Build log
Where Is Your Data If Europe Goes Dark?
The rhetoric of war in Europe has arrived. UK SaaS founders need to ask an uncomfortable question about their hosting decisions, and the answer is not simply "switch to US.
Nobody wants to write this post. So here it is.
The rhetoric of war in Europe is no longer background noise. It is a live variable in business planning, and if you run a UK SaaS company and you have not recently looked at where your data lives and what happens to it under a range of scenarios that would have seemed implausible three years ago, now is the time.
This is not a post with a clean answer. There is not one. Every hosting decision is a risk trade, not a risk elimination. What the current moment demands is that you understand the trade you are making, explicitly, with the actual variables on the table.
The On-Premises Question
On-premises infrastructure gives you control. No third-party dependency, no data leaving your building, no cloud provider terms of service sitting between you and your customers' data.
It also gives you a building.
What if the building is gone? What if the power grid is shut down, regionally or nationally, as part of a conflict that targets infrastructure before it targets anything else? What if your backup generators ran out of diesel and the supply chain that refills them has stopped working?
These are not hypothetical questions in 2026. They are the questions that organisations in Ukraine, and now others watching carefully from neighbouring countries, have had to answer under real conditions. The answer to on-premises sovereignty is not nothing. But it is not complete either. Physical resilience requires geographic distribution, and geographic distribution requires you to decide where the second and third copies of your data actually live.
The US Hosting Question
The obvious reflex, when Europe feels unstable, is to route everything to US infrastructure. AWS, Azure, GCP, all headquartered outside the conflict zone, all with enormous physical redundancy, all with uptime guarantees that no on-premises setup can match.
The CLOUD Act disagrees with the simplicity of that logic.
US-headquartered cloud providers are legally obligated to comply with US government requests for data stored anywhere in the world, including in their European data centres, without necessarily notifying you or your customers that this has happened. Executive orders can extend or modify those obligations faster than your legal team can review the implications. Bilateral data-sharing agreements between the US and other governments can create exposure you did not know existed when you signed your enterprise contract.
If your customer base includes NHS organisations, financial services firms, or any regulated entity with explicit data residency requirements in their contracts, you should read those clauses again today. Not because something has changed in your hosting setup. Because the political context in which those clauses were written has changed, and the risk they were designed to mitigate now has a different shape.
Routing your data to Virginia in response to instability in Eastern Europe is not a risk mitigation strategy. It is a different risk with a different flag on it.
The EU Sovereign Cloud Question
The European response to these concerns has been a push toward EU sovereign cloud. Gaia-X, various national initiatives, a growing market of providers positioning on data residency and regulatory alignment.
The honest assessment is that EU sovereign cloud is real but uneven. The redundancy, the geographic distribution, the uptime performance of the major US hyperscalers is not matched by most sovereign alternatives at the same price point. That gap is closing. It has not closed yet.
There is also a political question underneath the technical one. The sovereignty guarantee of a European hosting provider is underwritten by the political stability of the jurisdiction it operates in. That stability is currently the variable under discussion. Sovereign cloud hosted in a country whose sovereignty is under active rhetorical or physical threat is a different proposition from sovereign cloud hosted in a country that is not.
What Your Risk Register Actually Needs
Most UK SaaS companies have a risk register. Most of those risk registers have a data hosting section. Most of those sections were last meaningfully reviewed before the current geopolitical situation looked the way it looks now.
The questions that section needs to answer today:
Where does your data physically live, in every environment, production, staging, backup, DR?
What is the legal jurisdiction of every provider that touches that data, and what are their obligations to foreign governments under current law?
What are your contractual obligations to your customers around data residency, and have you verified that your current infrastructure meets those obligations under a range of scenarios, not just the stable one?
What is your recovery plan if your primary hosting becomes unavailable, not for hours but for weeks, and what does that plan assume about the availability of infrastructure, fuel, connectivity, and personnel in the same scenario that took your primary hosting offline?
Who owns this question in your organisation, and when did they last review it?
The Uncomfortable Truth
There is no hosting decision that eliminates risk. On-premises gets bombed. US cloud gets legislated. EU sovereign cloud gets disrupted by the same instability that prompted the question in the first place. Multi-cloud distribution raises its own questions about data consistency, compliance complexity, and cost.
What the current moment requires is not a different answer. It is an honest assessment of which risks you are carrying, which ones your customers know about, and which ones are sitting quietly in a risk register that nobody has opened since the world looked different.
The rhetoric of war has a way of making vague risks suddenly specific.
Update your risk register. Read your hosting contracts. Have the conversation with your legal team and your largest customers before the conversation becomes urgent for the wrong reasons.
That is the whole post. No clean answer. Just the question, asked clearly, while there is still time to think about it properly.