Glossary
Data sovereignty
Whose laws your material falls under, which the storage location alone does not settle, because the jurisdiction a provider itself belongs to can matter as well.
In plain terms
A vendor tells you your material sits in a particular country and you conclude that country's rules are the ones that matter. Sometimes that is right. It is not automatically right, because the company holding it belongs somewhere too, and where a company is established can matter alongside where its machines are. That gap between the two is what this term names.
Why it matters
Because a location commitment is easy to obtain, easy to verify and frequently treated as the end of the enquiry when it is the start of one. Organisations that need this settled properly are usually in a sector where somebody will eventually ask, and the difference between having asked the fuller question and having accepted a region setting is not visible until that moment.
How it works
Storage location and legal reach are two different questions, and the first is far easier to answer. Vendors publish regions and can confirm where processing happens, so that question closes quickly. Who could compel the company holding it, and under what circumstances, is a legal question about the company rather than about its hardware, and no configuration setting addresses it.
Corporate structure is where the answers sit and it is not always simple. A vendor may be established in one place, owned from another, and operating infrastructure in several, and which of those matters depends on the situation. That is why organisations with a genuine requirement here ask about the entity they are contracting with rather than only about the region they selected.
The chain extends past your vendor, which is the part most often missed. Where a product passes material to another company to do the actual work, that company's position matters too, and the published list of who those companies are is the practical starting point. For AI tools that list frequently contains a model provider established somewhere else entirely.
The strongest answers reduce the question rather than answering it. Material that never leaves your own infrastructure does not raise it; material processed by a locally established provider raises a simpler version of it. That is the actual reason organisations with hard requirements end up looking at self-hosted or locally established options rather than at a region setting on a global service.
For most organisations this is not a live concern, and saying so plainly is more useful than implying everything is fraught. It becomes one where a sector, a contract or a customer imposes it, and the sign is usually that somebody outside the buying team is asking. Where that has happened, the question needs somebody qualified rather than a reference page.
Two questions that sound like one
Seen in the wild
Choosing where an automation platform processes records, which answers the location question and not the wider one.
MakeReading which other companies a vendor passes material to, since each of those belongs somewhere too.
GleanRunning a model entirely on your own hardware, which is the arrangement that stops the question arising.
Ollama
Common misconceptions
People assume
We selected the region, so this is settled.
In fact
The region settles where material sits, which is a real answer to a real question. Whose laws could reach the company holding it is a separate question about that company, and no setting in a product addresses it. Both are worth having and only one of them is available from a dropdown.
People assume
It is the same thing as data residency.
In fact
Residency is where material is stored, and it is verifiable and usually offered. Sovereignty is whose law applies, which turns on the provider as well as the location. Residency is frequently how a sovereignty requirement is partly met, and the two are not interchangeable.
Telling them apart
Data sovereignty vs Data residency
Data sovereignty
Whose laws reach it. Turns on the provider as well as the location.
Which country it sits in. Verifiable, and usually offered as a setting.
You can select residency. Sovereignty is a conclusion somebody qualified reaches about your arrangement.
Questions
- Does choosing a region answer this?
- It answers where material sits, which is genuinely useful and is a different question. Whose laws could reach the company holding it turns on where that company is established and structured, and there is no setting for that. Organisations with a real requirement ask about the contracting entity as well as the region.
- What about the companies behind our vendor?
- They matter too, and the published list of who they are is where to start. For AI products that list frequently includes a model provider established somewhere else, so the question you settled with your vendor has a second version behind it that nobody raised.
- Do we need to worry about this?
- Most organisations do not, and the signal that you might is somebody outside the buying team asking: a regulator, a large customer, a sector requirement. Where that has happened it is a question for somebody qualified about your specific arrangement rather than one a reference page can close.
- What arrangements avoid the question?
- Material that never leaves infrastructure you control does not raise it at all, and a locally established provider raises a simpler version. That is the practical reason organisations with hard requirements look at self-hosted or local options rather than at a region selector on a global service.
Key takeaways
- Where material sits and whose laws reach it are two questions; only one has a setting.
- The contracting entity matters alongside the storage region.
- The chain past your vendor belongs in the question, and for AI that usually means a model provider.
- Arrangements where material never leaves your control do not raise it.
- For most organisations it is not live; when it is, it needs counsel.
Last checked July 2026