
UK data residency matters when your sector, contracts, risk profile or the type of information you hold demand it. For many other businesses, it matters less than the marketing suggests.
London Tech Week in June 2026 put sovereignty firmly in the spotlight. The government announced a £400 million commitment to specialist AI compute, while Microsoft has set out a $30 billion, about £23 billion, UK investment running from 2025 to 2028 across cloud, AI infrastructure and operations. The UK technology sector is now widely reported at around £1.2 trillion in value. That is serious money, but it does not mean every SME suddenly needs a sovereign cloud.
The useful question is narrower: where does your data actually need to sit, who can access it, and under whose law?
Data residency is not the same as data sovereignty
Two ideas often get muddled. Data residency is about where data is physically stored. Data sovereignty is about which country’s laws and controls apply to the data, the provider and the people who manage the service.
A US-headquartered provider can store your files in a UK data centre and still be subject to overseas legal obligations in some circumstances. So “stored in the UK” and “beyond the reach of foreign law” are not the same claim.
The ICO makes a practical point in its brief guide to international transfers. Transfer rules focus on whether personal information is sent or made accessible to a separate organisation outside the UK. In cloud contracts, that usually means looking at the legal entity you contract with, where support and processing may happen, and what safeguards are in place, not just the location of a server rack.
When UK data residency actually matters
| Situation | Does residency matter? | What to check |
|---|---|---|
| Regulated sectors such as health, finance, legal or defence | Often yes | Regulator guidance, client terms and procurement rules |
| Public sector contract | Often yes | Tender wording, framework terms and security classifications |
| Special category personal data | Sometimes, depending on risk | Lawful basis, Article 9 condition, safeguards and transfers |
| Customer contract mandates UK storage | Yes, contractually | Exact wording, audit rights and subcontractor clauses |
| General business data on standard SaaS | Usually less critical | Data region settings, processing terms and transfer safeguards |
So when does residency genuinely matter? If you are in a regulated sector, your regulator, insurer or client may require UK or in-region storage. If you hold a public sector contract, the tender may specify it. If you process sensitive health, legal, HR or financial data, the level of scrutiny is higher. And if a customer contract says data must stay in the UK, that is binding even if the technical risk is manageable.
Picture a small legal firm holding client files. A client’s outsourcing clause may demand UK-only storage, named subcontractors and clear access controls. In that case, residency is not a nice-to-have. It is part of the contract.
When sovereignty is oversold
For a lot of SMEs, residency matters less than getting the basics right. If you run Microsoft 365 or Google Workspace in an appropriate UK or EU data region, sign the correct processing terms, understand your subprocessors and complete a transfer risk assessment where needed, you have covered much of the substance of your data protection duties.
The timing also matters. Some cloud sovereignty announcements are infrastructure roadmaps, not products you can buy fully today. Microsoft’s UK investment runs through 2028, and Microsoft Sovereign Cloud is a broader set of capabilities, not a single magic switch. Buying sovereignty you do not need is just cost. It is the same judgement as deciding whether you ever needed an on-premise server, or whether the cloud was already the better home for your data.
What to do next
The practical path is dull but effective. Map where your data actually lives, including the SaaS tools staff signed up for without telling anyone. Your cloud providers are part of your supply chain, a point the 2025 retail attacks made expensive for several household names.
Then match each system to its real obligation rather than a slogan. A structured review of your cloud estate is the right starting point, and it helps to understand the cloud jargon like IaaS and SaaS before you sit across the table from a vendor selling sovereignty.
If you are weighing this up, our IT strategy consulting can help you separate genuine requirements from marketing. For firms with strict client or sector obligations, network penetration testing gives you evidence that wherever your data sits, the controls around it hold. And if you want day-to-day mapping and management handled, that is what our IT support for London businesses is there to do.
FAQs
What is the difference between data residency and data sovereignty?
Data residency is where your data is physically stored. Data sovereignty is about the laws, access controls and legal obligations that apply to the data and provider.
Does my business data have to stay in the UK?
Only in specific cases. Regulated sectors, public sector contracts, customer agreements and higher-risk personal data can make UK or in-region storage important.
What is sovereign cloud?
It is cloud infrastructure and governance designed to give customers stronger control over data location, access, administration and legal exposure.
Is Microsoft 365 data stored in the UK?
Microsoft offers UK data residency options for many core services, but exact storage and processing depend on your tenant, service, licence and configuration.
Work out what you actually need
Sovereignty is a useful idea that is often oversold to people who do not need it. If you want help mapping where your data sits and matching it to your real obligations, talk to Northern Star and we will give you a straight answer rather than a sales pitch.