Data sovereignty is the principle that data is subject to the laws of the country where it is physically stored. Kimsufi dedicated servers let your organization choose that country, keep regulated data on ISO 27001-certified European infrastructure, and retain control of the software layer above it.

Key takeaways

  • Data sovereignty means data answers to the law of the country where it is physically stored. Sovereignty follows the hardware.
  • Residence, sovereignty and governance are three different things: location alone does not settle jurisdiction.
  • A dedicated server makes sovereignty verifiable: one physical machine in a named datacenter, no other tenant, no silent migration.
  • Responsibility splits: the provider answers for the site, network and machine; your organisation answers for the OS, services and data.
  • Certified infrastructure (ISO 27001, HDS) is necessary but not sufficient: the compliance programme itself remains yours.

Understanding data sovereignty and why it matters for dedicated hosting

Data sovereignty means your data falls under the jurisdiction of wherever it physically sits. Move a database from Frankfurt to Virginia and the applicable law changes, along with which government can compel disclosure. Sovereignty follows the hardware. Data sovereignty is a procurement question now, not a footnote.

Three ideas get confused. Data residency is geographic: data stays in this region. Data sovereignty is legal authority: this data answers to this jurisdiction. Data governance is your internal framework for handling it. An organization can satisfy residency and still fail sovereignty, when a vendor sits under a legal regime with extraterritorial reach.

Dedicated infrastructure improves your sovereignty posture, which regulators test. On multi-tenant platforms your workload sits on hardware whose location may shift. A dedicated server is one physical machine in one named data center, with no other tenants and no silent migration. You know where the data is because the machine does not move.

For an organization under strict compliance restriction, that is the point. A dedicated machine in a jurisdiction you selected answers the question every auditor asks: where is the data, and whose law applies?

Key compliance requirements for dedicated servers

Most data sovereignty requirements reduce to a short list of obligations. Data sovereignty obligations are worded differently in each framework, but the controls converge, and all exist to ensure data stays where the law expects it.

RequirementWhat it means in practiceTypical framework
Data localisationRegulated data stays inside a defined territoryGDPR, national health law
Access controlOnly named individuals reach production dataISO 27001, SOC 2
EncryptionProtection of data at rest, in transit, and in usePCI DSS, HDS
Cross-border restrictionsLawful basis before regulated data leaves the regionGDPR Chapter V
Compliance evidenceRecords proving the controls actually operateEvery framework
Breach notificationDefined timelines for reporting data incidentsGDPR, sector regulators

Two points matter when your organization checks a vendor against these requirements. Responsibility splits: the service provider is accountable for facility operations, network and machine; your organization for the operating system, its services and the data inside it. And certification of the provider's infrastructure is necessary but not sufficient for data sovereignty compliance: an ISO 27001-certified datacenter does not make an unpatched service compliant.

Responsibility line: provider vs customer on an unmanaged dedicated server

That split is the model, not a loophole. Knowing which side each control sits on makes a sovereignty compliance programme survive its first review. It is also where vendor assessments go wrong, because buyers read a certification badge as proof they comply.

How Kimsufi dedicated servers support data sovereignty requirements

Kimsufi is a Kimsufi by OVHcloud range, running in OVHcloud datacenters. Three characteristics carry most of the data sovereignty weight, and each maps to a specific compliance obligation.

You choose the specific jurisdiction. Servers are available in France, Germany, the United Kingdom, Poland, Canada, Australia, Singapore and India. Your organization selects the country at order time, and the machine stays there. For an EU data policy with no exceptions, this is the control that enforces it.

The facilities are certified. OVHcloud datacenters are ISO 27001-certified. Dedicated servers in France run from Gravelines, Roubaix and Strasbourg, with ISO 27001, ISO 27701 and HDS certification. OVHcloud is a European provider subject to the GDPR, and processing is framed through GDPR-compliant agreements. That is the substantive difference between residency and sovereignty for many buyers: EU data stays under EU law.

You keep the root. Kimsufi servers are unmanaged, which makes sovereignty verifiable. No provider process runs inside your operating system, and nobody administers your data store. To document who reaches production data, exclusive hardware with sole root access beats a shared-responsibility diagram. Unlike colocation, you neither own nor ship the hardware, so the data sovereignty benefit arrives without the capital cost.

What Kimsufi does not do is manage data sovereignty compliance on your behalf. There is no managed compliance service, no policy engine and no advisory service attached. You get certified infrastructure, your chosen jurisdiction, dedicated resources and full control. The programme is yours to run.

Encrypted data transfer

Encryption of regulated data spans three states, each with different responsibility. Getting the split wrong is the commonest source of data sovereignty exposure.

At rest. Your responsibility. Full-disk encryption via LUKS, or database-level encryption, on your own storage. Because the machine is single-tenant, you control the keys with no provider in the path. That is how you secure data on a disk you do not physically own.

In transit. Mostly your responsibility. You terminate TLS for public traffic and tunnel private traffic with WireGuard or IPsec, using whichever tool your team already runs. The platform contributes vRack, a private network linking your servers across sites, so internal replication of sensitive data never crosses the public internet.

In use. Platform-assisted. A confidential computing server uses hardware enclaves, via Intel SGX or AMD Infinity Guard, to create a secure zone inside the processor. Code and data executing there are isolated from the operating system and from administrative access. Confidential computing closes the gap the first two states leave open, and it is the one control that keeps data unreadable while it is being processed.

