Skip to content
ISO 9001 ISO/IEC 27001 Proxmox Gold Partner Data in Italy
Rackone
Data sovereignty

Data sovereignty: what it is and why it matters

Data sovereignty is the principle that data is subject to the laws of the country where it is stored and processed. For a business, it means knowing where its data is, which jurisdiction governs it and who can access it. Rackone, an Italian company, delivers its cloud services from its Edge network of data centers in Italy and Europe.

No commitment · You speak to a systems engineer, not a salesperson

A technician's hands connect a fibre optic cable to the patch panel of a rack cabinet
  • 700+ active customers
  • 24h support in English and Italian
  • GDPR data kept in Italy

What is data sovereignty?

Data sovereignty answers three questions, and a provider respects it only if it satisfies all three:

  • Where the data is: in which data centers and in which country, backup copies included.
  • Which law governs it: the law of the country where the data centers are and the law of the provider's home country, which may differ.
  • Who can access it: the provider, its subcontractors and any authority that can order the provider to hand the data over.

Data localisation answers only the first question: it states the physical location of the data. A data center in Italy run by a provider subject to an extraterritorial law localises the data in Italy, but does not remove it from that law.

Digital sovereignty is the wider goal: the ability of a state, a company or a public body to control the data, infrastructure and technology it depends on, reducing its dependence on outside parties. The European Union also calls it technological sovereignty. Data sovereignty is the part of it a business can verify in a contract.

Why data sovereignty matters: GDPR, the CLOUD Act, NIS2 and DORA

Data sovereignty is a requirement, not a preference, for four documented reasons:

  • GDPR: personal data may leave the European Union only under the conditions of Chapter V of Regulation (EU) 2016/679 (Articles 44-49). In 2020 the Court of Justice of the European Union struck down the Privacy Shield in the Schrems II judgment (case C-311/18). The framework now in force for the United States, the EU-US Data Privacy Framework of 10 July 2023, was upheld by the EU General Court on 3 September 2025 (case T-553/23) and is still being litigated.
  • CLOUD Act: the 2018 US law requires providers subject to US jurisdiction to hand over data requested by a US authority even when it is stored outside the United States (18 U.S.C. § 2713). On 10 June 2025, at a hearing of the French Senate, Microsoft France stated that it could not guarantee that French citizens' data would never be passed to US authorities.
  • NIS2: Directive (EU) 2022/2555 lists among the mandatory measures for essential and important entities «supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers» (Article 21(2)(d); in Italy, Legislative Decree 138/2024, Article 24).
  • DORA: Regulation (EU) 2022/2554 requires financial entities to state, in their contracts with ICT service providers, «the locations, namely the regions or countries, [...] where data is to be processed, including the storage location», and to be notified in advance of any change (Article 30(2)(b)).

For the Italian public sector, the regulation of the National Cybersecurity Agency (ACN) on digital infrastructure and cloud services also applies (determination 21007/24 of 27 June 2024): cloud services that public bodies buy on the market must be qualified by ACN.

Business continuity planning under NIS2 and DORA (in Italian)

Italian cloud or an EU region of a US provider: what is the difference?

Italian provider, data centers in Italy
US provider, data centers in the EU
US provider, data centers outside the EU
Where the data is
In Italy, at the sites you choose
In the European Union
Outside the European Union
Law that applies to the provider
Italian and EU law
EU and US law
US law
CLOUD Act
Does not apply, if the provider is not subject to US jurisdiction
Applies
Applies
Transfer outside the EU
None
Possible on the order of a US authority
Built in: needs a GDPR Chapter V basis
What to check in the contract
Sites, backup copies and subcontractors
How requests from non-EU authorities are handled
Legal basis for the transfer and safeguards

The comparison is about the provider, not the individual service: a service run in Italy by a provider subject to the CLOUD Act remains subject to the CLOUD Act.

Sovereign cloud on the Rackone Edge network

Services delivered by Rackone, an Italian company, from our Edge network of data centers in Italy and Europe: a data center of our own in Venice, at Noventa di Piave, and partner sites. Your data stays where you choose, and you always know where it is and who can access it, in line with GDPR and NIS2.

Cloud services

Virtual Private Cloud on redundant Proxmox clusters, Cloud VPS, Cloud Infrastructure on Proxmox VE, S3-compatible object storage with data in Italy and ready-to-run cloud apps.

VPS

Linux and Windows virtual servers in data centers in Italy, with no resource overbooking, traffic included and support from Italian systems engineers.

Dedicated servers

Dedicated physical servers running Linux or Windows in data centers in Italy, with additional Microsoft licences on request.

Housing and colocation

Hosting for physical servers in the Edge network data centers in Italy: full or half rack, redundant power, independent access around the clock.

