Skip to content
Two specialists are checking access rights to production data at the plant, symbolizing data sovereignty in manufacturing
Amadeus Lederle12.8.202616 min read

Data Sovereignty: Ensuring Control Over Your Data

Imagine you arrive at the plant in the morning, want to access the process data from the last night shift, and nothing works. Not because of a server outage, but because an external provider has blocked access. Many IT and quality managers in manufacturing don’t ask themselves this question until it’s too late. Data sovereignty is the answer, and it begins long before an emergency arises.

In 2024, Schleswig-Holstein became the first federal state to begin removing Microsoft software from its state administration on a comprehensive basis. The reason was not solely to save costs, but rather a conscious decision to retain control over its own IT at all times. What applies to a state government applies just as much to an automotive supplier: Anyone who does not control their own quality-related data is, in a worst-case scenario, relinquishing the ability to act for their entire operation.

Produktionsteam bespricht Cloud Exit Strategie und Datenhoheit vor Bildschirm mit Archiv- und Serverstruktur

This article explains what data sovereignty specifically means for manufacturing companies, why server location is the wrong metric in this context, and how you can secure control over your data throughout its entire lifecycle. It is aimed at IT management, compliance, and quality assurance professionals in discrete manufacturing.

KEY POINTS AT A GLANCE
  • Data sovereignty means having the ability to determine at any time where data is stored, who has access to it, and how long it remains available.
  • The server location does not determine access control. What matters is the provider’s legal jurisdiction: A U.S. company such as Microsoft, Amazon, or Google is subject to the U.S. CLOUD Act even if its data center is located in the EU.
  • For manufacturers, data sovereignty is particularly critical for quality- and production-related data, which must remain traceable for 15 years or longer.
  • True sovereignty is achieved through three key factors: sole control over access, an open, vendor-neutral data format, and a documented cloud exit strategy.
IN A NUTSHELL
  • Sovereignty is not a state that is achieved once and for all, but a decision that must be made anew for every architecture.
  • About one in two medium-sized companies has no documented exit strategy for its cloud dependencies (Lünendonk Study, 2025).
  • Audit-compliant archiving in an open format ensures access to evidence, even if the original system has long since been shut down.

 

What Data Sovereignty Means in Practice for Manufacturers

Data sovereignty describes a company’s ability to independently manage its own data, access, and digital processes in compliance with the law. For a manufacturing company, this is not an abstract IT issue, but rather a prerequisite for operations. Anyone handling a complaint, passing an audit, or defending against a product liability claim needs reliable access to the relevant process and quality data at all times.

The distinction from data protection is important. Data protection regulates how personal data may be processed. Data sovereignty goes further and asks who has actual control over access. A system can be fully GDPR-compliant and still lack sovereignty if a third party could technically or legally block access at any time.

KEY METRICS FOR DATA SOVEREIGNTY
Key Metric Value Source
CIOs who prioritize digital sovereignty 78% Lünendonk Study 2025
Companies without a documented cloud exit strategy 43% Lünendonk Study 2025
Typical time required to verify quality data 15+ years IATF 16949, product liability
Effective Date of the U.S. CLOUD Act 2018 U.S. Congress
DISTINCTIONS: DATA SOVEREIGNTY, DATA PRIVACY, AND DATA SECURITY
Term Key Question Covers Example in Everyday Manufacturing
Data Sovereignty Who controls access? Control over storage location, access, and availability Audit data remains accessible even in the event of sanctions
Data Protection How may data be processed? Handling of personal data (GDPR) Storing Worker IDs in inspection reports in compliance with the law
Data Security How is data protected technically? Protection against loss, tampering, and unauthorized access Encryption and access control in the archive

The three sub-questions mentioned—where is the data stored, who has access to it, and how long will it remain available—constitute the practical core. These questions can be answered individually for each system. If any of the answers is unclear, sovereignty is not guaranteed at that point.

 

Why the server location does not determine access sovereignty

The most common misconception is that if the servers are located in Germany or the EU, the data is under sovereign control. That is incorrect. On paper, everything looks solid: redundant data centers in the EU, modern firewalls, and a 24/7 Security Operations Center. However, what matters is not the physical location, but the legal jurisdiction to which the provider is subject.

