Skip to content

Data sovereignty

Where your data lives is the easy half.

Choosing a UK or EU region takes a minute. Knowing who can be compelled to hand your data over takes longer, and that is the question that decides what you are allowed to build.

Three terms that get used interchangeably

They mean different things, and the difference is usually where the expensive surprise lives.

Data residency

Where the data physically sits. A region setting in a cloud console. It is the easiest of the three to change, and the one most often mistaken for the whole answer.

Data sovereignty

Which country's laws apply to that data, which is not always the country it sits in. A US-owned provider hosting in Frankfurt is EU-resident and still reachable under US law. Residency is geography. Sovereignty is jurisdiction.

Data localisation

A legal requirement that specific data must not leave a territory. Rarer than assumed in UK and EU finance, but absolute where it applies, and it removes options rather than adding cost.

Two regimes, not one

Since Brexit the UK and the EU are separate regimes with separate obligations. Most UK finance firms serving EU clients are subject to both at once.

United Kingdom

UK GDPR and the Data Protection Act 2018. Transfers out of the UK need an adequacy decision or their own safeguards. The UK's adequacy from the EU is granted, reviewed, and not permanent, which makes it a planning assumption rather than a settled fact.

European Union

EU GDPR, with transfers governed by adequacy decisions and standard contractual clauses. For a UK firm serving EU clients both regimes apply at once, and the stricter one sets the design.

Where does your site send its visitors?

Enter an address and see which organisations receive a visitor's data before anyone agrees to anything. This reports what loads and from where. It is not a compliance assessment, and it does not attempt one.

One page load, no consent clicked, from a UK address. Nothing kept beyond the domain. Your domain never goes to a commercial geolocation or data-broker service: the vendor and country lookups run against a local copy of the internet registries, and the one external query is to the registry’s own record for a single IP address.

What happens after the check

The test above is one reading, taken once. The work is the loop it belongs to, and the same instrument runs every stage of it.

  1. 01

    Find

    Every question your buyers actually put to the AI engines, and every page of yours that answers one. Not a capped sample of a few hundred prompts: the whole set, which is the difference between a survey and an inventory.

  2. 02

    Measure

    One crawl, two readings. Where your data goes and who receives it, alongside whether the engines name you and who they name instead. Both come from the same page load, so they cannot disagree about what your site does.

  3. 03

    Fix

    Page by page, against real URLs: what to remove, what to bring in-house, what to answer and where. Each proposal sits beside what the page says today, so you approve a change rather than receive a document.

  4. 04

    Prove

    The instrument re-runs and shows what moved. A fix that changed nothing is visible, which is the whole reason to measure before and after rather than only after.

The instrument behind it

This check shares its crawl with the AI visibility work, and that side of the platform has been reading answers since May. These are counts of what has actually been processed, not an estimate of reach.

9.6 million
words of AI answers read
204,422
citations analysed
23,976
distinct domains seen cited
5,623
questions monitored across five engines

Aggregated across engagements since 10 May 2026. The sovereignty check itself reads one page load of your site and keeps nothing beyond the domain.

Questions

What is data sovereignty?
Data sovereignty is the principle that data is subject to the laws of the country it is held in. In practice it decides which government can compel access to your data, which is a different question from where the servers are.
What is the difference between data sovereignty and data residency?
Data residency is where the data physically sits. Data sovereignty is which laws reach it. They diverge whenever the provider is owned in one jurisdiction and hosts in another: a US-owned cloud running in Frankfurt gives you EU residency without EU sovereignty, because the parent company remains subject to US legal process.
Does using a UK or EU region make us compliant?
Not by itself. Choosing a region settles residency. Compliance also depends on who owns the provider, what the contract says about onward transfers and sub-processors, and whether a lawful basis exists for the processing at all. The region setting is the easiest part and the least decisive.
We are in the UK but not the EU. Which rules apply?
Both, usually. UK GDPR governs what you do at home. If you hold data on people in the EU, EU GDPR applies to that processing regardless of where you are. Most UK finance firms design to the stricter of the two rather than maintain two architectures.
Does this mean we cannot use ChatGPT or Claude?

No, and treating it as a ban is how shadow usage starts. It means knowing what leaves your estate, under which terms, and having a sanctioned route for the cases where it must not. Enterprise agreements cover a great deal. A self-hosted model covers the rest.

Is this a legal service?

No. This is architecture and implementation. The obligations are established with your own counsel or DPO, and the work is building a system that satisfies them and proving that it does. Where a question is genuinely legal, it goes to a lawyer.

Where this stops being theory

It becomes an engineering question the moment AI sits in front of internal data. Every prompt is a transfer, and most tools are silent about where it goes.