Zscaler & Zero Trust operations glossary · Governance & sovereignty

What is EU data sovereignty?

Definition

EU data sovereignty is an organisation’s ability to keep its data, and how that data is processed, fully under European law and its own control. It decides where data sits, who can access it, and which legal jurisdiction the operations and the provider fall under. Sovereignty is more than data residency: beyond where data is stored, it also covers legal access by third countries, control over operational and audit data, and the ability to switch provider without losing data. What matters is control, not renunciation: EU data sovereignty does not mean giving up capable international technology, it means keeping the governance and evidence layer above it inside the EU.

EU data sovereignty in detail

In practice, EU data sovereignty rests on three layers. First, data residency: storage and processing in data centres within the EU. Second, jurisdiction: the operator is subject to European law; for providers under US jurisdiction, the US CLOUD Act can allow government access regardless of where the data is stored. Third, operational control: who administers the platform, where is support based, and where are metadata, analytics and audit logs generated? Only once all three layers are answered on European terms are operations genuinely sovereign.

EU clouds such as STACKIT, run by the Schwarz Gruppe with data centres in Germany and Austria, address exactly these layers. Frameworks such as Gaia-X additionally set shared rules for transparency and portability. Sovereignty is not an end in itself under the GDPR, but it makes the burden of proof considerably easier: processing data in the EU under EU law avoids the complexity of third-country transfers.

Why EU data sovereignty matters in Zscaler operations

For many organisations, Zscaler is the established security platform, and rightly so: the Zero Trust Exchange inspects traffic inline and protects users worldwide. The sovereignty question sits one layer above that, in operations: where do the operational, analytics and audit data generated while managing the platform actually live, meaning user diagnostics, configuration analyses, approval logs and reports? For public authorities, operators of critical infrastructure and financial institutions, that layer is increasingly a procurement criterion in its own right: operational metadata should not leave the EU.

EU-sovereign Zscaler operations therefore mean this: Zscaler stays the security platform, but the governance, analytics and evidence layer above it runs in an EU cloud under European law. That keeps GDPR evidence, NIS2 and DORA records, and personal operational data within European jurisdiction, without having to give up your existing Zscaler investment.

Common sources of error

EU data sovereignty in practice: what CentaurNexus contributes

CentaurNexus is built as a sovereign operations layer on top of Zscaler: a single pane of glass for ZIA, ZPA and ZDX, based on the official OneAPI, hosted in Germany and run in compliance with the GDPR. Operational, analytics and audit data, from user diagnostics through Policy Health Saga reports to four-eyes approvals in the audit trail, stay in the EU this way, while Zscaler remains the security platform. CentaurNexus is thus the optimal complement to your Zscaler security stack. Sovereignty here is enforced technically, not just promised: the GDPR log anonymisation gateway truncates IP addresses and pseudonymises personal log data per tenant directly at egress, fail-closed and with no way round it. RBAC with domain scoping further ensures that, within the operations layer, only people who are authorised can see and change anything. What this looks like in practice is shown in the guide Zscaler support without admin rights.

See in the live demo what EU-sovereign Zscaler operations look like in practice.Watch the live demo

Related terms

Frequently asked questions about EU data sovereignty

What does EU data sovereignty mean in concrete terms?

It means an organisation decides for itself where its data sits, who can access it, and which law governs processing and the provider. In concrete terms: storage and processing within the EU, an operator subject to European law, and control over all the operational and audit data this generates, including a realistic scenario for switching provider.

Is EU data sovereignty the same as data residency?

No. Data residency only describes where data is stored and processed. Sovereignty additionally covers the provider’s legal jurisdiction, control over operational and audit data, and the ability to switch. An EU data centre alone is not enough if the operator is subject to a third country’s jurisdiction and that country’s authorities can demand access.

Can Zscaler be run in an EU-sovereign way?

Yes. Zscaler remains the security platform that protects traffic; the governance, analytics and evidence layer above it runs in an EU cloud under European law. Operational, analytics and audit data stay in the EU this way, while your existing Zscaler investment continues to be used in full.

Why does the US CLOUD Act matter for European organisations?

The US CLOUD Act allows US authorities, under certain conditions, to access data controlled by providers under US jurisdiction, regardless of where it is stored. For European organisations, that is a reason to run at least the control and evidence layer of critical systems with an EU provider under EU law.

What role does the GDPR play in data sovereignty?

The GDPR requires lawful, demonstrable processing of personal data and sets tight limits on transfers to third countries. EU-sovereign operations make both easier: there are no third-country transfers for operational and audit data, and evidence stays within a single jurisdiction. GDPR obligations still apply either way, but sovereignty makes them considerably easier to meet.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.