UK Data Sovereignty After GDPR
Why the US CLOUD Act is forcing enterprises to rethink hosting
For UK enterprises, the phrase "data sovereignty" has evolved from a theoretical compliance exercise into a boardroom-level risk. Following Brexit, the UK retained the General Data Protection Regulation (UK GDPR) framework, maintaining strict controls over how personal data is processed and transferred. However, a significant legal conflict has emerged that threatens the data sovereignty of UK organisations using American cloud providers: the US CLOUD Act.
As we move through 2026, the tension between UK data protection laws and US extraterritorial reach is forcing legal, healthcare, and public sector organisations to fundamentally rethink where—and with whom—they host their most sensitive data.
The illusion of "UK regions"
When UK organisations procure cloud services from major US providers (such as Microsoft 365, Google Workspace, or AWS), they are typically offered the option to host their data in a "UK region" (e.g. London or Cardiff data centres). For many IT leaders, this appears to solve the data sovereignty problem. The data physically resides on British soil, satisfying basic data residency requirements.
However, data residency is not data sovereignty. Data sovereignty requires that data is subject exclusively to the laws of the country in which it is located. The US Clarifying Lawful Overseas Use of Data (CLOUD) Act, enacted in 2018, shatters this protection for customers of US-headquartered companies.
Understanding the US CLOUD Act threat
The US CLOUD Act grants United States law enforcement agencies the power to compel US-based technology companies to hand over data stored on their servers, regardless of where in the world those servers are physically located.
If a UK enterprise uses a US-owned cloud provider, the US government can issue a warrant or subpoena demanding access to that enterprise's data. Because the provider is a US entity, it is legally obligated to comply under US law, even if the data sits in a London data centre and belongs to UK citizens.
This creates a direct conflict of laws:
- UK GDPR strictly prohibits the transfer or disclosure of personal data to third countries without specific legal safeguards and data subject rights protections.
- The US CLOUD Act compels the provider to disclose the data to US authorities, bypassing UK legal jurisdiction.
While there is a UK-US Data Access Agreement in place (effective October 2022) designed to manage these conflicts for serious crime investigations, the fundamental reality remains: if you use a US provider, your data is ultimately subject to US extraterritorial reach.
The enterprise response: true sovereign hosting
For highly regulated sectors—such as financial services, legal practices, and government contractors—this jurisdictional exposure is increasingly unacceptable. A 2025 survey of UK IT leaders revealed that 83% fear geopolitical risks may threaten control over their data, prompting a shift away from US hyperscalers for sensitive workloads.
To achieve true data sovereignty, organisations must ensure two conditions are met:
- Physical residency: the data must be stored on servers located within the UK.
- Legal sovereignty: the infrastructure provider must be a UK legal entity, with no US parent company, ensuring the data is entirely outside the jurisdictional reach of the US CLOUD Act.
Comparing cloud deployment models
| DEPLOYMENT MODEL | PHYSICAL LOCATION | CORPORATE JURISDICTION | CLOUD ACT EXPOSURE | TRUE SOVEREIGNTY |
|---|---|---|---|---|
| US public cloud (US region) | USA | US | High | No |
| US public cloud (UK region) | UK | US | High | No |
| UK sovereign cloud | UK | UK | None | Yes |
| On-premises / air-gapped | UK | UK | None | Yes |
The OneOffice approach to sovereignty
This jurisdictional conflict is precisely why OneOffice UK was built. As a UK-registered entity operating dedicated infrastructure within UK borders, OneOffice provides a productivity suite—files, mail, calendar, calls, and editors—that is entirely insulated from the US CLOUD Act.
Furthermore, OneOffice employs customer-managed encryption keys (CMK). Even in the event of a lawful UK data request, OneOffice cannot hand over readable data because the customer holds the decryption keys.
For UK enterprises, the era of assuming "UK hosting" equals "UK sovereignty" is over. As regulatory scrutiny tightens, the only reliable way to protect sensitive organisational data is to ensure the platform hosting it is legally, as well as physically, British.
References
- CMS Law (2026). US CLOUD Act vs European/UK Data Sovereignty Explained.
- SecurityBrief UK (2025). UK IT leaders voice concerns over data sovereignty risks.