Skip to content
SealMetrics
Privacy

Residency Is Not Sovereignty: The Question to Ask Your AI Analytics Vendor

6 min readBy Rafa Jiménez

A European datacenter does not make your AI vendor European. If the company running the model answers to US law, your data is reachable under US law — no matter which flag flies over the server room.

Key Takeaways

  • Residency is where data sits. Sovereignty is who can legally compel access to it. They are not the same thing, and only the second one protects you.
  • The US CLOUD Act and FISA §702 follow the corporate parent, not the datacenter — so a US company's EU region is still reachable under US law.
  • An architecture where data never leaves the EU and the provider has no US parent does not trigger GDPR Chapter V at all — no Standard Contractual Clauses, no transfer assessment, no dependence on the Data Privacy Framework.
  • Three questions decide it: who owns the provider, where the model runs, and what is retained or used for training.

"Hosted in Europe" has become the reflexive answer to every question about AI and data protection. It is also, on its own, close to meaningless. The location of a server tells you where the bytes rest. It tells you nothing about who can knock on the door and demand them.

That distinction — residency versus sovereignty — is the single most important thing to understand before you let an AI feature touch your analytics data. It is also the distinction most vendors are quietly counting on you to miss.

Two words that are not synonyms

Data residency is a geography question: in which country is my data stored or processed? Data sovereignty is a jurisdiction question: whose laws can compel access to it? A provider can give you a perfect answer to the first while the second quietly undermines the whole thing.

Here is the mechanism. The US CLOUD Act (2018) obligates any provider subject to US jurisdiction to disclose data in its "possession, custody, or control" — regardless of where in the world that data is stored. For non-US persons, FISA Section 702 adds a separate foreign-intelligence collection regime. Neither cares which datacenter you picked. Both care who owns the company.

So when a US-headquartered AI provider offers you a Frankfurt or a Paris region, the data lives in Europe and remains reachable under American law at the same time. Residency: yes. Sovereignty: no.

Why the "EU region" checkbox is not enough

Every major US AI provider now offers some form of European processing — OpenAI through EU data residency, Anthropic's Claude via AWS Bedrock's EU regions, Google's Gemini pinned to Vertex AI in Belgium or the Netherlands. Each of these is a genuine improvement on sending data to Virginia. None of them changes the corporate jurisdiction of the entity operating the service.

And the fallback legal basis for EU-US data flows is not solid ground. The EU-US Data Privacy Framework survived its first court challenge in September 2025, but an appeal is pending before the Court of Justice of the EU, and a fresh challenge — already nicknamed "Schrems III" — was announced in 2026. Its two predecessors, Safe Harbor and Privacy Shield, were both struck down. Building a privacy-critical feature on a legal basis with that track record is a bet, not a guarantee.

The architecture that sidesteps the whole debate

There is a cleaner answer than arguing about transfer mechanisms: build so that no international transfer ever happens. If the data never leaves the EU and the provider running the inference has no US parent, then GDPR Chapter V — the entire international-transfer chapter, Article 44 onward — is simply not triggered. No Standard Contractual Clauses. No Transfer Impact Assessment. No dependence on the Data Privacy Framework surviving its next day in court.

This is the choice behind Seal AI, the private AI layer inside SealMetrics. Inference runs on Scaleway's infrastructure in Paris only. Scaleway is a French company with a French parent (the Iliad group) and no US ownership — it states plainly that its AI services are not subject to extraterritorial laws such as the American CLOUD Act. The model is open-weight and static; it is not trained on your data, and nothing is retained by default.

Three questions to audit any AI analytics vendor

You do not need to be a lawyer to test a vendor's claim. Ask these, in order:

  1. Who owns the company running the inference? If there is a US parent, an EU region does not remove CLOUD Act exposure. Stop here — the rest is secondary.
  2. Where is the model run, exclusively? "We can process in the EU" is not the same as "we only process in the EU." A global endpoint that mayroute elsewhere is not EU-only.
  3. What is retained, and what trains the model? Zero prompt retention and no training on your data should be the default, in writing, in the subprocessor documentation — not an enterprise upsell.

If a vendor cannot answer the first question with "a European company, no US parent," then whatever they say about residency, encryption, or certifications is decorating a house built on someone else's jurisdiction.

The bottom line

Residency is a marketing-friendly half of the answer. Sovereignty is the half that actually determines whether a foreign government can reach your customers' data. When the two conflict — an EU server owned by a US company — jurisdiction wins. Ask who owns the provider before you ask where the server is. For a privacy-first analytics platform, the AI layer cannot be the one place that answer goes wrong.

Related reading