Storing data in Europe is not the same as controlling it
Data sovereignty is often treated as a question of geography. In practice, it is just as much about legal reach and operational control.
Eurojust, the EU agency that supports judicial cooperation in criminal matters, has explained that the U.S. CLOUD Act made explicit that U.S. service providers can be required to preserve and produce data they control, regardless of where that data is stored.
In plain language: EU hosting does not automatically remove U.S. legal exposure when the provider remains subject to U.S. jurisdiction.
For organisations handling body-worn video, that distinction matters. These systems often process sensitive footage, involve public-facing incidents, and sit in environments where accountability and chain of custody matter.
The risk becomes more serious when:
- the provider is subject to U.S. jurisdiction through ownership, control, or operational nexus
- support or administration can access data from outside the EEAÂ (European Economic Area)
- sub-processors sit in third countries, or key services rely on non-EEA entities
The CJEU’s Schrems II ruling underlined why this matters. EU law requires essentially equivalent protection when personal data is exposed to third-country public authority access.
Where the tension starts: U.S. legal access versus EU data protection rules
GDPR is not the source of the problem. The real issue is that U.S. law may compel certain providers to disclose data under their control, while EU data protection law sets strict limits on when personal data may be disclosed or transferred.
That creates a direct tension for organisations handling sensitive body-worn video. Even if the data is stored in the EU, exposure to a provider under U.S. jurisdiction can still raise sovereignty and compliance questions.
The European Data Protection Board has clarified that a foreign government order does not automatically create a lawful basis under GDPR for disclosure or transfer. In other words, receiving an order is not the same as being allowed to comply with it under EU law.
For legal teams and procurement leads, that means vendor assessment should go beyond storage location alone.
A checklist for Legal Affairs and procurement
When assessing a provider, the key questions are straightforward:
- Who is the legal counterparty, and which jurisdiction governs it?
- Who can technically access the data, including support and incident response?
- What is the documented process for third-country requests, including challenge, notification, and transparency reporting?
- Who controls the encryption keys, and can the provider access them?
EDPB Recommendations 01/2020 also explain why supplementary measures, including strong encryption and organisational controls, may be necessary when transfer tools alone do not provide EU-equivalent protection.
What this means in practice
For many organisations, the practical lesson is simple: EU data storage on its own is not enough. If sensitive video data may still be reached through U.S. jurisdiction, then the real assessment has to include provider structure, operational access, subprocessors, and governance.
That is especially relevant for police, enforcement, inspection, and other public-sector contexts where recorded footage can contain personal data, evidence, or legally sensitive material.
Where ZEPCAM fits
For organisations that want to reduce potential exposure to U.S. jurisdiction, a more structural mitigation is to choose a body-worn video provider whose ownership, hosting model, and operational setup are designed to minimise that exposure as far as possible.
ZEPCAM is a European body-worn video provider headquartered in the Netherlands, with a Dutch legal and operational base. It offers deployment options that can support stronger local control over sensitive video data, including ZEPCAM-managed hosting in selected jurisdictions and customer-controlled infrastructure where applicable and on-premise installation.
ZEPCAM also highlights recognised certifications for information security, cloud security, and privacy controls, including ISO 27001, ISO 27017 and ISO 27018, where applicable within its service model.
This does not remove every compliance obligation, but it can help organisations reduce legal and operational exposure compared with provider models that remain more closely tied to non-EU jurisdiction.
Final thought
If body-worn video is part of your operational or legal workflow, the right question is not only where your data is stored. The more important question is who can ultimately be compelled to access it.
That is where the difference between storage and sovereignty becomes very real.