The U.S. CLOUD Act requires U.S. technology companies to hand over data upon order from U.S. authorities, regardless of whether the servers are located in Frankfurt, Paris, or Amsterdam. As long as the provider is a U.S. company—such as Microsoft, Amazon, or Google—U.S. law applies. Having a data center in the EU does not change this. The law does not require the affected company to be notified.

The EU is countering this with the EU Data Act, which takes effect in September 2025 and requires cloud providers to use technical measures to make unauthorized access from third countries more difficult. However, there is no legislation that nullifies the U.S. CLOUD Act. Anyone searching for an “EU CLOUD Act” will find that no such law exists in this form. Thus, the core message remains: a server location in the EU does not automatically mean it is safe from U.S. access. What matters is which jurisdiction the provider is subject to.

PRACTICAL ERROR

A supplier moves its quality database to the cloud, arguing that the data center is located in Germany. The provider is a U.S. corporation.

In the event of an emergency, it is not the location in Germany but the provider’s jurisdiction that determines access. The supposed security benefit is illusory.

LEVEL OF ACCESS ACCORDING TO THE PROVIDER’S MODEL
Model Server Location Provider’s Jurisdiction Jurisdiction
U.S. cloud, U.S. data center USA USA Low
US cloud, EU data center EU USA Low
EU cloud, EU provider EU EU Medium
Operated locally in-house Own facility Own company High

Data sovereignty refers to sole control over who can view and disclose the data. The provider’s jurisdiction carries more weight than the server’s location.

It is precisely this logic that is prompting the first public agencies to take action. Schleswig-Holstein is gradually transitioning its state administration from Microsoft to open source in order to fundamentally reduce its dependence on a U.S. provider. For a contractor, the solution does not necessarily have to be a complete software overhaul. The crucial step is to keep data relevant to documentation out of the jurisdiction of a foreign legal system—in particular, through a sound cloud exit strategy.

 

The Three Levels of Data Sovereignty in Manufacturing

Data sovereignty can be broken down into three levels, each of which must be met independently. If one is missing, control is incomplete, even if the other two are implemented in an exemplary manner.

Level 1: Access Sovereignty

Control over who accesses the data must lie with the company, not with a provider subject to a foreign legal system. This level is considered sovereign if the provider is subject exclusively to European law or if the data is stored on-premises, no third country can compel its disclosure, and access is logged and traceable. It becomes a risk as soon as a U.S. provider is involved—even if it has an EU data center—or if access is possible without notification.

Key question: Can a third party force access or block it against my will?

 

Level 2: Format Sovereignty

Data in a proprietary format ties the company to a single provider. Open formats remain readable for decades, regardless of the original system. This level is considered sovereign when archiving is performed in an open, documented format, data remains readable even after the source system is replaced, and no license agreement restricts access to the company’s own historical data. It becomes a risk if the data can only be read using the provider’s software or if a format change forces a costly migration.

Key question: Will I still be able to read my data in ten years without today’s provider?

 

Level 3: Freedom to Switch

Without a documented exit option, switching providers in a crisis situation would take months rather than days. The EU Data Act requires providers, starting in September 2025, to make switching technically possible. This level is considered secure if a documented cloud exit strategy exists, data portability is contractually and technically guaranteed, and a path for bringing data back in-house is defined. It becomes a risk if no exit plan is documented or if a switch would take six to 18 months.

Key question: How long would it take me to completely switch away from this provider?

These three levels—access sovereignty, format sovereignty, and switching sovereignty—together form the practical definition of data sovereignty. A company that can address all three is capable of taking action, even if the political or economic situation changes.

 

Think in terms of a crisis scenario: What happens if access is lost?

The most effective test of autonomy is to simulate a crisis scenario. The question isn’t how well everything runs under normal conditions, but what happens if access is lost. It is precisely this scenario that has prompted entire federal states to change course.

