The Cloud
29 June 2026
For a UK organisation, cloud sovereignty is best understood as a layered control objective. It covers where data is stored and processed, which laws and transfer rules apply, who can administer the service, how encryption keys are controlled, which suppliers and sub-processors are involved, and whether the service can survive disruption without breaching legal or business obligations. The NCSC’s cloud guidance is clear that cloud decisions must account for legislation, physical and legal jurisdiction, resilience, identity, supply chain security and customer control.
It also helps to separate three ideas that are often muddled together at board level. Data residency is about where data sits. Data localisation is a stricter legal or policy requirement to keep data in a place. Cloud sovereignty is broader: residency plus operational control, legal exposure and resilience. Microsoft’s EU Data Boundary shows why that distinction matters: even where data is committed to EU/EFTA processing and storage, some transfer scenarios can still occur for support, security operations, routing or customer-initiated actions.
The core legal principle is clear, though its application can be complex. The ICO says personal data must be processed securely with “appropriate technical and organisational measures”, and it requires written controller-processor contracts plus equivalent protections for sub-processors. Its transfers guidance sets out when international transfer rules apply and, as updated in January 2026, explains the need for a transfer risk assessment — now referred to in UK legislation as a “data protection test”.
The resilience and geopolitical case is just as important. NCSC supplier guidance warns organisations to consider supplier ownership and control because some countries have extra-territorial laws; its supply-chain guidance notes that vulnerabilities can be introduced and exploited at any point in a complex supplier chain; and the NCSC Cyber Assessment Framework makes plain that using third parties does not remove accountability. Meanwhile, the UK NIS Regulations already apply to cloud computing services, the Cyber Security and Resilience (Network and Information Systems) Bill broadens that regime. NIS2 also raises the EU cyber security baseline across a wider range of sectors. It may apply directly to some UK organisations operating or providing certain services in the EU, while others may encounter its requirements indirectly through customer contracts and supply-chain assurance.
UK public-sector guidance adds an important nuance. OFFICIAL-SENSITIVE is a handling caveat, not a separate classification, and there is no universal requirement for OFFICIAL data to be physically hosted in the UK if satisfactory safeguards exist. Government guidance now recommends a controlled multi-region approach where lawful and appropriate, precisely because resilience, capacity and access to innovation also matter. That is a useful reminder for private-sector boards too: sovereignty should strengthen continuity, not accidentally weaken it.
There is no single “correct” model. The NCSC’s guidance applies across public cloud, hybrid, multi-cloud and larger private-cloud deployments, and stresses that deployment choice changes the separation mechanisms, responsibilities and resilience options available to you.
| Model | What it controls | Strengths | Limitations | Best use cases |
| Data residency | Primary storage and processing location | Useful baseline for regional compliance and latency | Does not, by itself, control support access, telemetry, routing or onward transfers | UK/EU customer data with moderate sovereignty requirements. |
| Data localisation | Storage and processing kept in a specific country by law or policy | Strongest location control | Can narrow provider choice and recovery options; the EU has sought to remove unjustified localisation restrictions for non-personal data | National-security or strictly regulated domestic workloads. |
| Sovereign public cloud | Residency plus operational, legal and administrative controls | Preserves more hyperscale capability with added safeguards | Scope varies by provider and service set | Regulated sectors that still want managed hyperscale services. |
| Private cloud | Dedicated environment and bespoke governance | Greater scope for dedicated infrastructure and bespoke controls. | More customer responsibility for security and operations | Highly sensitive or heavily customised workloads. |
| Hybrid or multi-cloud | Splits workloads across environments with policy overlays | Flexible matching of data, performance and resilience needs | Governance can become complex | Mixed estates, phased migration and resilience-led designs. |
| Edge with sovereignty controls | Local processing near the workload, often with central cloud management | Helps uptime and low latency; can reduce data movement | Still depends on cloud control planes and separation mechanisms | OT, branch, retail, manufacturing and latency-sensitive use cases. |
The benefits are real: clearer legal positioning, tighter control over privileged access, better evidence for auditors and, when done properly, stronger business continuity. The dilemmas are real too: stricter geographic constraints can add cost and complexity, sovereign features differ by provider, and portability matters because lock-in is a board-level risk — one reason the EU Data Act now sets rules to support switching between data-processing providers. A useful rule of thumb is this: sovereignty is easier to market than to verify.
A sensible UK approach is usually contractual, technical and operational at the same time. Start by mapping data classes and transfers; define which workloads really need domestic hosting, which need EU-only administration, and which mainly need stronger encryption and access control; then test vendors against those requirements, not against marketing slogans. The NCSC Board Toolkit is useful here because it frames cyber risk as a board responsibility across strategy, supply chain, incident response and assurance.
A practical checklist for directors is:
A carefully governed hybrid or multi-cloud model may help separate workloads and reduce particular concentration risks. However, it can also increase operational complexity, so it should be adopted only where the resilience and control benefits justify that complexity.
The major vendors now all offer sovereignty features, but in different ways. AWS says its European Sovereign Cloud is a separate, independent cloud wholly located in the EU, with day-to-day operations controlled by EU-resident personnel in the EU during transition to EU citizens in the EU. Microsoft Sovereign Cloud supports public sovereign regions and private disconnected environments, while its EU Data Boundary documentation openly states that some transfer scenarios still continue. Google’s Sovereign Controls by Partners model uses partner-operated controls and explicitly includes data residency, encryption and key-management features such as Cloud EKM, Access Transparency and Key Access Justifications. In the UK market, providers such as Pulsant position UK-hosted private and IaaS platforms as a sovereignty option, typically paired with connectivity into global hyperscalers.