If you run a hosting company, you've probably had a client ask where their data is stored. That's the easy question. The harder one, and the one regulators are now forcing the industry to answer, is who can legally access it.
Data sovereignty has gone from a compliance buzzword to an actual operational headache. Three regulatory developments are hitting hosting providers in 2026, and each one rewrites the rules around how client data can be stored, moved and handed over. Here's what they mean for your infrastructure decisions and your client contracts.
Data Residency and Data Sovereignty Are Two Different Things
A lot of people in hosting assume that sticking a server in a specific country automatically ticks the sovereignty box. It doesn't.
Data residency answers "where is the data physically located?" Data sovereignty goes further. It asks which legal jurisdiction can force access to that data, and whether the company controlling the infrastructure falls under foreign legal authority.
A server in Frankfurt won't give you data sovereignty if it's run by a US-headquartered company. Under the CLOUD Act, US law enforcement can compel any US-based provider to hand over data no matter where the hardware is located. So a hosting client who picked a German data centre for GDPR reasons could still have their data exposed to US legal processes. And if you're reselling infrastructure from a US-headquartered hyperscaler, you're inheriting their jurisdictional exposure, and so are your clients.
Three Regulatory Shifts That Will Change How You Operate
The CLOUD Act's Extraterritorial Reach
The US CLOUD Act, passed in 2018, gives US authorities the power to demand data from any provider under US jurisdiction, regardless of where the servers are. If the parent company is American, the data is reachable.
This has already pushed a growing number of EU public-sector procurement processes to require providers that aren't subject to third-country law with extraterritorial reach. For hosting companies serving regulated industries, your upstream provider's corporate domicile is now part of the sales conversation.
The EU Data Act and Cloud Portability
Since September 2025, the EU Data Act has required cloud providers to support open interfaces and cut down on contractual lock-in. Switching fees must be eliminated entirely by January 2027. If your infrastructure doesn't support data export in structured, machine-readable formats, you're potentially non-compliant.
The EU E-Evidence Package
This one is the most urgent. Regulation (EU) 2023/1543 applies from 18 August 2026 and allows judicial authorities in one EU member state to issue Production Orders and Preservation Orders directly to service providers in another, skipping the old mutual legal assistance process.
Hosting and cloud providers fall squarely within scope. If your company offers services to EU users, you'll need a designated establishment or legal representative in the EU to receive these orders. Non-compliance can result in penalties of up to 2% of global annual turnover. Providers will have as little as 10 days to respond, or 8 hours in emergencies, which means you'll need clear internal processes and escalation procedures ready to go.
How to Assess Whether a Provider Satisfies Sovereignty Requirements
Sovereignty checks need to go beyond "where's the data centre?" If you're evaluating upstream infrastructure, or your clients are evaluating you, here's what to look at:
Jurisdiction and corporate structure. Where is the provider incorporated? If the answer includes the US, the CLOUD Act applies regardless of server location.
Encryption architecture. Server-side encryption won't stop a compulsion order, because the provider can still decrypt and hand over the data. Client-side encryption, where only the customer controls access, is the only model that actually holds up.
Key management. If the provider manages the encryption keys, they can be compelled to use them. True sovereignty means the keys sit outside the provider's reach entirely.
Jurisdiction matters at the country level too. Providers based in countries outside the reach of both the CLOUD Act and the EU e-evidence framework are in a different legal position entirely. Switzerland, for example, has its own data protection law (the revDSG, updated in 2023) and isn't subject to either US or EU compulsion orders. That's made it a popular base for privacy-focused infrastructure providers in recent years.
Where Storage Fits into the Sovereignty Equation
File storage is often where the most sensitive client data ends up, and it's the layer most exposed to compulsion orders.
For hosting companies advising clients on where to keep documents, backups and shared files, the combination of jurisdiction and encryption architecture matters most. Swiss-based cloud storage with client-side end-to-end encryption covers sovereignty at the file level by placing both legal protection and technical control outside the reach of US or EU compulsion. Switzerland isn't bound by the CLOUD Act or EU production orders, and if the provider genuinely can't access the encryption keys, there's nothing to hand over even if a request comes in.
That's the kind of detail hosting companies need to be communicating to clients in regulated sectors.
Your Clients Will Ask These Questions, So Have Answers Ready
The regulatory picture in 2026 puts hosting companies in an advisory role whether they want it or not. Your clients will expect you to explain how the e-evidence package affects their data and confirm that your infrastructure doesn't create compliance gaps they didn't sign up for.
Audit your own supply chain and be upfront about jurisdictional implications. The hosting companies that treat sovereignty as a real infrastructure decision, not a marketing claim, will be the ones clients stick with when the pressure ramps up.