CRISIS SCENARIOS: WITH AND WITHOUT DATA SOVEREIGNTY
Scenario Without Sovereignty With Sovereignty Action
Provider blocks access due to sanctions Quality data stored with a U.S. cloud provider. Complaints and audit verification are on hold because the supporting data is inaccessible. Verification data is stored in-house in an audit-proof manner. Complaints and audits continue without interruption. Bring data relevant to compliance under your own control before an emergency arises.
Source system is shut down Data is readable only in the legacy system. A product liability case ten years later can no longer be substantiated. Data is openly archived before the system is taken offline. The database contents remain structured and searchable. Convert the data to an open archive format before every system replacement.
Sovereignty is not a state that is achieved. It is a decision that must be made anew with every architecture.
Amadeus Lederle, Chief Technology Executive, CSP Intelligence GmbH

The crucial factor is timing. Those who wait until a crisis strikes to act are already too late. Industry experience shows that switching away from a provider takes six to 18 months. That time is not available in an emergency. Sovereignty must therefore be built into the architecture from the start, not retrofitted as an emergency measure.

 

Cloud Exit Strategy: Remain Capable of Acting Instead of Being Tied Down

A cloud exit strategy is a documented plan for how a company will migrate its data and applications from one provider to another or back in-house. It is the practical expression of the freedom to switch providers. To date, roughly one in two small and medium-sized businesses has not documented such an exit option, and that is precisely what becomes a risk in an emergency.

 

Step 1: Take inventory of data assets (1 to 2 weeks)

  • Identify all systems that contain production- and quality-related data
  • For each system, determine where the data is stored and who has access to it
  • Assign record-keeping requirements and retention periods

Result: A complete overview of which data is critical to sovereignty and to what extent.

 

Step 2: Assess dependencies and legal jurisdictions (2 to 4 weeks)

  • Check the jurisdiction for each provider, not just the server location
  • Identify proprietary formats that make switching difficult
  • Request data portability in accordance with the EU Data Act

Result: A prioritized list of systems posing the highest sovereignty risk.

 

Step 3: Define and test the recovery path (ongoing)

  • Establish a documented process for transferring critical data to your own system
  • Convert data relevant for audit purposes to an open archive format
  • Practically test the recovery path at least once

Result: Reliable operational capability that works even under time pressure.

 

The EU Data Act has been fully in effect since September 2025 and grants European companies the right to data portability. It requires cloud providers to make switching technically possible. This reduces the risk of lock-in but does not replace the company’s own decision regarding whether and when a switch makes sense. The strategy remains the company’s responsibility.

 

Control over the entire data lifecycle

Sovereignty does not end with the selection of a provider. It must be maintained throughout the entire data lifecycle—from collection in production through active use to long-term archiving. The last phase, in particular, is often overlooked, even though it is the longest.

SOVEREIGNTY OVER THE DATA LIFECYCLE
Phase What Happens Sovereignty Issue Typical Risk
1 Collection Process and quality data are generated at the machine and test station. Is the data collected in a controlled system from the very beginning? Siloed solutions without central control.
2 Utilization Data flows into analysis, complaint handling, and process improvement. Does access remain independent of external providers? Dependence on a proprietary analytics platform.
3 Archiving Audit trail data must remain readable for 15 years or longer. Is the data stored in an open format under the organization’s own control? Loss of readability after system replacement.

The archiving phase is the most critical point for manufacturers. A complaint or a product liability claim can arise many years after production. If the associated process history is no longer readable because the original system has been shut down and the format was proprietary, the evidence is lost. Reliable archiving does not back up the file system, but rather preserves the technically relevant database content in a structured manner tailored to the application.

KEY POINT

Backup and archiving are not the same thing. A backup is intended for short-term recovery. Archiving is intended for long-term, audit-proof, and structured retention. For data sovereignty spanning decades, archiving is what counts—not backup. Read more in the article “Backup vs. Archiving.”

 

How the CSP Manufacturing OS Ensures Data Sovereignty

Data sovereignty is not a product feature you buy, but rather a characteristic of the architecture. At CSP, we have relied from the very beginning on an architecture that allows customers to retain control over their own data. This applies throughout the entire lifecycle, from collection to audit-proof long-term archiving.

