With rising uncertainty around global data regulations and an increasing demand for clarity on digital sovereignty, new research from BARC is shedding light on how organisations are responding. Ahead of Big Data & AI World Frankfurt on 4-5 June, Dr Carsten Bange, CEO and Founder of BARC GmbH, sat down with us to unpack the findings from a new mini-survey on data sovereignty and what it means for cloud and infrastructure decision-makers in Europe.
– – – – – –
Carsten, welcome! You’ve just conducted a mini-survey on data sovereignty. Can you share a bit about the process and what you set out to explore?
Absolutely, Rebecca. Thanks for having me. I am very happy to speak about our latest research at BARC.
We find that the topic of data sovereignty is very hot right now. Wherever you go—even in private life—people are talking about it. It is basically driven by US politics. That is really the main driver behind the increased uncertainty around where things are heading. Things we once took for granted are no longer guaranteed.
This obviously affects the use of US-based hyperscalers. But our study also found that it is not just about the geopolitical situation; it is also about increasing regulation. Especially here in Europe, the European Union is pushing the topic of data sovereignty very high up the agenda.
That is why we conducted this survey. We had a great response—300 companies took part. It was short, just six questions, so it did not take much time. But the results were super interesting.
Why has data sovereignty transitioned from a compliance requirement to a core business priority in 2025?
It used to be more of a general topic—things like, “If data is stored in the EU, who can access it?” or “What are the requirements for handling it?” But now, it has become very concrete for companies.
The key issue is that it is increasingly obvious just how dependent most companies are on US hyperscalers. If your data is in the cloud, and that is the case for more and more businesses, it is typically stored with Microsoft Azure, Google Cloud, or Amazon AWS.
Now questions are arising: What happens if we cannot access that data anymore? What if there is a delay, or if we do not get access to the latest features on these platforms?
That is why the topic has become so concrete. It is not theoretical anymore—it is a real operational and strategic concern.
BARC’s recent mini survey found that 84% now see sovereignty as strategic. What surprised you most about the responses?
First of all, yes—84% is a very strong number. That alone signals that sovereignty is now a major issue for most organisations. But what really stood out to me was when we asked how this importance had changed over the last one to two years. About 70% of respondents said that the relevance of data sovereignty had increased. That clearly shows the momentum behind this topic.
Another interesting result came from the question, “What measures did you take here? How did you react to this increased importance of data sovereignty?” Many companies said they are now enforcing—or at least exploring—a hybrid cloud strategy. That shift really stood out.
We also saw that organisations are turning more toward local or regional cloud providers. They’re asking: “Where is my data actually hosted?” And notably, 19% said they plan to reinforce or even expand their on-premises strategy. That’s fascinating, considering we’re at least a decade into the cloud-first era. The fact that some are now reconsidering on-premises solutions shows just how seriously they’re re-evaluating sovereignty risks.
How do geopolitical tensions and evolving EU regulations shape the urgency around sovereignty, especially in the DACH region?
Yes, sure. One thing is that we have regulations, one after the other, coming into effect now. There is the EU Data Act, and for public bodies, there’s the Data Governance Act. We also have NIS2, and of course, GDPR still plays a big role. And now there is the AI Act, which also affects data, because without data, there is no AI.
So all of this is coming into effect and definitely has an influence. In some cases, data sovereignty is being enforced by law, or at least there is a regulation around it.
The other side is the political developments in the US. Things have become very uncertain, and the dependency on US software companies and cloud providers is now being seen as a potential problem—there is at least a risk. Before, nobody really cared. Now, it is something organisations are actively thinking about.
To put some numbers to it: 69% of respondents in our survey said that new legal requirements have influenced the importance of data sovereignty, and 46% said that political developments in the US contributed to that increased importance.
How can organisations balance innovation in AI with the need to secure proprietary datasets — is it a trade-off?
Yeah, maybe a little bit. I mean, companies are definitely looking more closely at this topic of data sovereignty now. When we asked how they want to tackle or strengthen their approach to sovereignty, about half of them said they plan to strengthen a hybrid cloud strategy.
That basically means they are being more careful about what goes into a public cloud versus a private cloud. I think the idea of the private cloud is gaining renewed interest and importance. Most data has already been moved to the cloud, and for many, going back to an on-premises system just isn’t an option anymore—often, the data centres simply are not there.
So, what can you do if you want to balance your risk? That is where private cloud options become quite interesting, and combining that with regional or local cloud providers is another key strategy. In fact, about 36% of respondents said they plan to increasingly use regional or local cloud providers. Running on a local cloud instance hosted by a local provider already gives you more control over where your data is stored.
The downside is that in many cases, it’s still US software that powers those environments, even if it is running in a local setup. So that is something else to consider. But based on the survey data, it looks like this combination—hybrid strategy, private cloud, and regional providers—is the main direction companies are exploring to manage both innovation and sovereignty.
What advice would you give to enterprises struggling with vendor lock-in while aiming for more sovereignty?
If you’re already locked in, then yes—it is a problem. So typically, my advice is more forward-looking.
One very simple recommendation: wherever you put your data, don’t just focus on the cost and restrictions around storing or using it on that platform. Also, look at what happens when you want to move that data off the platform, because some providers charge pretty hefty fees for exporting data. That’s something many companies haven’t looked at upfront. At the time, they were only thinking about how to move data onto the platform, not how to move it off again.
