Data sovereignty for SMEs: What businesses need to do
The German Mittelstand – the country’s small and medium-sized (SME) business sector – is the backbone of the economy. According to the German Federal Statistical Office, around 3.2 million companies, or 99.3% of all businesses in the sectors covered, were small and medium-sized enterprises in 2023. They provide jobs, drive innovation, and create value in their regions. Alongside machinery, products, and skilled employees, their success increasingly depends on digital data – from contracts and accounting records to customer data, development information, and intellectual property.
As more business processes become digitally supported or fully digital, one question becomes increasingly important: Who controls the data on which the company depends?
Providing a clear answer is not always easy, as cloud services and other third-party providers have become integral to day-to-day business. At the same time, concern about one-sided dependencies is growing. According to the Bitkom Cloud Report 2026, 85% of the companies surveyed believe Germany is too dependent on U.S. cloud providers. In addition, 64% of cloud users say that U.S. government policy is prompting them to rethink their cloud strategy. German cloud providers are already used by 53% of respondents – but 91% would prefer to use them.
These figures show that data sovereignty is no longer an abstract issue for the future. Businesses need to know what data they process, which providers and jurisdictions are involved, and where critical dependencies arise. Only then can they remain operational in the event of cyberattacks, system outages, political changes, or new compliance requirements.
What does data sovereignty mean for businesses?
Data sovereignty describes a company’s actual ability to make autonomous decisions about its data. This requires the company to understand and influence:
what data is collected and stored,
where and by whom it is processed,
who can access it,
who it is shared with,
how long it remains available,
and whether it can be fully exported or transferred to another system.
A common misconception is that data sovereignty requires companies to operate or control every technical component themselves. What matters is that they understand their risks and dependencies, make informed decisions, and have realistic alternatives available when circumstances change.
Data sovereignty, data privacy, and data security
Data sovereignty is often treated as synonymous with data privacy or data security. While these concepts are closely related, they address different aspects of data management.
Data privacy governs the lawful handling of personal data. This includes customer, employee, and contact information. The GDPR, for example, defines the purposes for which such information may be processed and the responsibilities companies have when handling it.
Data security covers the technical and organizational measures used to protect data and systems against loss, manipulation, outages, and unauthorized access.
Data sovereignty goes even further. It applies to all business-relevant data – including design documents, research data, strategy papers, contracts, and trade secrets. A company may protect its data effectively from a technical perspective and still remain dependent on a provider, a foreign jurisdiction, or a system that is difficult to replace.
A German server location alone is not enough
The server location – meaning the place where data is stored – is an important criterion when selecting a cloud solution. However, it does not determine on its own whether the solution is genuinely sovereign.
Companies should also examine:
Where is the provider headquartered?
Who owns the company?
Where is the software developed?
Which subcontractors and technical components are involved?
Which national laws apply to the provider and its owners?
Can the provider technically access customer data?
Can the data be exported in full and transferred to another service?
For international corporations, hosting data in Germany or elsewhere in Europe resolves only part of the legal dependency. The U.S. CLOUD Act, for example, allows providers subject to U.S. jurisdiction to be required to disclose data in their possession or control – regardless of where that data is stored.
A German server location therefore remains an important component of data sovereignty. But only when combined with a transparent ownership structure, a clearly defined jurisdiction, controlled technical access, transparent subprocessors, and appropriate contractual terms does it provide a reliable basis for evaluation.
Learn how netfiles supports your business with sovereign data rooms →
Risks are increasing – for SMEs as well
Cyberattacks, supply chain vulnerabilities, outages, and international conflicts can all directly affect whether a business can access critical information, work with customers, or meet legal requirements. Small and medium-sized businesses face particular challenges. They use many of the same digital services and process data that is just as sensitive as that of large corporations, but they often have fewer specialized IT resources and less staffing capacity.
Cyberattacks threaten data and business operations
The assumption that cyberattacks primarily affect multinational corporations or critical infrastructure is long outdated. According to Bitkom’s 2025 Economic Security Study, 87% of the German companies surveyed reported theft of data or IT equipment, industrial espionage, or sabotage within the previous twelve months. The estimated economic damage rose to around €289 billion.