Cross-border replication needs the same care as the primary workload. A backup and recovery server in a second facility inside the same region keeps recovery within your jurisdiction, and avoids an unlawful transfer through the back door of your backup policy.

Audit-ready reporting and continuous monitoring

Being audit-ready means producing data sovereignty evidence on demand. It comes from two sources, and it is worth knowing which is which in advance.

The infrastructure layer is covered by certification. OVHcloud publishes the ISO 27001, ISO 27701 and HDS certifications for its data centers, covering physical security, facility operations and the network. Your organization references them as third-party evidence for the parts of the estate you do not operate, which is why data governance records must cover the rest.

Everything above the metal is yours to evidence, and on an unmanaged server nothing collects it by default. A workable baseline:

  • System and access logs. Ship auth and system data off the machine so it survives the machine.
  • Configuration state. Keep firewall rules and server configuration in version control, so change history is a byproduct of how you work.
  • Continuous monitoring. Run your own tool for availability, disk and integrity checks, with alert thresholds you can defend.
  • Access review. Document who has credentials to production data, and review it on a schedule to ensure the list stays current.
  • Data inventory. Record what regulated data you hold, where it sits, and how long you keep it, to ensure data claims match reality.

None of this is exotic, but decide it early. Retrofitting an audit trail after eighteen months of undocumented change is expensive. Support from your provider will not fill the gap.

Choosing the right server configuration for your industry

Sector rules drive specific data handling more than raw performance does.

SectorDominant constraintConfiguration priority
HealthHDS-certified site, strict access controlFrench datacenter, confidential computing
FinanceEvidence depth, transaction integrityRedundant storage, log retention, confidential computing
Public sectorNational sovereignty, procurement rulesIn-country site, documented data flows
SaaSCustomer contractual commitmentsPer-region deployment, tenant isolation
E-commercePCI DSS scope on payment dataSegmented network, scoped cardholder data

Two decisions matter more than CPU choice. Storage capacity sets log and backup retention, a regulatory question more than a technical one. Datacenter selection sets the legal regime, so a SaaS organization serving EU and Canadian customers will operate one machine per region.

Sector-specific compliance requirements also govern retention. A finance organization may comply with seven-year record keeping, while a SaaS vendor faces contractual deletion deadlines. Both are storage decisions taken at order time, and both ensure data is neither kept too long nor lost. Retention limits ensure the audit evidence survives.

Illustrative scenario: enterprise compliance on Kimsufi dedicated servers

This is a worked example, not a customer reference.

A 40-person analytics organization sells to European insurers under EU data rules. Strict contract requirements say customer data never leaves the EU, encryption applies throughout, and access data is available within one business day. Those are typical data sovereignty commitments for a SaaS vendor in a regulated sector.

It runs two servers in Gravelines, one for the application and one for the database, connected over vRack so replication never touches the public internet. Disks are LUKS-encrypted with keys held by the organization. Nightly backups go to a second French site, keeping recovery inside the same jurisdiction. Logs are retained for thirteen months, and configuration lives in a private repository, giving a complete change history.

Sensitive model training runs inside a confidential computing enclave, so data is never exposed. When the insurer's auditor asks where the data is, the answer is two named machines in a named French data center, under one jurisdiction. The certifications cover the building; the organization's records cover the rest. That division is how a small company meets requirements written for a much larger company.

Frequently asked questions

What are the key principles of data sovereignty?

Four principles carry most of data sovereignty. Data is governed by the law of the specific territory where it is stored. That territory must be known and stable, not floating across a region, so you can ensure the location is provable. Any cross-border movement of regulated data needs a lawful basis first. And you must prove all three with records. Data sovereignty is a claim you evidence, not a setting you enable.

What is the difference between data sovereignty and data residency?

Residency is geographic: a commitment that data sits in a stated location. Data sovereignty is legal: which government and courts hold authority over it. They usually align, but not always. A provider can store your data in Europe while remaining subject to a foreign regime that compels disclosure, satisfying residency and failing sovereignty. Vendor nationality matters as much as the map.

How are cross-border data transfers secured on a dedicated server?

Encryption in transit is your responsibility to configure: TLS for public endpoints, WireGuard or IPsec for server-to-server links. Between Kimsufi servers, vRack provides a private network isolated from the public internet. For data in use, confidential computing keeps it unreadable during processing. Note that encryption alone does not make a transfer lawful: if regulated data leaves its jurisdiction, you still need a legal basis, and no technical control substitutes for a lawful basis.

What audit reports are available for Kimsufi dedicated servers?

The relevant attestations are the data center certifications: ISO 27001 for information security management, ISO 27701 for privacy, and HDS for health data in France. These cover the facility, physical security and the network operations run by the provider. They do not extend to your operating system, applications or data, so compliance evidence for those layers comes from records your organization maintains against its own compliance framework.

Get started

Pick the jurisdiction first, then the hardware, because the data center decides which law applies to your data. Kimsufi dedicated servers start at $11.10/month and deploy in minutes, so you can validate a compliant configuration before committing a region. If health data, PCI DSS scope or per-region commitments apply, talk to a Solutions Architect first, since location choices are hard to reverse. Our dedicated server range lists availability by country.