Most organisations meet the General Data Protection Regulation as a checklist: consent banners, a records-of-processing spreadsheet, a data protection officer to sign things off. That framing is not wrong, but it is small. The GDPR is better understood as a constitutional statement about power — specifically, about who gets to decide what happens to information about Europeans. Seen that way, data protection stops being a cost centre and becomes the legal bedrock of European digital sovereignty: the ability of European citizens, companies and states to set their own rules for their own data and have those rules actually hold.
This article explains what the GDPR protects, why US data practices collide with it at a structural level, and why the choice of where your data lives — and under whose law — is a sovereignty decision, not merely a compliance one.
What the GDPR actually protects
The GDPR, in force since 25 May 2018, treats the protection of personal data as a fundamental right, anchored in the EU Charter of Fundamental Rights. That is the crucial starting point: this is not consumer regulation bolted onto commerce, it is a rights framework that commerce must fit inside.
Its reach is deliberately broad. The regulation applies to any organisation processing the personal data of people in the EU, wherever that organisation is based — a US or Asian company serving European users is squarely within scope. It protects a wide definition of personal data, from names and location data to online identifiers and behavioural profiles. And it puts teeth behind the principles: supervisory authorities can impose fines of up to 20 million euro or 4 percent of global annual turnover, whichever is higher. Those are not theoretical numbers. In 2023 the Irish Data Protection Commission fined Meta 1.2 billion euro over unlawful data transfers to the United States — the largest GDPR fine to date, and a signal that transfer rules are enforced, not decorative.
Principles and rights, not just paperwork
The GDPR is built on a small set of principles that are easy to state and demanding to live by: process data lawfully and transparently, only for specified purposes, only as much as you need (data minimisation), keep it accurate, keep it no longer than necessary, and secure it. Crucially, the burden is on the organisation to demonstrate compliance — accountability is a legal obligation, not a good intention.
For individuals, this translates into concrete, enforceable rights: the right to know what is held about them, to have it corrected, to have it erased, to object to certain processing, and — importantly for sovereignty — the right to data portability, which lets people take their data and move to a competitor. Portability is quietly one of the most pro-competition ideas in the regulation: it makes switching a right, which is exactly what a directory of European alternatives depends on.
Why US data practice collides with European law
The friction with the United States is not about American companies being careless. It is structural, and it flows from US law reaching across borders. The CLOUD Act of 2018 lets US authorities compel any US-controlled provider to hand over data it holds, regardless of where in the world the servers physically sit. Section 702 of FISA and Executive Order 12333 authorise bulk signals intelligence with limited transparency and, historically, limited redress for non-Americans.
This runs directly into GDPR Article 48, which says a foreign authority's order to disclose data is only enforceable in the EU if it rests on an international agreement such as a mutual legal assistance treaty. A unilateral CLOUD Act warrant is no such agreement. That leaves a US-controlled cloud provider in a genuine bind: obey the warrant and breach EU law, or refuse and face US contempt proceedings. The point for a European decision-maker is simple — where a provider is incorporated, and whose government can lawfully compel it, matters as much as where the data is stored.
Schrems II and the fragile bridge of transfers
This tension has already reshaped the law twice. On 16 July 2020, the Court of Justice of the EU struck down the Privacy Shield in the Schrems II ruling, finding that US surveillance law did not give Europeans protection essentially equivalent to the GDPR, and that they lacked meaningful judicial redress. Transatlantic data flows were thrown into uncertainty overnight.
The replacement — the EU-US Data Privacy Framework, granted an adequacy decision on 10 July 2023 — rests on US executive-branch commitments to proportionate surveillance and a new Data Protection Review Court. It restores a legal basis for transfers, but many observers expect a 'Schrems III' challenge, and the framework rests on an executive order a future US administration could revise. The deeper lesson is not that the framework is bad, but that it is a bridge over a gap that European law cannot close from its own side. Sovereignty means not needing the bridge in the first place.
Data protection is a sovereignty question
Put these pieces together and the sovereignty argument writes itself. If the confidentiality and availability of your citizens' health records, your firm's contracts, or a ministry's correspondence ultimately depend on the political and legal decisions of another jurisdiction, you do not fully govern them. Sovereignty here does not mean isolation or protectionism; it means the capacity to set your own rules and have them hold — to understand your infrastructure, control where data flows, and avoid unwanted outflows.
The GDPR supplies the legal backbone for that capacity. It defines the standard European data must be held to, and it makes that standard travel with the data rather than stopping at the border. What it cannot do alone is build the infrastructure that lets Europeans meet the standard without depending on foreign-controlled platforms. That is where the rest of the toolbox comes in.
The wider European rulebook
The GDPR no longer stands alone. The Digital Markets Act and Digital Services Act, both now in force, rein in gatekeeper platforms and set obligations for online services. The Data Act, which entered into application in 2025, governs access to and sharing of industrial and connected-device data and includes safeguards against unlawful non-EU government access to data held in the EU. The NIS2 Directive raises baseline cybersecurity duties for essential and important entities. And the proposed EU Cybersecurity Certification Scheme for Cloud Services (EUCS) aims to give buyers a common way to judge a cloud provider's assurance level.
EUCS also shows how contested sovereignty still is: earlier drafts included explicit European-control and data-localisation requirements for the highest assurance tier, but these were removed in the March 2024 draft after heavy lobbying, leaving member states to apply such requirements themselves if they wish. The rulebook is real and growing — but it is a floor, not a finished building.
From principle to practice: the European alternatives
The encouraging news is that sovereignty is being built, not just legislated. The German state of Schleswig-Holstein is migrating roughly 30,000 public-sector workstations away from Microsoft to LibreOffice, Linux, Nextcloud, Open-Xchange and Thunderbird; by late 2025 it had moved more than 40,000 mailboxes and over 100 million emails and calendar entries off Exchange, expecting to save more than 15 million euro a year while gaining control of its own stack. At federal level, Germany's openDesk sovereign workspace pursues the same goal, and the Franco-German Gaia-X initiative works on a federated, European-governed data infrastructure.
For businesses and public bodies, the practical takeaways are concrete. Map where your data actually lives and which legal regime governs the provider, not just the datacentre. Favour providers incorporated in the EU and beyond the reach of extraterritorial disclosure laws. Use the GDPR's portability right to keep switching costs low, and treat European alternatives — for email, office suites, cloud storage and collaboration — as real options rather than compromises. Compliance keeps you out of trouble; sovereignty keeps you in control. The GDPR is where the second one starts.
