# Data Sovereignty Data sovereignty is the principle that data is subject to the **laws of the jurisdiction where it lives** — and the practice of choosing where it lives accordingly. Distinct from [[Data Ownership]] (who holds rights to the data): you can fully own data that sits on a US-controlled cloud, and the US CLOUD Act still reaches it. Ownership is about rights; sovereignty is about reach. ## Three terms people conflate - **Data residency** — where data is physically stored (a location fact) - **Data sovereignty** — whose laws apply to it (a legal consequence of residency *and* of who operates the infrastructure) - **Data localization** — a legal *requirement* that certain data stay in-country (the strictest form) The operator question is the one that bites: EU-resident data in an EU datacenter run by a US hyperscaler remains exposed to US legal process. That tension — GDPR and Schrems II on one side, the CLOUD Act on the other — is why "EU region" checkboxes never fully settled the compliance argument, and why European sovereign-cloud offerings and self-hosting keep coming back. ## Why it matters more with AI Every AI API call exports data to wherever the provider processes it. Data sovereignty is the legal backbone of the [[Sovereign AI]] argument: [[Apertus]]-style national models and self-hosted deployments (a single-container [[Mistral OCR 4]], local open-weight models) exist largely so regulated data never crosses a border. At personal scale, [[Local-First Software]] is data sovereignty by construction — no jurisdiction question when the data never leaves your disk. ## Related - [[Data Ownership]] — rights, not jurisdiction - [[Sovereign AI]] — the capability layer this underpins - [[Local-First Software]] · [[File over app principle]] - [[AI Wiki - PKM - Local-First and Data Sovereignty]]