Most sovereignty reviews end at the warehouse. Where is it hosted, who operates the region, which certifications does the provider hold. Reasonable questions, and a European organization that has answered them feels, understandably, like it has answered the question.
It has answered half of it.
Data residency is about where bytes physically sit. Data sovereignty is about who has the legal authority to reach them. The two diverge more often than most stacks admit, and the place they diverge hardest is not the warehouse. It is the stretch in between: the connectors, pipelines, and integration tools that hold your data, however briefly, on every hop between systems.
Data at rest has a custodian you can name. Data in motion usually has several, and they are rarely all on the same continent.
We made the general version of this argument on the Data Expo blog, without naming any vendor. This piece is the follow-on: if you accept that the pipe matters, what exactly do you test it against, and what does a passing answer look like?
The criterion that names pipelines out loud
The sharpest version of this question is not in a manifesto. It is in a procurement document.
The European Commission's Cloud Sovereignty Framework scores providers against eight sovereignty objectives for public procurement. One of them, SOV-3, covers the extent to which AI models and data pipelines are, in the framework's own words, "developed, trained, hosted, and governed under EU control."
Not the storage layer. The pipelines.
That wording matters because it breaks a comfortable assumption: that sovereignty is a property you buy once, at the infrastructure layer, and everything above it inherits. It is not. Every hop in a data flow inherits its own legal regime. A warehouse in Frankfurt fed by an integration layer headquartered in California is only as sovereign as the integration layer.
And the integration layer is almost never scored. It is bought by a data team on technical merit, renewed on inertia, and never appears in the sovereignty review at all.
Why this stopped being a philosophy discussion
Three data points, in ascending order of how much money is attached to them.
On 10 June 2025, Microsoft France's director of public and legal affairs told a French Senate committee, under oath, that he could not guarantee data stored in France would never be passed to US authorities. Asked directly, his answer was "Non, je ne peux pas le garantir" - no, I cannot guarantee it. The mechanism is the US CLOUD Act of 2018, which lets US authorities compel US-headquartered providers to hand over data regardless of where the servers are. It has never been formally reconciled with the GDPR or the EU Data Act, which point the other way.
In November 2025, all EU member states signed a Declaration for European Digital Sovereignty in Berlin. Non-binding, but a clear statement of direction. In June 2026 the Commission followed with a Tech Sovereignty Package that would limit how US cloud providers can be used for sensitive public-sector data in health, finance, and justice.
And in December 2025, Airbus prepared a tender reported at over EUR 50 million and running up to ten years, to move mission-critical systems to a sovereign European cloud, explicitly citing the reach of the CLOUD Act. Whatever you make of the legal argument, someone has now attached a decade-long budget line to it.
For regulated private companies the pressure arrives through a different door. DORA has required financial entities to map and de-concentrate their critical ICT third-party dependencies since January 2025. A foreign-routed data pipeline is exactly that kind of dependency, and no public-sector contract is needed to make it one.
Managed integration does not have to mean managed custody
There is an assumption buried in most of these reviews, and it is worth pulling out into the open, because it is the thing that makes teams believe they face a choice between sovereignty and convenience.
A data integration platform can be used without your data ever leaving your own environment. In a two-plane architecture, the data plane - the component that actually reads, transforms, and writes your records - executes inside your own infrastructure, while only the control plane, which schedules and monitors jobs without touching the payloads, runs as a managed service.
This is why a security policy that forbids customer data from leaving your cloud does not, by itself, rule out managed data integration. It rules out the single-plane SaaS architecture that most integration vendors use, in which every record is routed through the vendor's own cloud in order to be processed.
Dataddo runs on the two-plane model: the data plane executes in the customer's environment across cloud, hybrid, and fully on-premise deployments, and customer data does not transit Dataddo's cloud.
Once that distinction is on the table, "sovereign integration" stops being a slogan and becomes something you can test.
The test: what a sovereign data-movement layer actually has to do
"Sovereign integration" is a claim any vendor can put on a website. It becomes checkable when you break it into three bars, all of which have to clear at once.
1. Sovereign in transit
The part of the platform that actually touches your data - the data plane - executes inside your own environment. Your data never transits the vendor's cloud, in any region. This is the bar most SaaS integration tools fail by construction: their architecture routes your records through their infrastructure, because that is how the product works.
2. Sovereign by vendor
The vendor is an EU legal entity under enforceable EU law, with no foreign parent that can be compelled to act against you. An EU subsidiary of a US company does not clear this bar. That is precisely what the French Senate testimony established.
3. Sovereign by control
The orchestration layer - the part that schedules and monitors, without touching payloads - can also be hosted in the EU or on a European cloud, so the whole layer sits under EU law when the deployment requires it.
Storage and compute sovereignty without movement sovereignty is a stack with an open seam.
Five questions to put to your integration vendor
Take these to a renewal conversation. The right answers are specific; vague answers are answers.
- Where does my data physically execute? Not "where is it stored" - where does the transformation run. If any part of it runs in the vendor's cloud, name the region and the legal entity operating it.
