Data sovereigntyEU jurisdictionGDPR & NIS2

Store and access data sovereignly

Storing data sovereignly means your databases, files and backups fall under European jurisdiction, beyond the reach of the US CLOUD Act. But storage alone is not enough: the data must also remain usable. Appfront is a software and app agency: we design and build the data layer and its access, from APIs and dashboards to private AI, and we work with specialist Dutch partners for the storage infrastructure.

What is sovereign data storage?

Sovereign data storage means your business data is kept with providers established in the EU, under European ownership and subject exclusively to European law. The location of the data centre is not decisive: a US provider falls under the US CLOUD Act and can be compelled to hand over data, even if it is physically held in the Netherlands. Sovereignty is therefore about jurisdiction and ownership, not just geography.

There are two sides to it. The first is the storage itself: databases, object storage and backups with Dutch providers, encrypted with keys your organisation manages itself, and data classification that determines which data must be sovereign and which may stay elsewhere. The second side is often overlooked: the data must remain usable. Reports, dashboards, integrations and AI applications must be able to run on that data without copies leaking to American services along the way.

Regulatory pressure is increasing. The GDPR sets requirements for transferring personal data outside the EEA, NIS2 adds a duty of care for the digital supply chain, and the revised Dutch central government cloud policy of 3 July 2026 requires central government to store and process data within the EEA, with a mandatory risk assessment and an annual exit plan. If you first want to know where your own dependencies lie, a sovereignty assessment is a logical starting point.

How we approach this

1
Data classification and inventory
We map out what data you hold, where it currently resides and which legal and contractual requirements apply to it. Together we determine what must be stored sovereignly and what may remain elsewhere.
2
Architecture and storage choices
We design the data layer: databases, object storage, backups and key management. For the infrastructure, we select a suitable Dutch provider together with you, independently and based on your requirements.
3
Migration and access
We move the data, set up encryption and access management, and build the access layer: APIs, dashboards, reporting and, where wanted, private AI on your own data.
4
Operations and ongoing development
After handover, we take care of monitoring, maintenance and further development, so the environment continues to meet changing legislation and new needs within your organisation.

What we build and manage

Sovereign databases and object storage
Relational databases, document stores and S3-compatible object storage with Dutch providers, set up for your workload and growth path.
Backups under EU jurisdiction
Encrypted backups and recovery tests on infrastructure that falls exclusively under European law, with retention periods that match your policy.
Encryption with your own key management
Encryption in transit and at rest, with keys managed outside the storage provider so that control demonstrably stays with your organisation.
Data classification
A practical classification model that determines which data must remain sovereign and which data may be held elsewhere, recorded in policy and architecture.
APIs and integrations
A data layer with secure APIs that gives your applications and chain partners controlled access, with authorisation and logging per consumer.
Dashboards, reporting and private AI
Management dashboards, reporting and AI applications that run within the sovereign environment, without data traffic to American services.

For whom

Government and public sector

The revised Dutch government cloud policy requires storage and processing within the EEA, a prior risk assessment and an annual exit plan. We set up the data layer accordingly, in line with the BIO.

Healthcare

Medical data calls for careful handling under NEN 7510 and strict access control. Sovereign storage with your own key management makes it demonstrable who can access patient data.

Financial sector

Under DORA, applicable since 17 January 2025, organisations must manage their ICT risks and outsourcing chain. A sovereign data layer gives you control over where critical data resides and who can reach it.

Industry and critical sectors

Organisations falling under NIS2 must also manage the risks posed by suppliers in their digital supply chain. Knowing where business data is stored and under which law it falls is the foundation for that.

Technology and approach

We build the data layer with open, portable technology so your data isn't tied to a single vendor. We choose databases and object storage based on open standards, set up encryption with key management outside the storage provider, and build access through well-documented APIs. For AI on your data, we work with models that run within your own environment; see also building private AI.

PostgreSQL and open databases
S3-compatible object storage
Encryption in transit and at rest
Own key management (KMS)
Kubernetes / containers
Infrastructure as Code
Open standards and APIs
Monitoring and logging

Why Appfront

Appfront is an independent software and app agency. We do not sell storage or hosting ourselves; the infrastructure comes from specialist Dutch partners whom we select independently. Our strength lies in the layer above: a data model that holds up, well-designed encryption and access management, and an access layer that ensures the data is actually used across your organisation.

  • Independent of hyperscalers and storage vendors
  • Experience with data migrations, APIs and custom integrations
  • Encryption and key management designed in from the start
  • Open standards so your data stays portable
  • Data layer and access designed and built as one

Frequently Asked Questions

What does storing data sovereignly mean?
Sovereign storage means your data sits with a provider established in the EU, under European ownership and subject exclusively to European law. The physical location of the data centre is not enough on its own: a US provider falls under the US CLOUD Act, even if its servers are in the Netherlands. That is why we look at jurisdiction and ownership, not just server location.
Does all of our data need to be stored sovereignly?
Usually not. We start with data classification: personal data, trade secrets and regulated data get a sovereign home, while public or low-risk data can remain elsewhere. This way you invest where the risk really lies, rather than moving everything at once.
Does Appfront provide the storage infrastructure itself?
No. Appfront is a software and app agency. We design and build the data layer and access layer: databases, APIs, dashboards and private AI. For the underlying infrastructure, we work with specialist Dutch hosting and data centre partners and advise independently on the provider that fits your requirements.
What is the benefit of self-managed encryption keys?
With self-managed encryption keys, the encryption keys are held outside the storage provider. The provider then only stores encrypted data and cannot make it readable without your keys. This reduces the impact of a data breach and demonstrably keeps control of access within your organisation.
Is sovereignly stored data still usable?
Yes, that is precisely the aim. We build APIs, dashboards and reporting on the sovereign data layer, and can connect private AI that runs within your environment. The data remains fully usable for your processes without copies leaking to US services.
How does this relate to the GDPR and NIS2?
The GDPR sets requirements for transferring personal data outside the EEA. NIS2, implemented in the Netherlands through the Cybersecurity Act, which takes effect on 15 August 2026, adds a duty of care for the digital supply chain: you must also manage the risks posed by your suppliers. Where your data is stored and who can access it is therefore part of your own compliance.

Getting started with sovereign data storage

Would you like to know which data should be stored sovereignly and how it stays usable for your organisation? We are happy to think along with you, independently, on classification, storage and access.

Edit content