obliges better safeguards.
- UK Data (Use and Access) Act 2025. Rolling out through 2026, this reforms how the UK assesses whether a third country offers adequate protection, replacing the old ‘essentially equivalent’ test with a ‘not materially lower’ standard. In good news for continuity, the European Commission renewed the UK’s own adequacy decision in December 2025, valid until December 2031, so EU-to-UK data flows remain on a stable footing for now.
None of this amounts to a ban on US cloud or US software. It amounts to a more demanding compliance environment, and a much lower tolerance for vague reassurance from suppliers.
The CLOUD Act, and what it actually requires
The US Clarifying Lawful Overseas Use of Data Act, passed in 2018, allows US law enforcement to compel a US company to produce data it holds, regardless of where in the world that data physically sits. The legal test is ‘possession, custody or control’ of the data by the company, not the location of the server. This is the detail that catches people out: choosing a UK or EU data centre region from a US-headquartered provider does not remove the exposure, because the obligation attaches to the corporate entity, not the postcode.
There are limits worth knowing. Requests generally require a warrant for content held less than 180 days, under the older Stored Communications Act framework the CLOUD Act sits alongside. Providers have a narrow right to challenge a request if complying would breach a qualifying foreign government’s law, though this is rarely used successfully and does not pause the request while under challenge. And where the UK is concerned, the UK-US Data Access Agreement, in force since October 2022, gives the two governments a formal channel to resolve conflicting demands, which does provide some structural reassurance that does not exist for most other countries.
The detail that tends to unsettle people most is the non-disclosure order. A CLOUD Act request can come with a gag order preventing the US provider from telling you, its customer, that your data was ever requested. That is a real and fair concern, and it is one no amount of regional data centre marketing resolves.
Where the public debate gets ahead of the facts
A good deal of what circulates on LinkedIn and in vendor marketing is directionally right but factually loose. The table below sets out the more common claims against the evidence we have found.
| Area | What people often say | What the evidence shows |
| Naming | ‘The EU Cloud Act’ will fix this. | There is no EU statute by that name. The EU relies on GDPR and the EU Data Act (Chapter VII) instead, and neither directly overrides US law. |
| Data location | Our data sits in an EU or UK region, so it is out of US reach. | The CLOUD Act tests corporate ‘possession, custody or control’, not the address of the data centre. Region selection changes geography, not jurisdiction. |
| Sovereign cloud | A ‘sovereign’ EU offering from a US hyperscaler removes the risk entirely. | Under sworn questioning by the French Senate in June 2025, Microsoft’s own French subsidiary said it could not guarantee protection from US legal demands, even under a French-marketed sovereign product. |
| Notification | We would be told if a US agency asked for our data. | CLOUD Act requests frequently come with a non-disclosure order. The US provider can be legally barred from telling you. |
| Vendor ownership | Our backup software is European, so it sits outside US jurisdiction. | Several well-known platforms with European engineering roots are now US-owned or US-headquartered companies. Ownership and incorporation, not engineering heritage, decide legal exposure. |
Is the software itself part of the problem?
This is the question we get asked most often once people have grasped the jurisdiction point, and it deserves a straight answer: it depends on architecture, not on the passport of the engineers who wrote the code.
Backup platforms broadly fall into two camps. Self-hosted software, such as Veeam Backup and Replication deployed on your own servers and storage, moves your data between systems you control. The vendor’s company is still subject to whatever jurisdiction it is incorporated in, but it typically never holds your data, your encryption keys, or your repository. You do. The second camp is vendor-managed cloud platforms, where backup data, metadata, or key management sits inside the vendor’s own cloud environment. Here, the jurisdiction of the vendor’s corporate entity matters directly, because the vendor genuinely has possession of your data.
Ownership has also shifted in ways worth knowing. Veeam began as a Swiss engineering business, but has been US-owned by Insight Partners since 2020 and was explicitly repositioned as a US company as part of that acquisition. Commvault and Rubrik are both US-headquartered, US-listed companies. None of this makes any of them unsuitable, and we are not in the business of telling people which vendor to prefer. What it does mean is that ‘our backup vendor is European’ is no longer a reliable statement for most of the well-known platforms, and it is worth checking rather than assuming.
The question is not ‘which country made this software’, it is ‘who holds my keys, and where does my data actually sit when it is not on my own hardware’.
Can a US authority really reach data physically stored in the UK?
In principle, yes, if the company holding it is a US company or US-controlled, because the CLOUD Act tests corporate control rather than server location. In practice, the frequency of this happening to a UK mid-market business is low, and the legal process involved is not trivial.
The honest position, and the one the legal commentary increasingly reflects, is that data residency alone (a UK or EU data centre address) is a useful but incomplete control.
What closes the gap is technical: encryption where you, not the vendor, hold the keys; genuine operational separation between the vendor’s support access and your data; and contractual clarity about what happens if a request does arrive.
A practical checklist for UK mid-market IT & Security leaders
- Ask who actually holds the encryption keys for your backup data, not just where the storage is physically located.
- Establish whether your backup platform is self-hosted software you control, or a vendor-managed cloud service where the vendor has genuine possession of your data.
- Check the parent company and country of incorporation of every vendor in your data path, not only the primary cloud provider. This includes backup software, replication targets, and any SaaS-delivered management console.
- Review your contracts for what the vendor commits to do, and tell you, if it receives a government data request.
- Keep at least one recovery copy on infrastructure and under a legal jurisdiction you fully understand and control, as a practical hedge rather than a political statement.
- Revisit your international transfer risk assessment in light of the ICO’s updated guidance from January 2026 and the UK’s ‘not materially lower’ adequacy test.
Where Covenco fits in
Covenco offers a design choice most organisations have not been offered plainly: architectures where you retain control of your keys and your repositories, UK-based infrastructure and support, and the flexibility to run backup, disaster recovery and archive on platforms hosted on our own UK infrastructure rather than a US-controlled cloud console, where that genuinely matters to your risk profile.
As a UK, independent IT infrastructure and managed services business since 1989, working across IBM Power and Storage, Veeam, and a range of backup and recovery architectures, our job is to help you understand where your actual exposure sits, and then build a backup and DR strategy that matches your appetite for risk rather than the loudest headline of the month. Sometimes that means a US-owned platform with the right controls wrapped around it. Sometimes it means keeping a recovery copy closer to home. Both are legitimate answers, and the right one depends on your business, not ours.
If your board has started asking where the backups ‘really’ live, and you would like a second opinion grounded in the current legislation rather than the current mood on social media, we are happy to talk it through.