Glossary · Privacy & regulation
Data sovereignty
Data sovereignty is the principle that data is subject to the laws of the jurisdiction that governs it — broader than data residency, since a legal claim can reach across borders regardless of where servers physically sit.
The distinction from residency matters in practice: a server in Switzerland is subject to Swiss law by residency, but if the company operating it is a US-headquartered entity, US laws with extraterritorial reach — the CLOUD Act being the frequently cited example — can potentially compel disclosure of data the company controls, wherever it’s stored. Sovereignty asks who can lawfully compel access to the data, not merely where the disks are.
This is why sovereignty-conscious organizations look past the marketing claim of "data stored in country X" to ask which legal entity controls the infrastructure, what jurisdiction that entity is incorporated and headquartered in, and what legal process could reach it. A jurisdiction with strong statutory protections and no extraterritorial-reach conflicts is a stronger sovereignty position than residency alone provides.
Ciphera’s infrastructure runs on Exoscale, a Swiss-headquartered cloud provider, hosted in Zurich — aligning both residency and the operating entity’s jurisdiction with Switzerland’s FADP regime, rather than relying on residency in a jurisdiction whose data could still be reached through a foreign parent company’s legal obligations.