Your Data Has a Passport: A Practical Guide to Digital Sovereignty in 2026

There is a question that used to be the preserve of compliance officers and has quietly become a question for ordinary people: where does my data physically live, and whose laws reach it there?
For most of the past two decades the honest answer, for most people in North America and Europe alike, was some version of “a very large American company, and I would rather not think about it.” That was a reasonable position when the arrangement was stable and the incentives were legible. Storage was cheap, the products were good, and the main risk anybody worried about was a breach.
Two things changed.
The first is that the legal foundation for moving European data to the United States has become visibly unsteady. The second is that the commercial value of stored personal data was transformed by artificial intelligence — from an asset that had to be protected into an asset that could be used, at enormous scale, as training material.
This piece is not an argument that American technology is uniquely untrustworthy, and it is not an instruction to delete your accounts. Many European alternatives are worse. Some are excellent. The point is narrower and more useful: the default is no longer automatically correct, the alternatives have become genuinely good, and it is now worth making an actual decision.
Here is what changed, and what your options are.
The Legal Ground Is Moving
The mechanism that permits personal data to flow from the European Union to the United States has now been struck down twice by Europe's highest court. Safe Harbour fell in 2015. Privacy Shield fell in 2020. Both cases were brought, in substance, on the same argument: that United States surveillance law gave American authorities access to European data in ways that European fundamental rights do not permit, with no meaningful redress for the individuals concerned.
The third attempt, the EU–US Data Privacy Framework, has been in force since July 2023. It survived its first legal challenge in September 2025, when the EU General Court dismissed a case brought by the French parliamentarian Philippe Latombe, finding the newly created US Data Protection Review Court sufficiently independent.
It remains in force as of this writing, and it is under strain.
In January 2025 the Privacy and Civil Liberties Oversight Board — the American body whose existence the European Commission specifically relied on when it judged US protections adequate — lost its quorum when three of its five members were removed. A board without a quorum cannot conduct the annual reviews the framework assumes. An appeal in the Latombe case is pending before the Court of Justice of the European Union, the same court that invalidated both predecessors. And Section 702 of the Foreign Intelligence Surveillance Act, the surveillance authority underlying much of the dispute, lapsed in April 2026 and has been operating on short-term extensions.
Then there is the CLOUD Act, which is the part most people miss.
Under the CLOUD Act, a US-headquartered company can be compelled to produce data it controls regardless of which country the servers sit in. This is why the common reassurance — “our data is in the EU region” — is weaker than it sounds. Choosing a European data centre operated by an American parent company changes the physical location of the disk. It does not necessarily change which jurisdiction can reach it.

None of this means catastrophe is imminent. It means the arrangement most organisations and individuals rely on rests on foundations that have twice collapsed and are currently being contested again.
The Second Change: Your Data Became Fuel
The other shift is more recent and, for individuals, more concrete.
For most of the cloud era, the business case for holding your files was subscription revenue, with advertising attached to some services. Your documents were a liability to be secured.
The arrival of large-scale AI changed the calculation. Text, images, code, email and documents are exactly the material these systems are trained and tuned on. Several major platforms have updated their terms in recent years to permit the use of customer content for improving AI features, usually with an opt-out, sometimes with the opt-out enabled by default and sometimes not, and generally announced by email in language most people do not read.
This is a legitimate business activity, and the companies doing it are not acting covertly. But it does mean the calculation you made when you chose a provider in 2016 was a calculation about a different product.
The practical question for a reader is not whether this is sinister. It is whether you have checked what your current provider's settings actually say, and whether you would choose it again knowing what it now does.
What Actually Reduces Your Exposure
Before the list of alternatives, an unglamorous point that matters more than any of them.
Switching providers does very little if the underlying data is readable by whoever holds it. The property that matters is end-to-end encryption: the data is encrypted on your device with a key the provider does not have, so the provider physically cannot read it, hand it over, or train on it — regardless of jurisdiction, subpoena, or change of ownership.
A US company with real end-to-end encryption protects you better than a European company without it. Jurisdiction is the second question. Encryption is the first.
The trade-off is real: if the provider cannot read your data, the provider cannot recover it when you lose your password, and features that require server-side processing — full-text search, some collaboration — become harder. Providers solve this in different ways, and some solve it badly.
The Alternatives, Honestly Assessed
Email. Proton Mail (Switzerland) and Tuta (Germany) are the two serious end-to-end encrypted options. Both are mature and usable. The honest caveat: end-to-end encryption only applies between users of the same service. Mail you send to a Gmail address arrives on Google's servers in readable form, because that is how email works. What you gain is that your archive is not readable by your provider, which over a decade of correspondence is not nothing.
Files and documents. Proton Drive, Tresorit (Switzerland/Hungary), and Nextcloud (Germany) are the main options. Nextcloud is different in kind: it is open-source software you can either self-host or rent from any of dozens of independent European providers, which means you are not tied to a single company's future decisions. It is the most sovereign option and requires the most from you.
Messaging. Signal is the correct answer and is run by a US non-profit — a useful illustration of why jurisdiction is the second question. Its encryption is the reference standard, it holds almost no metadata, and its protocol is what most competitors licensed.
Network privacy. Mullvad (Sweden) is the most rigorous VPN on the market by a distance: no account names, no email required, a random account number, and a company that has undergone police searches and had nothing to hand over because it stores nothing. IVPN (Gibraltar) operates similarly. Be clear about what a VPN does, though — it moves your traffic's exit point. It does not make you anonymous to services you log into.
Search. Qwant (France), Startpage (Netherlands), Ecosia (Germany), Brave Search (US, independent index). Search quality is genuinely lower than Google's for hard queries; this is the trade-off that most people abandon first, and it is a fair reason to abandon it.
Cloud infrastructure. For anyone running a business: Hetzner (Germany), Scaleway and OVHcloud (France), UpCloud (Finland), Exoscale (Switzerland), and Zone and Elkdata in Estonia. Hetzner in particular is priced aggressively enough that the sovereignty argument is almost secondary.

