Is Data sovereignty now as critical as land and power to data centres?

The real estate mantra has always been “location, location, location.” For data centres, the focus was traditionally on land and power. Now, data sovereignty is becoming just as critical.

Concerns over the CLOUD Act were already on the radar, but recent moves by the US administration and shifting geopolitics have intensified the debate. In response, Amazon has introduced the AWS European Sovereign Cloud, following similar steps by Google and Microsoft. AWS has recently unveiled a robust independent European governance framework designed to emphasise its operational separation from its US parent company.

While this framework includes commendable features, such as a dedicated Security Operations Centre, many customers are left questioning whether these measures go far enough, given that Amazon remains a US-headquartered entity. Ultimately, a parent company retains significant control whatever the governance framework of the subsidiary may say and critical intellectual property and technology are likely licensed to, not owned outright, by the European subsidiary.

Even if assets are transferred to the European entities (which are understood to be a standalone European parent company with 3 subsidiaries incorporated in Germany), assets could easily be returned if required by the US parent, or the US parent could take control of the European entities.

It brings to mind the difference between ‘restrictions on assignment’ in a contract and a ‘change of control’ provision. They have to be treated differently because whilst the parties can sign up a restriction on assignment which will be legally enforceable, a party cannot realistically promise never to undergo a change of control (such as being acquired or merged), because this is typically determined at the parent company level, not by the contracting subsidiary itself. Instead, contracts can only specify what happens if a change of control occurs, such as requiring notice, giving the other party the right to terminate etc.

In the context of the Amazon EU companies, while they can commit to certain obligations in their own contracts or governance framework, ultimate control could go back to the US parent company and no contract between the subsidiary and a third party could override this reality.

Is this an initial veil of sovereignty only?

How will customers know if their contracts and therefore their data are with/fall under the control of the new European companies?

Will the US seek to take back control?

Get in touch for a wider discussion and follow Jane Pittaway for more updates ad data sovereignty continues to be a key focus not only for data centres but all industries.

Authored by: