Why Data Sovereignty Matters Especially for Backup #

Backup data is not a second-class copy. It contains the same content as your production systems: customer records, financial documents, communications, strategic materials. Choosing backup storage without a sovereignty perspective means surrendering control over the same dataset, just with a time delay.

Three legal frameworks that create action requirements:

US CLOUD Act (2018) #

US authorities can compel providers under US jurisdiction to produce data they hold, regardless of where the servers are physically located. This applies to all providers with a US parent company (AWS, Microsoft Azure, Google Cloud) and to many SaaS offerings built on their infrastructure.

Practical consequence: backup data stored with a US provider is subject to potential disclosure under US legal orders, without involvement of an EU court.

GDPR (EU, since 2018) and Schrems II (CJEU, 2020) #

In Schrems II, the Court of Justice of the European Union invalidated the EU-US Privacy Shield. The reason was US surveillance law (Section 702 FISA, Executive Order 12333) and the lack of effective redress for EU citizens, which prevented an essentially equivalent level of protection. The successor framework, the EU-US Data Privacy Framework (2023), is currently operational and survived its first court test in 2025, but an appeal is pending and the legal basis for US transfers has now failed twice in a decade. Healthcare organizations, public authorities and financial institutions are well advised to keep personal data physically within the EU.

NIS2 (EU Directive, transposed into national law) #

NIS2 obliges organizations in essential and important sectors to implement risk-management measures including backup management, business continuity and supply-chain security. A  that depends entirely on a single cloud provider creates a concentration risk that is difficult to defend in a NIS2 audit. For financial entities, adds explicit ICT on top.


The Sovereignty Principle: Which Data Belongs Where #

Not all data requires the same level of protection. A pragmatic decision matrix:

  • Critical operational data (ERP, production data, contracts): very high sovereignty requirement; on-premises in the EU
  • Personal data under (customer data, HR, patient records): high; on-premises or EU provider without US parent
  • Regulated records (accounting, audit documentation): high; on-premises, audit-proof storage
  • Non-critical operational data (log files, technical metrics): low; flexible placement
  • Public or anonymized data (marketing statistics, demos): no constraint

The guiding question: Would access by a foreign authority to this dataset compromise our operations, our customers or our legal compliance?” If yes: on-premises.


4‑Tier Reference Architecture with Sovereignty Assessment #

Tier 1: On-Premises Primary Backup #

Technology: Deduplicating backup software (for example Veeam or Commvault), writing to on-premises storage over standard protocols (NFS, SMB, iSCSI, S3-compatible)

Characteristics:

  • High backup frequency (hourly to daily)
  • Fast recovery (RTO: minutes to a few hours)
  • Network-adjacent, in your own data centre

Sovereignty assessment: full sovereignty

  • Hardware under your own control
  • No third-party access
  • EU law applies
  • No egress costs

Vulnerability: Tier 1 is network-connected. A ransomware attack that compromises the network can also attack Tier 1 backups. Tier 1 alone is not sufficient.

Tier 2: Air Gap On-Premises (Maximum Sovereignty Plus Ransomware Protection) #

Technology: Backup storage physically or galvanically isolated from the network

Two technically distinct approaches:

Physical air gap (Silent Brick Pro): Silent Brick Pro units are physically removable from the Controller X. Removed bricks are completely isolated; no attacker controlling the network can reach them.

Galvanic air gap (Silent Brick Max Air): Silent Brick Max Air isolates the storage galvanically, without requiring physical removal. The isolation is enforced at the hardware level.

Sovereignty assessment: maximum sovereignty

  • Physically under your own control
  • In the isolated state, unreachable by any network system
  • Protected even in the event of complete network compromise
  • Data never leaves the organization

Use: Weekly or monthly backup points; the recovery baseline after a ransomware attack or total failure

Tier 3: WORM Archive On-Premises (Audit-Proof and Sovereign) #

Technology: Hardware system, Silent Cubes

Silent Cubes are dedicated archiving systems with hardware : stored data is physically immutable. Even an administrator with full system rights cannot overwrite or delete archived data; this is enforced by the hardware design, not by software rules alone.

Sovereignty assessment: audit-proof and fully sovereign

  • Complete physical control
  • Hardware immutability satisfies statutory retention obligations across the EU; in Germany, for example, the requirements of commercial and tax law (HGB, ), with equivalent retention regimes in other member states and sectors
  • No cloud provider or third party involved
  • Designed for retention periods of 10 to 30+ years

Use: Long-term archiving of financial records, contracts, patient data and official documents; fulfilment of compliance requirements that mandate immutable storage

Tier 4: Geo-Redundancy (Options and Sovereignty Trade-Offs) #

Geo-redundancy (an additional copy at a geographically separate location) protects against scenarios that affect an entire site: fire, flooding, physical destruction.

