Digital sovereignty: what the EU Data Boundary does and does not solve
Robin Damen ā managing director of Virtual Computing, 20+ years of MSP experience
Two years ago digital sovereignty was a debate for government ministries and healthcare umbrella organisations. Today the question shows up in ordinary SMB procurement terms: *where is our data, who can access it, and under which jurisdiction does that fall?* Not because everyone suddenly became a lawyer, but because clients pass the question down to their suppliers ā exactly as happens with NIS2.
Microsoft has delivered substantially on this over the past year. The EU Data Boundary is complete, and the sovereignty portfolio has expanded considerably. This article explains what that actually solves, what it does not solve, and how to make a sensible choice as an SMB without ending up in a trench war of principle.
What the EU Data Boundary is
The EU Data Boundary means Microsoft stores and processes customer data and pseudonymised personal data for its core services within the EU and EFTA countries. That now applies to Microsoft 365, Dynamics 365, Power Platform and the vast majority of Azure.
What matters about the latest expansion round: the boundary now also covers the parts that previously fell outside it ā AI processing, Copilot interactions, telemetry and confidential computing. For Microsoft 365 Copilot, processing has additionally been pulled in-country across a growing number of countries.
That is more than a marketing promise. For the most frequently asked question ā "is our mail sitting in America?" ā the answer for European customers is now simply no.
Sovereignty is more than where the disk sits
The more interesting shift is in how Microsoft reframes the question itself. Sovereignty has long stopped being only about data residency; it breaks down into four questions you need to answer separately:
| Question | What it covers | What to ask yourself |
|---|---|---|
| Data sovereignty | Where data is stored and processed | Does everything stay inside the EU, including backups and logging? |
| Operational sovereignty | Who administers the system | Can an administrator outside the EU access my environment? |
| Technology sovereignty | Where the software comes from | Can I leave if the vendor or the pricing changes? |
| Infrastructure sovereignty | Whose hardware it runs on | Is this public cloud, or infrastructure that can be isolated? |
Most organisations that say "we want sovereignty" actually mean one or two of these four. It pays to get that clear first ā it saves a lot of expensive solutions to problems you do not have.
What the EU Data Boundary does not solve
Honesty is called for here, because it tends to be missing from the brochures. The US CLOUD Act has not been repealed. As long as a US parent company controls a service, US authorities can in theory demand data ā regardless of where that data physically sits. Microsoft contests this legally and publishes transparency reports about it, but it cannot offer an absolute guarantee. Microsoft does not claim otherwise.
For the vast majority of SMBs that is an acceptable residual risk: the chance that a US prosecutor takes an interest in the quotations of an installation company in Brabant is negligible. But it is the point where the discussion tips for some sectors ā healthcare, legal, defence-related supply chains, and organisations under an explicit instruction from their own regulator.
How to approach this practically as an SMB
Not all-or-nothing, but per type of data. This is how we handle it with clients:
| Type of data | Sensible location | Why |
|---|---|---|
| Email, calendar, collaboration | Microsoft 365 within the EU Data Boundary | Usability weighs heavily, sensitivity is usually limited |
| Business files and line-of-business software | Online workspace in a Dutch data centre | Full control over storage, backup and administration |
| Heavily regulated data (healthcare, legal) | Dutch hosting with ISO 27001, plus NEN 7510 for healthcare | Demonstrability towards regulators and clients |
| Backup of your Microsoft 365 data | Separate from Microsoft, in the Netherlands | Microsoft does not back up your data ā see Microsoft 365 backup |
That last row is structurally overlooked. The EU Data Boundary is about *where* your data sits, not about whether it is retained. A deleted mailbox or a ransomware encryption is not a residency issue.
Where we stand ourselves
We believe you can only give this kind of advice if you practise it. Our online workspaces and cloud servers run in Dutch, ISO 27001-certified data centres, administered by a Dutch team. Last year we also moved our own virtualisation layer from VMware to XCP-ng ā partly for cost reasons, partly because we did not want to depend on a single vendor that can overturn its licensing model overnight. That story is in from VMware to XCP-ng.
At the same time we are not an anti-Microsoft outfit. For mail, collaboration and Office, Microsoft 365 is simply the best choice for SMBs, and with the EU Data Boundary the biggest objection on paper has been removed. The art is in the combination: Microsoft where it is strong, Dutch hosting where control matters.
Four questions for your IT provider
If you want to know how sovereign you actually are, ask these four:
- In which country is our data ā and where are the backups? Those two answers differ surprisingly often.
- Who can technically access it, and from which country? Operational sovereignty is rarely verified.
- What happens if we want to leave? Do we get our data in a usable format, and within what timeframe?
- Where is this recorded? In the data processing agreement, or only in a sales pitch?
We answer all four in writing. If your current provider does the same, you are in good shape ā and we will simply say so.
Want us to take a look?
Unsure where your data sits and whether that matches what your clients expect of you? Take the free IT check ā seven questions, and you receive a personal roadmap. Prefer to discuss your cloud setup directly? Book a consultation, no obligation, via Teams or by phone. Already know what you need? Request a quote.
*This article describes the situation as of August 2026 based on Microsoft's publications on the EU Data Boundary and the Sovereign Cloud portfolio. It is a high-level explanation and not legal advice.*
Written by
Related articles
What is a cloud workspace?
Nowadays we see many companies working in the cloud, but what exactly is a cloud workspace and how does it work?
CloudWhat is cloud computing?
To answer the question 'what is cloud computing,' we explain in this blog what it entails and what benefits it offers.
CloudWhat is a Cloud Server and How Do We Use It?
A cloud server is a virtual server that runs on a cloud computing platform. At Virtual Computing we use these servers to give businesses flexible and scalable cloud workspaces.