Edge data centers

Ten data centers across Italy and Europe: the data center we own in Venice and carrier-neutral partner sites, with replication between sites.

Proxmox servers and clusters

Turnkey Proxmox VE servers and clusters, from a single node to a Ceph cluster: an open source platform developed in Europe, on your premises or in colocation, with Proxmox Backup Server Cloud in the Noventa di Piave data center.

With European partners, data in Italy

Services delivered on Acronis Cyber Protect Cloud, a platform by Acronis, and managed by Rackone, Acronis Platinum Service Provider. Your data stays in the Acronis data center in Rome or in another data center in the European Union, as you choose, and is not moved without your authorisation. Acronis Cyber Protect Cloud is qualified by ACN, the Italian National Cybersecurity Agency (listing SA-3698, level QC2).

Cloud backup

Acronis backup of servers, PCs, virtual machines and Microsoft 365, with immutable copies in the Acronis data center in Rome or elsewhere in the European Union, as you choose.

Disaster recovery

Server restart in the Acronis data center in Rome, with automatic failover tests on an isolated network and RPO threshold monitoring.

Microsoft 365 backup

Copies of Exchange Online, OneDrive, SharePoint and Teams, and of Google Workspace, in the Acronis data center in Rome or elsewhere in the European Union.

Data sovereignty: frequently asked questions

What is data sovereignty?

Data sovereignty is the principle that data is subject to the laws of the country where it is stored and processed. In practice it covers three things: where the data is, which law governs it, including the law of the provider's home country, and who can access it. It is broader than data localisation, which only states the physical location of the data.

What is the difference between data sovereignty and digital sovereignty?

Data sovereignty concerns the data: where it is, which law governs it and who can access it. Digital sovereignty, which the European Union also calls technological sovereignty, concerns the whole technological dependence of a state, a company or a public body: data, infrastructure, software and skills. Data sovereignty is the part of digital sovereignty that a business can verify in its contracts with providers.

What is the CLOUD Act and when does it apply to European data?

The CLOUD Act is the 2018 US law that requires providers subject to US jurisdiction to hand over data requested by a US authority, even when it is stored outside the United States. It applies to a European company's data when the provider of the service, or its parent company, is subject to US jurisdiction, whatever the country of the data center.

Does an EU region of a US cloud provider guarantee data sovereignty?

No, an EU region of a US cloud provider keeps the data in the European Union, but does not remove it from the CLOUD Act: the provider remains subject to US jurisdiction and can be ordered to hand the data over. Data sovereignty requires the provider itself, not only its data centers, to be subject solely to EU and national law.

Do Microsoft 365 and Google Workspace respect data sovereignty?

No, Microsoft 365 and Google Workspace do not respect data sovereignty in full: Microsoft and Google are US companies subject to the CLOUD Act, even for data stored in Europe. On 10 June 2025 Microsoft France told the French Senate that it could not guarantee the data would never be passed to US authorities. A backup copy on separate infrastructure keeps the data available under a second contract.

Where is my data stored with Rackone?

Data for Rackone services is stored in the Edge network data centers you choose: the data center we own in Venice, at Noventa di Piave, and partner sites in Italy and Europe. For services on Acronis, data is stored in the Acronis data center in Rome or in another data center in the European Union, as you choose. Your data is not moved without your authorisation.

Is data sovereignty a legal requirement under NIS2 and DORA?

No, neither NIS2 nor DORA requires data to be stored in a specific country, but both require control over the supply chain. The NIS2 Directive (Article 21) makes supply chain security a mandatory measure; DORA (Article 30) requires contracts to state where data is processed and stored and to give advance notice of any change. A provider with its data and its head office in the EU makes these checks simpler.

Can a company outside Italy use Rackone services?

Yes, a company outside Italy can use Rackone services: Rackone sells worldwide, and the same team answers in English or in Italian. The data stays in the Edge network data centers in Italy and Europe that the customer chooses, under EU law, whatever the customer's own location.

How do I check whether a cloud provider respects data sovereignty?

A cloud provider's data sovereignty is checked with five questions: which data centers and countries hold the data and its backups; which law applies to the provider and its parent company; which subcontractors process the data; how the provider handles a request from a non-EU authority; how much notice it gives before a change of location. They are the same points DORA requires in the contract.

Can data be moved back to Europe from a cloud outside the EU?

Yes, moving data from a cloud outside the EU to infrastructure in Italy or Europe, also called cloud repatriation, is planned service by service: inventory of data and dependencies, choice of site, migration, verification and decommissioning of the source copy. Rackone designs and runs the migration onto its Edge network, with a rollback plan for each step.

Let's talk about your data.

Where it is today, which law governs it, where it could be tomorrow: you speak to a systems engineer, not a salesperson.

Talk to an expert

No commitment · Support in English and Italian

Call Talk to an expert