Data Sovereignty / Source date:

Data Sovereignty Before It Had a Name: EU vs US in 2007

In 2007, the foundations of today's data sovereignty crisis were already forming — EU-US data tensions, early cloud governance gaps, and US surveillance law colliding with European privacy expectations.

Staged cross-border processing review with location, transfer-mechanism and fallback folders, not transfer approval or historical diplomacy.

Nobody used the phrase "data sovereignty" in 2007. The concept was already in force — it was just filed under trade diplomacy, counter-terrorism cooperation and a self-certification scheme called Safe Harbor that almost nobody was checking. By the middle of that year the European Union and the United States were arguing simultaneously about financial messaging data, airline passenger records, and whether American companies holding European personal data were honouring the privacy commitments they had publicly signed up to. The answer to that last question, when somebody finally counted, was largely no.

The Arrangement at the Centre of It

European law prohibited transfers of personal data to countries without adequate protection. US law had no comprehensive privacy statute, so the United States was not adequate. That should have blocked routine transatlantic data flows entirely. Safe Harbor was the workaround. Agreed in 2000, it allowed a US organization to self-certify to the Department of Commerce that it complied with seven privacy principles — notice, choice, onward transfer, security, data integrity, access, and enforcement. Certification was a filing, not an audit. Enforcement fell to the Federal Trade Commission on the theory that a false privacy claim is a deceptive trade practice. The structure had an obvious weakness that took years to quantify: the only real check on a company's compliance was that company's own statement that it complied.

What an Actual Audit Found

Shortly after 2007, the consultancy Galexia examined the entire Safe Harbor list and published The US Safe Harbor — Fact or Fiction? The findings are worth reading slowly. Of roughly 1,600 organizations on the list, only 348 passed a basic test of compliance with a single principle — enforcement and dispute resolution. Only four organizations correctly identified the European data protection authority panel as their dispute resolution mechanism. Some privacy policies backing a Safe Harbor certification were two sentences long. And 208 organizations were making false claims of Safe Harbor membership outright. That number grew rather than shrank: a later review counted 331, and by 2013 a study prepared for the European Parliament found 427 false claims and observed that for every seven public claims of membership, one was untrue. Galexia also noted that the problems had been identified in European reviews in 2002 and 2004, and had not been fixed. The compliance gap was not a discovery. It was a known condition that everyone found convenient to leave alone.

Why 2007 Was the Year the Conflict Surfaced

Three disputes ran in parallel, and together they exposed what Safe Harbor could not address. Financial messaging. European regulators had found that the US Treasury was accessing European banking transaction data through the SWIFT cooperative, and pressed European financial institutions to resolve their position during 2007. Passenger records. After years of disagreement over how much airline passenger data European carriers must hand to US authorities and how long it could be kept, a further EU–US agreement on passenger name records was concluded in mid-2007. Ordinary commercial data. Meanwhile the Safe Harbor framework continued to certify the routine flows: HR records, customer databases, support tickets, marketing lists. The common thread was not commercial misuse. It was government access. European regulators were discovering that data lawfully transferred for business purposes could be compelled, lawfully under US law, for purposes Europe had never agreed to. No privacy principle signed by a company can constrain the legal powers of the state where that company's servers sit. That is the actual definition of data sovereignty, and 2007 is when European regulators started arguing it in practice.

Later decisions changed the transfer frameworkHistorical dates verified against court and Commission sources. This chronology is not a legal opinion on today's transfer eligibility or the article's stored2007 source date.

Each event links to its supporting source. This is a selective chronology, not a performance comparison.

How It Ended, Twice

The Court of Justice invalidated the Safe Harbor adequacy decision in October 2015, following a challenge grounded in exactly the surveillance-access problem regulators had been circling since 2007. Its replacement, Privacy Shield, was agreed in 2016 with stronger commitments and an ombudsperson mechanism. The Court invalidated that too, in July 2020, on substantially the same reasoning: US surveillance law provided no equivalent protection and no effective judicial redress for non-US individuals. The judgment also made clear that standard contractual clauses remain valid only where the exporter has assessed, case by case, whether the destination's law undermines them. The current arrangement — the EU–US Data Privacy Framework, adopted in 2023 after a US executive order created a redress mechanism including a data protection review court — is the third attempt at the same problem. It faces the same structural challenge, and it is already under legal scrutiny. Twenty-six years after the first framework, the underlying conflict between European data protection rights and US government access powers has been renegotiated three times and resolved zero times.

What This Means for Your Business Now

The sovereignty question is no longer transatlantic. It is everywhere, and it applies to mid-sized companies, not just multinationals. Saudi Arabia, the UAE, India, China, Australia, Canada, Brazil and others have all introduced transfer, localisation or residency requirements of varying strictness. A company operating across the GCC and Europe can face simultaneous obligations to keep certain data in-country, transfer other data only under assessed safeguards, and delete data a third regime requires it to retain. The practical failure mode is not a regulator's fine. It is discovering during a tender, an audit or a customer security review that you cannot answer basic questions about your own data:

  • Which countries is each category of personal data stored in, including backups, disaster recovery copies and log aggregation?
  • Which of your SaaS vendors sub-process data, and where do their sub-processors operate?
  • What transfer mechanism covers each flow, and when was the underlying assessment last reviewed?
  • Who holds the encryption keys for data held abroad — you, or the provider subject to a foreign disclosure order?
  • If a transfer mechanism were invalidated tomorrow, which systems would be affected and what is the fallback? Most organizations cannot answer the first question, which means they cannot answer any of the others.

Common Questions

What is data sovereignty?

The principle that data is subject to the laws of the country where it is stored or processed, and the resulting requirement to control where data resides and which governments can compel access to it.

Why was Safe Harbor invalidated?

Because self-certification did not deliver equivalent protection in practice, and because US surveillance law allowed government access to transferred data without adequate limits or effective redress for European individuals.

Do standard contractual clauses solve cross-border transfers?

Only partly. They remain a valid mechanism, but the exporter must assess whether the destination country's laws prevent the clauses from being effective, and apply supplementary technical or organisational measures where they do.

Does encryption remove the sovereignty problem?

Strong encryption with keys held exclusively by the customer significantly reduces exposure to foreign disclosure orders, because the provider cannot produce readable data. It does not eliminate metadata exposure or resolve localisation requirements.


Data Sovereignty Assessment — Outpace maps where your data actually lives across systems, vendors, sub-processors and backups, identifies the transfer mechanism covering each flow, and tells you what breaks if one of them is invalidated.

Continue reading

Talk to OPS

Start with the operating problem.