- Under whose law does the vendor operate? Not where the sales office is. Where the legal entity is incorporated, and whether a foreign parent sits above it.
- Who holds the keys? If a foreign authority issues a lawful demand, does the provider hand over readable data, or only ciphertext whose keys you control?
- Can the control plane move? If a deal requires both planes under EU law, is that a configuration or a roadmap item?
- Could I re-home this flow? If the answer is no, sovereignty is theoretical regardless of how the first four went.
How Dataddo answers the test
We would rather be checkable than impressive, so here is the honest version, bar by bar.
Sovereign in transit: yes, by architecture. Dataddo's data plane runs inside your environment. Your data does not transit Dataddo's cloud - only the control plane, which handles orchestration and the UI, sits on our side. The platform supports cloud, hybrid, on-premise-to-on-premise, and fully on-premise execution, including SSH and reverse-SSH into segmented networks. We do not store your data, and we do not train or host AI models on it, which removes two whole sections from most sovereignty reviews.
Sovereign by vendor: yes. Dataddo is a Czech company, headquartered in Prague, under EU law. There is no foreign parent that can be compelled to act against a customer.
Sovereign by control: available, not automatic. This is where we will not overclaim. On a standard deployment, the control plane runs in Dataddo Cloud on a hyperscaler. It is cloud- and region-agnostic and can be deployed in the EU or on European providers such as OVHcloud, Scaleway, Exoscale, STACKIT, or Hetzner, and it is portable across Kubernetes, OpenShift, and Tanzu. But that is a per-deployment decision, not the default. If your requirement is both planes under EU law, say so at the start and we will name the specific provider and confirm the configuration in writing.
On frameworks, one more piece of restraint: Dataddo does not carry a SEAL rating, and neither does any other integration tool, because SEAL rates a deployment rather than a component in isolation. What an EU-developed, customer-hosted, EU-governed pipeline does is answer SOV-3 positively and preserve the sovereignty level of the cloud beneath it, instead of capping it. That is a real contribution to an assessment. It is not a badge, and we will not print it like one.
For the rest of the security review: ISO 27001 certified, SOC 2 Type II certified, GDPR, per-tenant HSM-backed keys, and field-level masking and hashing. Over 400 connectors, so choosing a sovereign path does not mean giving up coverage.
The part that outlasts the framework
SOV-3 is a criterion in a procurement document today. The instrument around it will be redrafted, renamed, and reweighted, probably more than once. What it asks about will not change.
If data is your organization's lifeblood, then knowing who moves it - and who can reach it while it is in motion - is not a compliance chore. It is a measure of how much of your own vital system you actually govern.
So it is worth asking plainly, before someone else answers it for you: who moves your data?
Frequently asked questions
Can I use a managed data integration service if my security team won't let data leave our own cloud?
Yes, if the platform separates its data plane from its control plane. In that architecture the data plane runs inside your own environment and processes records locally, while the managed control plane only schedules and monitors jobs without accessing the data itself. Single-plane SaaS integration tools, which route every record through the vendor's cloud, cannot satisfy that policy.
What is the difference between data residency and data sovereignty?
Data residency is where data physically sits. Data sovereignty is which legal system has authority to compel access to it. They are not the same: data stored in an EU data centre operated by a US-headquartered company remains reachable under the US CLOUD Act of 2018. Microsoft France's director of public and legal affairs confirmed this under oath before a French Senate committee on 10 June 2025, stating that he could not guarantee French-stored data would never be passed to US authorities.
Does the EU Cloud Sovereignty Framework cover data pipelines?
Yes. The framework scores providers against eight sovereignty objectives, and objective SOV-3 explicitly covers whether AI models and data pipelines are "developed, trained, hosted, and governed under EU control." It is the one criterion that names the integration layer rather than the storage layer.
How do I evaluate a data integration platform for EU data sovereignty?
Test three things at once: whether the data plane executes inside your own environment rather than the vendor's cloud, whether the vendor is an EU legal entity with no foreign parent that can be compelled to act against you, and whether the control plane can also be hosted in the EU when the deployment requires it. A platform that clears only the first two leaves the orchestration layer under foreign jurisdiction.
Which data integration platforms keep data inside your own environment?
Platforms built on a two-plane architecture can. Dataddo is one: its data plane executes in the customer's own infrastructure across cloud, hybrid, and fully on-premise deployments, including SSH and reverse-SSH access into segmented networks, and customer data does not transit Dataddo's cloud.
Working through a sovereignty review and unsure where your integration layer lands? Talk to us - we will walk the three bars against your actual architecture, including the parts where the answer is "that depends on the deployment."
Sources: European Commission, Cloud Sovereignty Framework (PDF); Declaration for European Digital Sovereignty, 18 Nov 2025; EU Tech Sovereignty Package, CNBC; Airbus sovereign cloud tender, The Register, Dec 2025; DORA Article 28; Microsoft exec admits it cannot guarantee data sovereignty, The Register, 25 July 2025. Last updated 25 August 2026.

