← All articles

Security & Architecture

Data sovereignty: assess the architecture, not just the location.

Data location, legal exposure and technical control are different questions. A sound cloud decision examines all three for the actual workload.

Drazen Nikolic · Published 24 Jan 2026 · Revised

Start with the workload

Classify the data, identify who needs access and document recovery, latency and connectivity requirements. Include backups, logs, management services, support and external integrations in the data-flow model. A region setting alone does not describe the whole system.

The CLOUD Act and data location

US jurisdiction can be relevant even when data is stored in Europe. Location alone does not eliminate legal access questions. Assess applicable law, provider commitments and the actual technical access model with the responsible legal and data-protection specialists. A technical architecture review cannot establish legal immunity.

What the EU Data Boundary covers

Microsoft’s EU Data Boundary commitments cover defined enterprise online services in the EU and EFTA. The commitments distinguish customer data, personal data in system-generated logs and professional services data. Scope depends on the service and configuration; Microsoft documents limited transfers outside the boundary. This is not a blanket promise that every data category in every Microsoft service always stays in the EU.

Azure Local: local workloads with a defined service scope

Azure Local extends selected Azure capabilities to customer-owned environments. It is not the entire public Azure portfolio on premises. Connected and disconnected deployment models have different prerequisites and available capabilities. Examine identity, management, telemetry, updates, backup and support paths for the selected model before making residency claims. Local workload execution does not by itself prove that no data leaves the site.

Microsoft 365 Copilot and local AI are different architectures

Microsoft 365 Copilot operates within the Microsoft 365 service boundary and accesses organizational content according to user permissions. It is not an on-premises installation of Microsoft 365 Copilot. Local model inference or a custom RAG application is a separate architecture with its own functionality, identity model and operating requirements.

Customer-managed keys are not an automatic access barrier

Customer-managed keys add control over key lifecycle, access policies and cryptographic operations. In server-side encryption designs, an authorized service can use keys to process data. CMK therefore does not automatically prevent the service from accessing plaintext during normal operation. Evaluate key location, permissions, caching, rotation and recovery for each service.

Confidential computing addresses data in use

Confidential computing uses hardware-based trusted execution environments and attestation to protect data during processing. It complements encryption at rest and in transit. Its protections depend on the selected technology, threat model, configuration and application design; it is not a universal sovereignty or compliance guarantee.

Choose controls against requirements

Compare public cloud, hybrid and local options against the same requirements. Provider certifications are evidence within a defined scope, not automatic certification of your workload. Record residual risks, ownership, test results and the reasons for the architecture decision. The result should be a defensible decision for your team, not a general endorsement or rejection of a provider.

Sources & further reading

Technical documentation consulted on 14 September 2026. Product scope and availability may change.