Manufacturing OS

The CSP Manufacturing OS captures, utilizes, and archives quality- and production-related data on a shared basis. Audit trail data is stored in an open format that complies with OAIS standards, installed locally, and remains under the company’s sole control. This ensures that the data remains audit-proof and readable even after legacy systems are phased out.

  • 100% audit-proof archiving in an open, vendor-neutral format 
  • Over 70% reduction in database size through offloading of inactive data
  • Over 40% cost savings in IT operations through reduced system load 
  • Can be installed locally: Data never leaves the company, and access control remains in-house
  • Legacy systems can be decommissioned without losing audit-traceable access to historical data

View data archiving with CHRONOS →

The approach is deliberately conservative: The focus is not on the convenience of a third-party platform, but on the customer’s long-term control over their own data. Manufacturers in the automotive industry, commercial vehicle manufacturing, rail technology, and mechanical engineering use this approach to confidently manage traceability and product liability over decades. Read the linked article to learn why manufacturer independence is not merely a matter of convenience in this context.

 

Frequently Asked Questions

What does data sovereignty mean for a manufacturing company?

Data sovereignty means that a company determines for itself at all times where its data is stored, who has access to it, and how long it remains available. For manufacturers, this primarily concerns quality- and production-related data that must remain traceable for decades. Sovereignty is achieved when access remains possible even if an external provider or a political decision were to restrict it.

Why isn’t a server location in the EU sufficient for data sovereignty?

The server location alone does not determine control over access. What matters is which jurisdiction the provider is subject to. A U.S. company such as Microsoft, Amazon, or Google—even with a data center in Frankfurt—remains subject to the U.S. CLOUD Act and can be compelled to hand over data, regardless of the physical storage location. There is no EU legislation that supersedes the CLOUD Act. True data sovereignty therefore requires that the provider be subject exclusively to European law or that the data be stored in-house under the company’s sole control.

What is the difference between data sovereignty and data protection?

Data protection regulates how personal data may be processed. Data sovereignty is a broader concept and concerns the question of who has actual control over access. A system can be GDPR-compliant and still lack sovereignty if a third party could technically or legally block access at any time. Sovereignty is therefore the prerequisite for enforcing data protection even under pressure.

What role does the U.S. CLOUD Act play for German manufacturers?

The U.S. CLOUD Act of 2018 requires U.S. technology companies to hand over data upon order by U.S. authorities, regardless of where it is stored. For German manufacturers, this poses a compliance risk as soon as quality- or production-related data is stored with a U.S. provider. The law does not require notification to the affected company, so access can occur without the customer’s knowledge.

What is a cloud exit strategy, and why is it important?

A cloud exit strategy is a documented plan for how a company will transfer its data and applications from one cloud provider to another or back to its own premises. It is relevant because roughly one in two small and medium-sized enterprises (SMEs) does not have a documented exit strategy for its cloud dependencies. The EU Data Act requires providers, starting in September 2025, to make such a switch technically possible; however, the strategic decision remains with the company.

How can manufacturing companies ensure long-term data sovereignty over quality data?

Quality and production data often must remain traceable for 15 years or longer, for example, in accordance with IATF 16949 or for product liability cases. Data sovereignty over this period is achieved through audit-proof archiving in an open, vendor-neutral format that remains readable even after the original system has been replaced. It is crucial that the archiving process remains under the company’s control and is not tied to a proprietary platform.

What happens to archived data when the original system is decommissioned?

With proper archiving, the business-relevant data remains fully available and searchable even after the original system is decommissioned. This requires not only backing up the file system but also archiving the relational database contents in a structured manner appropriate for the application. This allows legacy applications to be decommissioned without losing audit-traceable access to historical production data.

Is on-premises archiving still relevant, or should you move to the cloud?

Both models have their merits. The decisive factor is not whether it’s cloud-based or on-premises, but who retains control over access. On-premises or locally operated archiving offers maximum data sovereignty because the data never leaves the company. Those using the cloud should ensure they choose a provider subject to European law, an open data format, and a documented exit strategy—so as not to trade sovereignty for convenience.

Amadeus Lederle
Chief Technology Evangelist, CSP Intelligence GmbH. 15 years in industrial software architecture and legacy migration across DACH manufacturing.
COMMENTS

RELATED ARTICLES