Sovereignty

Digital sovereignty: why the Cloud Act changes your architecture

Where your recordings live has stopped being a technical decision. It is a decision about legal exposure, and it belongs to the board.

Digital sovereignty: why the Cloud Act changes your architecture

For years, data location was treated as a question of latency, cost and availability, a matter for systems architects rather than for directors. The Clarifying Lawful Overseas Use of Data Act, known as the Cloud Act, changed that framing. From the moment a provider falls under United States jurisdiction, the question stops being «where is the data?» and becomes «who can demand it, and which law governs whoever holds it?». For an archive of compliance recordings, that question belongs to the board.

What does the Cloud Act actually establish?

The Cloud Act, passed in 2018, provides that a service provider subject to US jurisdiction can be compelled to hand over data under its control, whether that data is physically stored in the United States or in a European data centre. The decisive test is not geographical, it is control by the entity. A data centre in Lisbon operated by a US parent company is not, for that reason, beyond the reach of the Cloud Act.

This logic runs into direct tension with the GDPR, which restricts transfers of personal data to third countries and requires a legal basis for any disclosure to foreign authorities. In practice, the organisation is caught between two legal orders that may demand incompatible things.

Why does this matter for compliance recordings?

Recordings subject to MiFID II or required by DORA are not ordinary files. They contain personal data, market information, orders, positions and, frequently, clients’ trade secrets. A compelled disclosure under a foreign order can amount, at the same time, to a GDPR breach and to a breach of contractual confidentiality. The risk stops being technical and becomes reputational and legal.

The question the board has to be able to answer is not «is our data encrypted?». It is «if a foreign authority demands our recordings from our provider, can that provider hand them over, legally and technically, without our knowledge?».

What architectural options exist, without illusions?

There is no single answer. There is a spectrum of options, each with a different exposure profile:

  • On-premise: the archive sits on infrastructure the organisation controls. Maximum sovereignty, in exchange for full operational responsibility for resilience and security.
  • Sovereign private cloud: dedicated infrastructure, operated by an entity under European jurisdiction, with no dependency on control by foreign third parties.
  • National cloud: providers established in the territory, subject exclusively to Union and national law, outside the reach of the Cloud Act.
  • Foreign hyperscaler: convenient and mature, but with a structural exposure that no contractual clause removes entirely.

Does encryption solve the problem?

Double encryption, where data is encrypted at rest and key management stays exclusively on the organisation’s side, is a real defence. If the provider never holds the keys, a disclosure order returns nothing but useless ciphertext. But this architecture only works if custody of the keys is genuinely beyond the provider’s reach, otherwise it is an apparent guarantee. Sovereignty over the keys matters as much as sovereignty over the data.

Why is this a board decision?

The choice between these architectures determines how exposed the institution is, legally, to a foreign order. It is not a decision that can be delegated to the infrastructure team, because it involves a trade-off between operational convenience, cost and legal risk that only the management body has the mandate to arbitrate. DORA reinforces the point by making the management body directly accountable for resilience and for the risk attached to third-party ICT providers.

It is worth being clear about what a contractual clause can and cannot do. Providers offer, quite reasonably, data residency commitments, notification guarantees and mechanisms for challenging requests. Those commitments have value and they reduce risk. What they cannot do is change the law the provider is subject to. A clause promising to notify the client before handing over data is useless if the order arrives with a gag provision attached. An honest analysis therefore starts with the provider’s jurisdiction, not with the drafting of the contract.

Where the recordings live is today one of the few architectural decisions with a guaranteed seat in the boardroom. Treating it as a technical detail is the mistake that turns out, later, to be expensive. Treating it as an exposure decision, documented, deliberate and reviewed, is what separates an organisation that controls its archive from one that merely hosts it.

Published by the uPlayback team, a Grupês product. Three decades of experience in compliance recording.

Continue reading

More from our blog.

MiFID II: the seven questions an auditor asks first MiFID II

MiFID II: the seven questions an auditor asks first

Before asking for recordings, the regulator tests whether you can find them, evidence them and retain them. A guide to the questions that decide…

Read article →
DORA in practice: RPO, RTO and the end of the generic DR plan DORA

DORA in practice: RPO, RTO and the end of the generic DR plan

Since January 2025, operational resilience is a regulatory outcome, not a document. What that demands of every capture pipeline.

Read article →
Voice, chat and email: why three systems are a risk Platform

Voice, chat and email: why three systems are a risk

Compliance fails at the seams. A single governed archive is what makes a compliance project achievable.

Read article →

Ready when you are.

Compliance, integrations and deployment answered live, with your questions on the table and no generic pitch.

Book a Demo Take the assessment