INDUSTRY
Why Data Sovereignty Became a Boardroom Priority
I’ve spent more than 30 years in cloud and infrastructure, and I can’t remember a storage conversation climbing the org chart as fast as data sovereignty.
A few years ago, data sovereignty sat with the legal team. It was a compliance line, a box to tick. Today I’m having the same conversation with IT leaders, CISOs, and, more and more, the board itself (often all in the same room).
From a compliance checkbox to a boardroom mandate
In a recent report, analyst firm IDC describes the operating environment facing EMEA organizations in 2026 as “brittle, anxious, uncertain, and nonlinear.” It’s a blunt phrase, but a fair point.[1]
Geopolitical instability, a cascade of overlapping regulation across GDPR, NIS2, and the EU Data Act, and heavy concentration of enterprise data in a handful of hyperscalers have converged on one hard truth: you can rarely control the legal and regulatory landscape of any given country. You can, however, control where your data lives and how it's governed.
That’s the shift IDC captured when its research showed data sovereignty now outranks growth and innovation as a strategic priority for one in every four organizations. For a quarter of the market, sovereignty is the first step to take if you want to make growth possible.
Organizations aren’t just talking about it. They’re acting on it. IDC’s December 2025 CloudOps and Governance Survey found 69% of EMEA organizations are increasing their data governance, sovereignty, security, and resilience budgets for 2026.[2] When budgets move, you know a topic has left the whiteboard and entered the operating plan. And while the board sets the outcome it wants, delivering it lands squarely on IT. The mandate comes from the top, but the mechanism is built by the people who run the infrastructure.
What’s changed in my own meetings is who’s in the room. We used to talk to infrastructure and cloud architecture leads. Now those same leaders are pulling us up a level, because their board is asking questions that headlines can’t answer.
Pressure from every direction at once
Here’s what makes this genuinely hard for the people I talk to each week. The pressure inside the boardroom builds from several directions at the same time, and no single policy or vendor contract answers all of them. Regulation pulls one way. Cost pulls another.
The business wants to innovate and move fast, but the tension is real.
The instinct to lock everything down usually backfires. Having sovereignty as a checkbox is limiting, because it can block access to state-of-the-art services simply based on where the provider is headquartered.
The organizations getting this right are the pragmatic ones. They’re not asking, “how much can we lock down?” They’re asking, “how do we deploy the best possible service while keeping control?”
It’s telling that IDC expects CIOs at multinationals to boost investment in modular, sovereign-ready cloud environments by 65% before 2028.[3] They’re not all-in on a public cloud, and neither are they making a full retreat to a private data center, but looking at a deliberate middle built from components that give them both scale and control.
Sovereignty is an evolving discipline
The most important thing I can tell any leader starting this journey is that it is a continuous process. IDC frames sovereignty as an ongoing discipline to be designed into your infrastructure, not a project you finish and file away.
IDC predicts that by 2028, 60% of organizations with digital sovereignty requirements will migrate sensitive workloads to new cloud environments to reduce risk and increase autonomy.[4]
That prediction should give data-heavy organizations pause. If your data has deep roots in a single hyperscaler, moving it later is a long, expensive, and painful exercise. Teams that avoid that pain are the ones that build for portability from the start.
The practical first move is classification. Once you know which workloads and data sets actually carry risk, the conversation gets much easier. You can apply real controls where they matter, and leave everything else free to benefit from the scale and economics of the public cloud.
It’s also why I always recommend this tactic for our customers: decouple your backup and recovery from your primary cloud provider.
We see customers every day hosting their data in a hyperscaler and backing it up to the same hyperscaler, and honestly, that’s probably the worst thing you could do! Would you leave your spare car keys in the same car’s glove box? Absolutely not. That’s not a slight on the hyperscalers. You just don’t do it.
Backup works the same way, and separating it early is one of the simplest, highest-value moves an organization can make. It pays off long before any migration is ever on the table.
One variable you can act on today
You can’t control geopolitics, but you can decide where your data physically lives. That single decision is what makes every other layer of sovereignty possible because encryption, access governance, audit trails, and recovery independence all sit on top of it. Sovereignty done well isn’t about restriction. It’s about control.
Control your data, so you decide where it sits and who can touch it.
Control your ecosystem, so open standards and an S3-compatible API keep you free to build the best-of-breed stack you want instead of being locked to one vendor.
And control your costs, so you can futureproof your data infrastructure years ahead instead of bracing for the next surprise on the invoice.
Get those three right and your roadmap stays in your hands. At Wasabi, that's what we give customers: control over their data.
Where your data lives is the foundation everything else is built on. In the next piece in this series, I’ll break down what sovereignty actually requires across its four dimensions and why most organizations only address one of them.
Read the research
For the full picture on how EMEA organizations are turning sovereignty into a practical, resilience-led architecture, read IDC’s Spotlight, Cloud Without Compromise: Building Data Sovereignty into Your Infrastructure with a Resilience-First and Risk-Mitigating Approach.
Sources
[1] IDC, Cloud Without Compromise: Building Data Sovereignty into Your Infrastructure with a Resilience-First and Risk-Mitigating Approach, #US54512826, May 2026
[2] IDC, CloudOps and Governance Survey, December 2025
[3] IDC, Cloud Without Compromise: Building Data Sovereignty into Your Infrastructure with a Resilience-First and Risk-Mitigating Approach, #US54512826, May 2026
[4] IDC, IDC FutureScape: Worldwide Cloud 2026 Predictions, #US53859425, October 2025
Related article
Most Recent
Webb County, Texas avoided weeks-long budget approvals and egress fees by moving to Wasabi, which separated its DA's evidence billing and locked in five years of predictable storage pricing.
The memory shortage is doubling storage hardware costs. Learn how MSPs use Wasabi Cloud NAS to tier data, cut costs, and build recurring revenue.
AI storagemaxxing: the framework for optimizing storage across the AI lifecycle. Cut egress fees, avoid lock-in, and make storage AI-ready with Wasabi.
SUBSCRIBE
Storage Insights from the Storage Experts
Storage insights sent direct to your inbox.
&w=1920&q=75)