ES Technical meeting
Menu
01 — Definition

Three independent properties

«Data sovereignty» is frequently used as a synonym for storage in Europe. Strictly speaking it describes three distinct conditions, which can be met separately. An organisation assessing a provider needs an answer to all three.

Property 1

Residency

The physical location of the data and of the systems that process it. It is the easiest condition to establish and the one every infrastructure provider offers through geographic regions.

Property 2

Jurisdiction

The legal system that binds the entity controlling the data. It depends on the provider’s nationality and ownership structure, and is not determined by where the servers sit.

Property 3

Portability

The ability to move the data to another system and carry on operating. It depends on the storage format and on the contractual terms for extraction and termination of the service.

The distinction matters in practice: a European region establishes the first condition and says nothing about the other two. A good share of the discrepancies between a project’s commercial assessment and its risk assessment originate in that difference.

02 — Jurisdiction

Extraterritorial reach and ownership structure

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act), in force in the United States since 2018, empowers its authorities to compel data from entities subject to its jurisdiction regardless of the country where it is stored. The location of the data centre does not change that reach.

General framework

The obligation falls on the company, not the server

What determines whether a company must answer a US demand is where it is incorporated and who controls it, not where it keeps the data. A European subsidiary with a US parent remains within reach.

Opendome’s configuration

European providers, no parent outside the EU

The managed service infrastructure runs on European-owned providers with data centres in the European Union. The condition is verifiable in the public subprocessor inventory, not solely in a contractual statement.

03 — Deployment

Where the data resides in each model

Opendome is deployed in three ways. In two of them the data resides in the customer’s infrastructure; in the third, in Opendome’s. European jurisdiction and the storage format are common to all three.

Model Who operates Where the data resides Opendome's GDPR role
Managed Opendome, end to end Opendome infrastructure, on European providers with data centres in the EU Processor
BYOC
Bring your own cloud
Opendome operates the software; the customer supplies the infrastructure The customer's infrastructure, in the location they determine Processor
Self-host The customer or an integrator they appoint The operator's infrastructure; Opendome takes no part in operations Not applicable

In all three models the customer is the data controller. Opendome does not determine purposes and does not use the data for its own ends. In the managed model and in BYOC it acts as processor, under a processing agreement pursuant to article 28 GDPR; in self-host it does not process customer data.

How controls are split between the parties in each model is set out in Shared responsibility.

04 — Verifiability

Open source and standard formats

A contractual commitment not to access the data, not to monetise it and to respect the customer’s jurisdiction can only be checked indirectly. An open source system on standard formats can be checked directly. Opendome takes the second route for auditability, not only for cost.

Inspection

The system’s behaviour is legible

The customer, their auditor or the regulator can examine how data is processed, where it is stored and what information leaves the infrastructure, without relying on the provider’s word.

Format

Storage in open standards

Data is stored in Apache Iceberg and Lance, readable by any compatible engine in the ecosystem. On a change of provider it remains accessible with no prior conversion.

Access

No per-query pricing

Certain architectures on the market expose the organisation’s data through APIs and charge for each operation. At Opendome there is no metering or charge for agents accessing customer data.

05 — Verification

Claims and the documentation behind them

Each of the statements above, mapped to the source where it can be checked.

Production customer data does not leave the EU/EEA
An obligation of the information security management system, verifiable against the provider inventory. Subprocessors
Every subprocessor that handles customer data resides in the EU/EEA
No provider is taken on without a prior assessment proportionate to its risk; critical ones are reviewed periodically and every provider handling personal data has an article 28 agreement. Subprocessors
Two non-EU exceptions exist, with no access to customer data
Development tools with access to code and internal technical context, inventoried as an exception and with migration as the stated goal. International transfers
The processing agreement is signed before any processing begins
A DPA pursuant to article 28 GDPR, with the article 32 technical measures set out in detail. Privacy policy
The management system is aligned with ISO/IEC 27001:2022 and with SOC 2 criteria
Certification and attestation are in progress; neither has concluded as at the date of publication. Regulatory compliance
Storage uses open, standard formats
Apache Iceberg and Lance, with no proprietary formats. The terms for return or deletion at the end of the contract are set in the processing agreement. Privacy policy

Technical meeting

A working session to determine the applicable deployment model, the resulting residency of each data set, and the documentation needed for your internal approval.

Request a technical meeting