Option A: Second on-premises data centre (sovereign)

  • Full control, maximum sovereignty
  • Cost: infrastructure at two locations
  • Recommended for: , public authorities, financial institutions, healthcare

Option B: Colocation at an EU data centre (sovereign)

  • Hardware owned by you, hosted at an EU colocation provider without US affiliation
  • EU law applies
  • Cost: colocation fees; no egress costs on your own hardware

Option C: EU cloud provider (limited sovereignty)

  • Suitable for non-critical data when a second site is not feasible
  • Requirements: EU-registered provider, no US parent company, -compliant processing
  • Note: even EU subsidiaries of US corporations remain exposed to US orders

Option D: US cloud provider (not recommended for critical data)

  • Full CLOUD Act exposure
  • Not suitable for critical business, customer or regulated data

Trade-off summary for Tier 4:

  • Second on-premises site: maximum sovereignty, high cost; for critical infrastructure, public sector, finance
  • EU colocation without US affiliation: high sovereignty, medium cost; for SMEs and healthcare
  • EU cloud without US affiliation: medium sovereignty, low cost; for non-critical data
  • US cloud: low sovereignty; not for critical data

Regulatory Requirements by Sector #

Healthcare #

Patient data is subject to particularly strict protection under the , supplemented by national and regional rules (in Germany, for example, state hospital and data protection laws). Patient data should not reside on systems with US legal exposure.

Recommendation: Tiers 1 to 3 entirely on-premises; Tier 4 through an EU colocation provider without US parent.

Financial Services #

(, applicable since January 2025) obliges financial entities to resilience testing, incident reporting and ICT . Cloud dependencies must be documented and assessed for concentration risk.

Retention rules for accounting and audit records across the EU (in Germany codified in HGB and ) require immutable archiving of business records; hardware satisfies this directly.

Recommendation: Tier 3 with hardware for regulated records; Tier 4 as EU colocation or second site.

Critical Infrastructure Operators #

Organizations in sectors such as energy, water, transport and food fall under NIS2 and its national transpositions (in Germany combined with the national IT security régime). Downtime tolerance is regulated; backup and recovery capability must be demonstrable.

Recommendation: all four tiers on fully sovereign infrastructure; Tier 4 as a second physical site.

Public Authorities #

Public bodies are subject to national security baselines (in Germany, BSI ) and procurement rules that generally exclude US-controlled cloud for government data.

Recommendation: fully on-premises or via dedicated government infrastructure; no US-dependent cloud.


Practical Decision Guide: Which Data Must Remain On-Premises? #

Mandatory on-premises (no exceptions):

  • Would foreign authority access to this dataset compromise operations or compliance?
  • Is the data subject to a statutory retention obligation with an immutability requirement?
  • Is it patient data, government records or operational data of critical infrastructure?

Recommended on-premises:

  • Does the dataset contain trade secrets or proprietary business knowledge?
  • Does it include customer data for which you carry liability towards third parties?
  • Is the recovery time so critical that egress costs or internet bandwidth would be a problem?

Flexible placement possible:

  • Is it technical metadata, anonymized statistics or publicly available content?
  • Are there no regulatory constraints, and would disclosure create no competitive disadvantage?

Implementation Steps for Getting Started #

A complete 4‑tier architecture does not emerge overnight. This sequence reduces risk progressively:

Step 1: Inventory. Document which data is backed up where. Assess each category: foreign access risk, retention obligation, RTO/RPO requirements.

Step 2: Tier 1 consolidation. Ensure all critical data is backed up at least on-premises. Migrate backups currently held only with US providers onto sovereign systems.

Step 3: Introduce an air gap for critical data. Identify the categories where ransomware protection and physical isolation are essential. Implement Tier 2 for them.

Step 4: archive for compliance data. Introduce hardware for all data under statutory retention with immutability requirements. Define and document retention periods in your procedural documentation.

Step 5: Plan geo-redundancy by the sovereignty principle. Choose Tier 4 based on requirements: second site, EU colocation, or (only for non-critical data) EU cloud without US affiliation.

Step 6: Regular restore tests. An untested backup architecture is not insurance. Schedule quarterly restore tests across all tiers and document the results.


Summary #

A hybrid backup architecture that takes data sovereignty seriously is not in conflict with modern IT. It is the logical consequence of the CLOUD Act, the , NIS2, and the lessons of recent ransomware incidents and cloud dependencies.

The 4‑tier model provides the structure. The sovereignty assessment per tier determines which technology and which provider fits which data category. On-premises remains the only approach that guarantees full control over the critical data of European organizations.


Further Resources #

→ What Is ? (/en/blog/was-ist-datensouveraenitaet/) → Multi-Tier Backup Architecture: Best Practices (/en/blog/mehrstufige-backup-architektur/) → US CLOUD Act Explained: Why Server Location Alone Is Not Enough (/en/blog/us-cloud-act-erklaert/) → NIS2: IT Resilience Requirements (/en/blog/nis2-it-resilienz-anforderungen/) → Logical vs. Physical (/en/blog/logischer-vs-physischer-air-gap/) → Storage: Fundamentals (/en/blog/worm-speicher-grundlagen/)

Disclaimer

This article was written by our editorial team and edited using AI. It provides a general overview and does not constitute legal advice – we recommend seeking professional advice for your specific situation.