Cloud and data sovereignty caught in a paradox | Computer Weekly
Summary
The piece investigates how US-based hyperscaler cloud providers may be incompatible with data sovereignty because US legal instruments (Cloud Act, FISA) can compel access to overseas data and technical assistance. It finds vendor responses avoided core technical issues and highlights risks such as court-ordered compiled updates, data-in-use vulnerabilities, and routine cross-border data transit in standard terms. The article warns customers must opt out of standard cloud terms, use air-gapped services, or accept residual risk, noting no approach is 100% proof against intrusion. It emphasizes the urgency for the UK public sector, which heavily relies on US hyperscalers, and notes gaps such as DSIT lacking a clear definition of data sovereignty.