What is EU data sovereignty?
EU data sovereignty is an organisation’s ability to keep its data, and how that data is processed, fully under European law and its own control. It decides where data sits, who can access it, and which legal jurisdiction the operations and the provider fall under. Sovereignty is more than data residency: beyond where data is stored, it also covers legal access by third countries, control over operational and audit data, and the ability to switch provider without losing data. What matters is control, not renunciation: EU data sovereignty does not mean giving up capable international technology, it means keeping the governance and evidence layer above it inside the EU.
EU data sovereignty in detail
In practice, EU data sovereignty rests on three layers. First, data residency: storage and processing in data centres within the EU. Second, jurisdiction: the operator is subject to European law; for providers under US jurisdiction, the US CLOUD Act can allow government access regardless of where the data is stored. Third, operational control: who administers the platform, where is support based, and where are metadata, analytics and audit logs generated? Only once all three layers are answered on European terms are operations genuinely sovereign.
EU clouds such as STACKIT, run by the Schwarz Gruppe with data centres in Germany and Austria, address exactly these layers. Frameworks such as Gaia-X additionally set shared rules for transparency and portability. Sovereignty is not an end in itself under the GDPR, but it makes the burden of proof considerably easier: processing data in the EU under EU law avoids the complexity of third-country transfers.
Why EU data sovereignty matters in Zscaler operations
For many organisations, Zscaler is the established security platform, and rightly so: the Zero Trust Exchange inspects traffic inline and protects users worldwide. The sovereignty question sits one layer above that, in operations: where do the operational, analytics and audit data generated while managing the platform actually live, meaning user diagnostics, configuration analyses, approval logs and reports? For public authorities, operators of critical infrastructure and financial institutions, that layer is increasingly a procurement criterion in its own right: operational metadata should not leave the EU.
EU-sovereign Zscaler operations therefore mean this: Zscaler stays the security platform, but the governance, analytics and evidence layer above it runs in an EU cloud under European law. That keeps GDPR evidence, NIS2 and DORA records, and personal operational data within European jurisdiction, without having to give up your existing Zscaler investment.
Common sources of error
- Confusing sovereignty with giving up technology: this is about control over data and operations, not about replacing proven platforms.
- Looking only at primary data: operational metadata, analytics and audit logs are sensitive too, and belong within sovereign scope.
- Equating an EU region with EU sovereignty: an EU data centre run by a provider under third-country jurisdiction does not fully resolve the jurisdiction question.
- Forgetting the exit strategy: without data portability and documented ways to leave, sovereignty stays a label.
EU data sovereignty in practice: what CentaurNexus contributes
CentaurNexus is built as a sovereign operations layer on top of Zscaler: a single pane of glass for ZIA, ZPA and ZDX, based on the official OneAPI, hosted in Germany and run in compliance with the GDPR. Operational, analytics and audit data, from user diagnostics through Policy Health Saga reports to four-eyes approvals in the audit trail, stay in the EU this way, while Zscaler remains the security platform. CentaurNexus is thus the optimal complement to your Zscaler security stack. Sovereignty here is enforced technically, not just promised: the GDPR log anonymisation gateway truncates IP addresses and pseudonymises personal log data per tenant directly at egress, fail-closed and with no way round it. RBAC with domain scoping further ensures that, within the operations layer, only people who are authorised can see and change anything. What this looks like in practice is shown in the guide Zscaler support without admin rights.
Related terms
Frequently asked questions about EU data sovereignty
It means an organisation decides for itself where its data sits, who can access it, and which law governs processing and the provider. In concrete terms: storage and processing within the EU, an operator subject to European law, and control over all the operational and audit data this generates, including a realistic scenario for switching provider.
No. Data residency only describes where data is stored and processed. Sovereignty additionally covers the provider’s legal jurisdiction, control over operational and audit data, and the ability to switch. An EU data centre alone is not enough if the operator is subject to a third country’s jurisdiction and that country’s authorities can demand access.
Yes. Zscaler remains the security platform that protects traffic; the governance, analytics and evidence layer above it runs in an EU cloud under European law. Operational, analytics and audit data stay in the EU this way, while your existing Zscaler investment continues to be used in full.
The US CLOUD Act allows US authorities, under certain conditions, to access data controlled by providers under US jurisdiction, regardless of where it is stored. For European organisations, that is a reason to run at least the control and evidence layer of critical systems with an EU provider under EU law.
The GDPR requires lawful, demonstrable processing of personal data and sets tight limits on transfers to third countries. EU-sovereign operations make both easier: there are no third-country transfers for operational and audit data, and evidence stays within a single jurisdiction. GDPR obligations still apply either way, but sovereignty makes them considerably easier to meet.
- Regulation (EU) 2016/679 (GDPR), principles and third-country transfers - eur-lex.europa.eu
- Directive (EU) 2022/2555 (NIS2), risk management for essential and important entities - eur-lex.europa.eu
- BSI: Cloud Computing Compliance Criteria Catalogue C5 (requirements for cloud services) - bsi.bund.de/.../kriterienkatalog-c5
Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners.