<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on Sovereign Shift</title>
    <link>https://sovereignshift.eu/tags/security/</link>
    <description>Recent content in Security on Sovereign Shift</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Thu, 15 Jan 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://sovereignshift.eu/tags/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Eight Control Points US Cloud Providers Hold Over European Businesses (and Which Ones to Fix First)</title>
      <link>https://sovereignshift.eu/blog/data-driven-decision-making/</link>
      <pubDate>Thu, 15 Jan 2026 00:00:00 +0000</pubDate>
      <guid>https://sovereignshift.eu/blog/data-driven-decision-making/</guid>
      <description>&lt;p&gt;European organisations that choose EU data centres for their Microsoft 365 or Google Workspace deployments often believe they have addressed their sovereignty exposure. The data is in the EU. The box is ticked.&lt;/p&gt;&#xA;&lt;p&gt;But data location is only one of many control points a cloud provider holds over your organisation. Even with EU-hosted data, a US provider retains administrative access, controls the encryption keys, operates the identity layer, and can push updates or policy changes without your consent. The CLOUD Act (18 U.S.C. §2713) gives US law enforcement the legal authority to compel data disclosure regardless of where the data is physically stored.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
