When a European business contracts an email service, it rarely asks which law that service is subject to. It asks about price, storage and whether it works in Outlook. And yet that is the question that determines everything else, because data does not live only in a place: it lives under a jurisdiction. Over the last decade it has become clear that those two things may not coincide.
Two different grammars
The European legal tradition thinks of sovereignty in terms of territory. The law applies to what happens within borders, and the GDPR extended that logic: Europeans' data travels protected, and may only leave the Union for countries that offer equivalent safeguards.
The American tradition starts from another principle. The connecting factor is not the soil, it is the person: nationality and, above all, control. A company incorporated in the United States, or controlled by an American company, remains subject to American law wherever it operates and wherever it stores what it stores. It is neither an anomaly nor a manoeuvre. It is how that system understands its own authority.
As long as the two worlds did not touch, the difference was a matter for textbooks. Once the entire economy came to live on servers, it became the central problem of European digital sovereignty.
How the American model gained global reach
The turning point was October 2001. After 9/11, the Patriot Act significantly expanded intelligence-gathering powers, with an implicit principle that would shape the following two decades: in matters of national security, access to information prevails over objections of form.
What followed was more decisive than the Patriot Act itself. In 2008, Section 702 of FISA authorised the collection of communications of non-US persons located outside the United States, from American electronic service providers, for foreign intelligence purposes. Without the targets being notified, and without them having any means of defence comparable to those in Europe.
Note the construction. The law does not protect foreigners less by oversight. It protects them less by design, because the Fourth Amendment is a right of Americans.
2013: the year the debate stopped being technical
In June 2013, Edward Snowden's revelations showed the real scale of the collection programmes. But it was in October that the issue went from expert debate to diplomatic crisis: documents indicated that the NSA had been monitoring Angela Merkel's mobile phone. The Chancellor's reaction entered the European vocabulary, "spying among friends, that's just not done", and the unease between Berlin and Washington lasted for years.
Honesty about the detail matters. The German criminal investigation was eventually closed in 2015, because the available documents did not make it possible to prove where and how the interception had taken place. What was proven was not the crime. It was the asymmetry. A European government discovered that it did not control the confidentiality of its own communications, and that it had no instruments to challenge this.
The case that settled the question for good
The decisive proof came through ordinary law, without scandal. In December 2013, an American warrant required Microsoft to hand over the contents of an email account. The company found that the messages were in a data centre in Dublin and refused to hand them over, with a simple argument: a United States warrant does not reach a server in Ireland. In 2016, the Court of Appeals ruled in its favour.
It lasted two years. In March 2018, Congress passed the CLOUD Act, which required American providers to hand over data in their possession, custody or control, whether that data is inside or outside the national territory. A new warrant was issued under the new law, Microsoft complied, and the Supreme Court declared the case moot.
The lesson is clear and still relevant: building a data centre in Europe does not change the jurisdiction of whoever operates it. The physical location of the servers is an answer to the wrong question.
The European response, three times insufficient
On the European side, the solution attempted was always the same: a political agreement declaring the United States a safe destination for data.
Safe Harbor fell in 2015, in the Schrems I judgment. The Privacy Shield that replaced it fell in 2020, in Schrems II, with the Court of Justice concluding that American surveillance legislation offered neither equivalent safeguards nor effective remedies to European citizens. The third agreement, the 2023 Data Privacy Framework, rested on one essential piece: the existence of administrative authorities independent of the American executive.
In June 2026, that piece was removed. The US Supreme Court decision in Trump v. Slaughter ended the independence of the Federal Trade Commission, and the challenge to the agreement, already treated by many as the future "Schrems III", is once again under way.
Three agreements, three weaknesses of the same kind. Not because of bad faith by those who negotiated them, but because no political agreement can reconcile two incompatible definitions of sovereignty.
What this means for decision-makers
For a European business or public body, the practical conclusion is less dramatic than it seems, and more actionable.
The question to ask a provider is not where the servers are. It is which law the entity operating them is subject to, and who controls it. If the answer involves an American company or one controlled by it, the organisation's compliance comes to depend on the validity of an international agreement that has already fallen twice and is being challenged for the third time.
If the answer is a European company, European-owned and subject only to European law, the question disappears. Not because someone promises more, but because there is no second law claiming access.
For professions with a duty of confidentiality, the reasoning is even more direct. A lawyer, a doctor or a public administrator is not only answerable for what they disclose. They are answerable for the architecture they chose to keep what cannot be disclosed.
Digital sovereignty is not a flag. It is knowing, precisely, whom the infrastructure holding your organisation's information answers to.