The consequences extend far beyond the loss of individual files: If systems are encrypted, trade secrets are stolen, or accounts are compromised, companies can face operational interruptions, recovery costs, contractual and compliance issues, and a loss of trust among customers and business partners. Even a limited incident can have serious consequences for an SME. Unclear responsibilities and organically grown IT environments often delay the response. Data sovereignty creates the foundation companies need to identify which data is most critical, where it is stored, and which protection and recovery measures are available.
Intransparent services and digital supply chains
Companies do not have to be attacked directly to lose data. Risks can also arise from software vendors, IT service providers, and their subcontractors. One example was the critical vulnerability exploited in the MOVEit file transfer software in 2023. Criminals used the vulnerability to access data belonging to numerous organizations. Some affected companies were exposed because MOVEit was used within their supply chain – even though they had not knowingly introduced the software themselves.
The incident highlights a fundamental problem: Many companies do not fully understand their digital supply chains. They may know which primary provider they have contracted, but not necessarily which platforms, subcontractors, or transfer services are involved behind the scenes.
Data sovereignty therefore also requires transparency about indirect dependencies. Certifications and contracts are important, but they do not replace an assessment of how a provider manages its own supply chain, which subprocessors it uses, and how it communicates security incidents.
Sabotage and geopolitical risks
The physical infrastructure supporting digital data exchange is also vulnerable. In November 2024, two communications cables in the Baltic Sea were damaged: the C-Lion-1 connection between Finland and Germany and the BCS East-West Interlink between Sweden and Lithuania. Incidents of this kind do not automatically cause individual businesses to lose access to their cloud systems. However, they demonstrate the growing importance of redundancy, business continuity, and reliable infrastructure partners.
Risk assessments should also go beyond individual countries or providers. Current discussions focus primarily on dependence on major U.S. cloud corporations. Companies should nevertheless examine more broadly which foreign owners, jurisdictions, and supply chains are involved in processing their data.
Political and legal frameworks can change
The EU-US Data Privacy Framework currently permits personal data to be transferred to participating U.S. companies. It is based in part on commitments to protect European data and on enforcement by U.S. institutions.
The U.S. Supreme Court’s ruling in Trump v. Slaughter demonstrates how quickly such institutional conditions can change. The Court struck down the previous statutory removal protections for commissioners of the Federal Trade Commission. This may allow the political leadership to exert greater influence over the agency’s composition and enforcement priorities. The ruling does not automatically invalidate the EU-U.S. Data Privacy Framework. Certified U.S. companies remain bound by their commitments, and the FTC retains its statutory powers. However, the long-term institutional stability of an important enforcement authority has become less certain.
The case is another warning signal: Data sovereignty cannot depend on the assumption that political and legal conditions in a third country will remain permanently stable and unchanged.
Compliance requirements increasingly affect SMEs
Since December 6, 2025, Germany’s NIS2 Implementation Act has imposed higher cybersecurity requirements on numerous companies and organizations. The Digital Operational Resilience Act, or DORA, has applied since January 17, 2025 and requires companies in the financial sector, among other obligations, to manage ICT and third-party risks in a structured manner. The pressure extends beyond directly regulated organizations. Customers and business partners increasingly require security documentation, clearly defined processes, and reliable information about all service providers involved.
TISAX has a similar effect. It is an assessment and exchange mechanism for information security used within the automotive industry and its supply chains. Companies working with regulated or audited customers may therefore need to meet requirements that indirectly affect their own choice of tools and service providers.
Data sovereignty helps businesses answer central compliance questions in a clear and verifiable manner: Where is the data stored? Who has access? Which service providers are involved? What security evidence is available? And what happens in the event of an outage or provider change?
Data sovereignty is not a decision against the cloud
An on-premises system – IT infrastructure operated directly by the company – provides extensive technical control. For this reason, many businesses continue to view it as a safer alternative to the cloud. At the same time, on-premises infrastructure makes the company responsible for updates, security vulnerabilities, backups, availability, and disaster recovery. In other words, if the business lacks the time, staff, or specialist expertise required for secure operation, a theoretically fully controlled system may be less secure in practice than a professionally managed cloud solution. Conversely, not every cloud environment is sovereign by default.
The right solution depends on the specific use case, the sensitivity of the data, the internal resources available, and the level of control provided by the service. The Bitkom Cloud Report illustrates this conflict. While 43% of the companies surveyed see no equivalent European alternatives to U.S. hyperscalers for their current requirements, 58% are unwilling to accept functional, pricing, or quality disadvantages in exchange for a sovereign German cloud. Sovereignty alone is therefore not a sufficient product promise. Whether an on-premises system, a cloud solution, or a combination of the two is most appropriate must be decided based on the company’s actual requirements.
