Skip to main content

Operations, Systems & Owner Dependency

Data Sovereignty for UK SMEs

Data Sovereignty for UK SMEs

TL;DR “Data sovereignty” isn’t a government problem; it’s a business one. If your cloud provider is US-owned, such as Microsoft, Google or Amazon, it can be legally compelled to hand over your data, regardless of where the server sits. UK SMEs need to know this for client due diligence, contracts and risk management, not to panic or switch software. This guide sets out the basics, with links to more detail.

Why this has suddenly become a talking point

In September 2026, the Swiss government announced a pilot to move 3,000 federal workstations from Microsoft 365 to openDesk, an open-source alternative, citing cost and digital sovereignty as the reasons. It’s the latest in a run of similar moves: Denmark’s Ministry of Digital Affairs migrating away from Microsoft 365, France banning non-European videoconferencing tools from government use, and the Netherlands demanding exit strategies from US cloud providers.

None of this is really about software preference. It’s about a legal question that most SMEs have never had reason to think about: who can be compelled to hand over your data, and under what law?

The basic legal mechanism

The US CLOUD Act (2018) allows US authorities to compel a US-headquartered company to produce data it controls, wherever in the world that data physically sits. A provider’s UK or EU data centre doesn’t block this, because the compulsion is aimed at the company, not the building. If Microsoft, Google or Amazon is legally US-owned, then in principle your data is reachable under US law even if it never leaves a data centre in Reading or Amsterdam.

This creates a genuine tension with UK GDPR, which expects organisations to protect personal data against unauthorised access, including by foreign governments. There’s no UK court precedent testing exactly how this plays out, and no firm ICO guidance telling businesses what to do about it. It’s an unresolved conflict between two legal systems, not a settled question with a clean answer.

Why this isn’t just a government-scale issue

It’s tempting to read all of this as something for Whitehall and multinational corporations to worry about. For most SMEs, the exposure is unlikely to mean an actual data request ever lands on your desk. But there are three ways it becomes a genuinely practical business issue:

  • Client and tender requirements. EU clients in particular increasingly ask where data is processed and who controls it, as standard due diligence. Not having a clear answer can cost you the contract.
  • Contractual obligations. Confidentiality and data-residency clauses are common in professional services and hospitality contracts. If you can’t demonstrate you’ve thought about this, you may be in breach without realising it.
  • Insurance and risk assessment. Cyber insurers are starting to ask more detailed questions about data governance, not just security posture.

What UK SMEs can actually do about it

You don’t need to migrate off Microsoft 365 tomorrow, and for most businesses that wouldn’t be proportionate. What’s worth doing instead:

  1. Know who legally owns your providers. Not just where the servers are, but who the parent company is.
  2. Ask providers about encryption key control. If you hold the encryption keys rather than the provider, the provider may be technically unable to hand over readable data even under a valid order.
  3. Check your contracts. Look for data-residency or data-sovereignty clauses you’ve already signed up to, and make sure your actual setup matches what you’ve promised clients.
  4. Have an answer ready. Even a brief, honest explanation of where data sits and who controls it is better than being caught out by the question.

Where the UK stands

Unlike Switzerland, France or the Netherlands, the UK government has no overarching digital sovereignty strategy. It has set out an approach to building “sovereign capability” in specific technologies, but there’s no equivalent of the Swiss pilot or the French ban on non-European tools. This means UK SMEs are, in practice, on their own when it comes to assessing this risk. Nobody is going to mandate a solution for you, which makes it more important to understand the basics rather than less.

Frequently asked questions

Does storing my data in a UK data centre protect it from the US CLOUD Act? No. The CLOUD Act applies based on who legally owns and controls the provider, not where the server is physically located. A UK data centre owned by a US company doesn’t remove the exposure.

Is this actually illegal under UK GDPR? It’s a legal grey area rather than a clear breach. UK GDPR requires organisations to guard against unauthorised access, but there’s no UK case law establishing exactly how CLOUD Act exposure should be treated, and no specific ICO guidance on it yet.

Do I need to stop using Microsoft 365 or Google Workspace? Not necessarily. For most SMEs, switching providers isn’t proportionate to the actual risk. What matters more is understanding your exposure, checking your contracts, and being able to answer the question if a client or auditor asks.

What’s the single most useful thing I can do this month? Find out whether your cloud provider gives you control of your own encryption keys. If you hold the keys and the provider doesn’t, that’s the most concrete technical safeguard available without changing software.

Is this only relevant to businesses that work with EU clients? No, though it’s most acute there. UK-only businesses can still be affected through insurance requirements, sector-specific regulation, or simply good governance practice, but the pressure is currently strongest from EU-facing contracts and tenders.


This is the first in our Data Value series, looking at what data ownership and control actually mean for UK SMEs. Read on for a deeper look at [the CLOUD Act explained], [what to ask your cloud provider], and [what to say when a client asks where your data is stored].

About this guidance

Sources and guidance are checked for relevance before publication. Where decisions affect legal, financial or regulatory duties, obtain advice for your circumstances.

More useful guidance

Related to this issue