Productivity. LibreOffice and the Collabora and OnlyOffice suites integrate with Nextcloud for collaborative editing. They are noticeably less polished than Google Workspace or Microsoft 365, and anyone who claims otherwise has not tried to do serious collaborative work in them.
What the North Already Knew
There is a reason this argument sounds familiar to Estonians in particular.
Estonia built its digital state on a decentralised architecture called X-Road, in which government databases exchange data through a secured layer rather than pooling it into a single central store. Every access to a citizen's records is logged, and the citizen can see the log. A doctor who looks at a file they have no business looking at leaves a trace the patient can read.
.jpeg)
The country then did something almost nobody else has: it established a “data embassy” in Luxembourg — a facility holding critical state data under Estonian sovereignty on foreign soil, so that the state can continue to function even if its physical territory is compromised.
That was not a privacy project. It was a continuity-of-government project, designed by a small country next to a large and unpredictable neighbour that has already experienced a major state-level cyberattack, in 2007.
But the underlying principle generalises well, and it is the useful thing to take from it: sovereignty is about who can be locked out, and who can be held accountable. Not about where the building is.
Applied to an individual, that translates into a short and unromantic checklist. Can the provider read my data, or only store it? If they were compelled to hand it over, would there be anything to hand over? If they were bought, or changed their terms, could I leave — and could I take the data with me in a format something else can open?
That last one is the most neglected and the easiest to check.
A Reasonable Position
The maximalist version of this argument — leave everything American, self-host, run Linux, trust nobody — is available online in large quantities and is not, for most people, good advice. It has high costs, real security risks if done badly, and a tendency to substitute identity for judgement.
The reasonable position is smaller.
Decide which of your data you would actually mind losing control of. For most people it is a short list: correspondence, financial and legal documents, medical records, family photographs, anything relating to children. Move that specific category to something end-to-end encrypted, and leave the rest where it is convenient.
Check the AI training settings on the services you already use, and turn off what you want off.
Make sure you could get your data out. Export something once, and confirm the file opens.
That is perhaps two hours of work, and it addresses most of the realistic risk.
The Nordic and Baltic contribution to this conversation has never been a claim that Europe is virtuous and America is not. It is a much older and more practical idea: that infrastructure you depend on should be designed on the assumption that the people running it will not always be the people running it now.
That assumption used to sound paranoid.
Lately it just sounds like planning.
References and further reading
European Commission, adequacy decision on the EU–US Data Privacy Framework (July 10, 2023).
Case T-553/23, Latombe v Commission, EU General Court judgment of September 3, 2025; appeal pending before the CJEU.
Clarifying Lawful Overseas Use of Data (CLOUD) Act, 2018.
Nortal and the Estonian Information System Authority publish ongoing technical documentation of X-Road and the Estonian data embassy programme.
European Alternatives (european-alternatives.eu) maintains a comparison directory of EU-based services.

)%20(1).avif)