Glossary
Key terms and definitions for European digital sovereignty. This glossary defines terms as used within SovereigntyScore and related European digital sovereignty discussions. These definitions are intended to be neutral, factual, and suitable for citation.
Digital sovereignty
Digital sovereignty is the capacity of individuals, organisations, or states to maintain meaningful control over their digital infrastructure, data, and technological dependencies. It encompasses data residency, operational control, provider jurisdiction, and the ability to switch providers or operate independently.
Data residency
Data residency refers to the physical or geographic location where data is stored and processed. Data residency requirements may be imposed by regulation, contract, or organisational policy. Data residency alone does not determine legal jurisdiction over that data.
Jurisdictional risk
Jurisdictional risk is the exposure created when data or systems fall under the legal authority of a government whose laws may conflict with an organisation's interests or regulatory obligations. This risk is determined primarily by where a provider is legally incorporated, not where data is physically stored.
CLOUD Act
The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) is a US federal law enacted in 2018. It allows US law enforcement to compel US-based technology companies to provide data in their possession, custody, or control, regardless of where that data is physically stored. The CLOUD Act creates jurisdictional exposure for organisations using US-headquartered providers.
EU-first architecture
EU-first architecture is a design approach that prioritises European-headquartered providers for data processing and storage, particularly for sensitive workloads. This approach aims to reduce jurisdictional risk from extraterritorial data access laws while maintaining operational capability.
Data controller vs data processor
Under GDPR, a data controller determines the purposes and means of processing personal data, while a data processor processes data on behalf of the controller. The controller bears primary responsibility for compliance. Most SaaS vendors act as data processors, but the distinction affects liability, contractual obligations, and audit requirements.