Businesses need solutions that combine legal and organizational control with security, performance, and ease of use.
Particularly sensitive data and document processes can be moved into a sovereign environment without replacing every less critical business application at the same time.
What SMEs can do to strengthen data sovereignty
Even without enterprise-scale resources, SMEs have many options for achieving genuine control over their data. Before migrating data or changing providers, the first step is to create transparency and prioritize the most critical areas.
SMEs should consider six key areas:
Identify data and systems: What information is stored in which applications, and through which channels is it shared?
Determine protection requirements: Which data would cause the greatest damage if lost, disclosed, or unavailable?
Assign responsibilities: Who maintains an overview of data flows, providers, access rights, and security requirements?
Assess providers and dependencies: Which owners, jurisdictions, subprocessors, and technical platforms are behind the solutions in use?
Control access and data flows: How are sensitive files stored, collaboratively edited, and transferred to external recipients?
Prepare exit and emergency scenarios: Can data be exported in full, and what alternative is available in the event of an outage or provider change?
These steps do not need to be implemented across the entire IT environment at once. It makes sense to begin with particularly sensitive or business-critical data and processes. Bitkom provides a practical guide to implementing cloud sovereignty (only available in German).
How data sovereignty benefits SMEs
By investing in data sovereignty, SMEs can better protect business-critical data and intellectual property while reducing the risk of outages and one-sided dependencies. Clear control over data locations, access rights, and service providers also makes it easier to meet security and compliance requirements, prepare for audits, and give customers and partners reliable information about data processing. In this way, data sovereignty helps businesses safeguard their long-term digital autonomy. Data sovereignty therefore becomes a competitive factor: Companies that understand and control their data flows can introduce new digital processes more deliberately and respond more quickly when conditions change.
How to identify a sovereign cloud provider
When selecting a cloud, data room, or file-sharing provider, SMEs should evaluate more than pricing, functionality, and the stated server location.
The most important criteria include:
corporate and ownership structure,
company, development, and hosting locations,
applicable jurisdictions,
subprocessors involved,
the provider’s technical ability to access customer data,
encryption and secure authentication,
role and permission management,
logging of relevant activities,
recognized certifications and attestations,
availability and business continuity,
complete data export and provider-switching options,
transparent contractual terms and data processing agreements,
and responsive, expert support.
A sovereign provider must combine legal clarity, technical security, transparent processes, and practical usability.
netfiles: Your sovereign data partner in Germany
For 25 years, netfiles has helped businesses manage sensitive and business-critical documents securely. The company, its software development, and its hosting operations are all based in Germany. Data is processed with geo-redundancy across German data centers in Munich and Nuremberg. netfiles has no U.S. parent company and is therefore not dependent on the corporate and legal structure of a U.S.-based organization.
netfiles data rooms enable structured document storage and controlled collaboration with internal and external participants. Roles and access rights can be assigned precisely, while relevant activities remain traceable. The software is clear and intuitive, requires no installation, and can be used through any browser and on any device.
For the secure transfer of large and confidential files, netfiles Send complements the data room portfolio. Instead of sharing sensitive documents through conventional email attachments or uncontrolled file-sharing services, businesses can use a centralized and protected transfer channel.
The information security and availability of netfiles are regularly assessed by independent auditors. netfiles is certified to ISO/IEC 27001:2022 and ISO 22301:2019 and holds BSI C5 and SOC 2 attestations.
Conclusion: Data sovereignty safeguards digital autonomy
For SMEs, data sovereignty is essential to remaining operational during cyberattacks, system outages, or changes in the legal environment. This does not require companies to operate every system themselves or replace their entire IT infrastructure at once.
The first priority is transparency: Which data is particularly critical, where is it processed, who can access it, and which dependencies exist? Based on this information, businesses can prioritize risks and gradually move sensitive processes into more sovereign environments. This allows them to decide which technological dependencies are acceptable – and where secure, high-performance alternatives are needed.
Learn more – try netfiles
European cloud solutions are not a fallback option – they are the strategically right choice for companies that want to retain control over their data.
See for yourself – try netfiles free of charge for 14 days. No dependence on US providers and full access to all features. Start your free trial now →
Do you have questions about cloud sovereignty? Talk to our team →