Another key point: look for open formats and open APIs. Make sure interoperability is technically supported from the beginning.
There is actually an exciting development here—open-source table formats that are gaining interest and traction. One of them is Apache Iceberg, and another is Delta. These formats let you store data in a way that’s independent of any specific platform. Your data platform or query engine of choice can pick it up, and you can switch engines later on if you want.
So, if you are thinking about your next data lakehouse implementation, I really recommend exploring these open table formats. They can help keep your options open and give you more flexibility to move between systems in the future.
Skills shortages and regulatory complexity came through strongly as challenges — how are leaders best overcoming these?
It really comes down to truly investing—and that is the pain point. Data is already a crucial competitive factor and a real asset for companies today, and that will only grow in the future.
When we talk about AI, most companies now recognise that they can only move forward with AI use cases—and an overall AI strategy—if they get their data in order. That means making it accessible, ensuring data quality, and more. All of that requires investment.
In our survey, 45% said missing personnel resources are a major challenge, and almost 40% cited a lack of internal expertise. These are the top two issues, and both can be addressed through investment. That includes hiring more people, but also educating the people you already have.
We all know there is a skills shortage, especially in key data-related roles. So companies need to think long-term: be attractive as an employer, hire people with strong data skills, and make data literacy a priority across all roles.
But realistically, we will not be able to hire our way out of every skills gap. So, continuous education—building up internal expertise and growing your existing talent—is just as important. That has to be part of the overall data strategy.
Is cross-functional collaboration between IT, legal and business teams improving, or still a weak spot?
So it is actually our advice that there should be more cross-functional collaboration. Because if you treat all of this in silos, it is not really helpful.
When you think about data sovereignty, there are several areas involved. We need IT know-how—what systems do we have, what cloud providers are we using, how can we move data, and so on.
But we also need security knowledge. And by the way, we have not touched on that yet, but cybersecurity and security incidents are also drivers behind data sovereignty considerations. Data has to be safe—shielded from outside, illegal access. That is a key part of sovereignty. And for that, we need security expertise, which is sometimes bundled under a Chief Security Officer or other security roles.
Then we need legal understanding—what can we actually do with the data? There are certain requirements, especially when it comes to personal data—data linked to individuals.
All of this needs to come together to understand how I can treat data, how I should treat data, and how I can approach data sovereignty effectively.
What misconceptions do organisations still hold about what “data sovereignty” really entails?
I believe that with the recent discussions and developments, most organisations now have a fairly clear understanding of data sovereignty. The topic has gained significant importance, and many companies are actively looking into it.
The real question is: what can we actually do about it? Because simply moving off cloud systems is, in most cases, not a realistic option.
My recommendation is to begin by classifying the data you have. Start with an inventory that not only lists your data but also includes classification. It is important to understand where your data is located and in which systems. Many organisations operate within highly heterogeneous technical environments, using a wide variety of providers.
With the current focus on risk assessment—something that has become much more important recently—it is essential to understand where data is stored, both physically and in terms of providers. You need to know what guarantees those providers offer, under what conditions you can access your data, and what risks are involved.
This also means considering potential risk scenarios: What happens if something unforeseen occurs? Do you have a backup plan? Where is that backup located?
There are many considerations, but the starting point must be to understand your current situation. What data do you have? Where is it located? How critical is it to your business? And what regulations must you comply with? Only then can you take meaningful steps toward improving data sovereignty.
Looking ahead, what does the “next generation” of sovereignty look like? Are we heading toward more decentralisation, or tighter regulation?
The regulatory landscape is certainly present, and I am sure there will be further additions. However, the current discussion within the European Union suggests a tendency not to over-regulate. For example, we saw some reconsideration in the area of supply chain regulation, and there are ongoing debates within the EU AI Act about whether the proposed measures may have gone too far. Some are now discussing whether certain aspects should be relaxed.
So, in the near future, I do not expect an increase in regulation. Rather, the main challenge is that the regulations which already exist are now coming into effect. Companies will need to pay close attention to these developments, and that will require significant resources and time in the coming years, both to understand and to comply with what is required.
On the other side, I believe we are seeing a wave of renewed risk assessments. What was previously considered low-risk or stable is now being re-evaluated. It is becoming clear that organisations must take a more careful approach moving forward.
This means thinking ahead about possible scenarios—what would happen if a provider becomes inaccessible, stops delivering services, or no longer receives updates? Do you have a backup plan in place? At a minimum, companies should be able to answer that question.
There is a new kind of risk that had not been previously accounted for. Even the largest cloud providers might become inaccessible for certain reasons. We might experience reduced performance, such as lower bandwidth, or find ourselves unable to guarantee who can access our data. We may even conclude that the data is no longer secure in those environments.
All of this is part of a new reality. The geopolitical landscape has shifted significantly, and organisations must now adapt to this changed environment by conducting more thorough risk assessments and preparing accordingly.
You will be speaking at Tech Show Frankfurt. What can audiences expect to learn from your session?
Absolutely. I have the honour of delivering the keynote, and I will definitely be sharing the detailed results of our latest survey. So for those interested in data sovereignty, it is a great opportunity to get first-hand insights into the findings.
In addition to the survey, I will also speak about two major developments we are seeing in the market. The first is on the AI side—there is a significant shift happening toward agentic AI. I find this development very exciting because it brings AI closer to operational business processes. This proximity makes it easier to demonstrate the value of AI and scale its use across the enterprise.
AI has been a hype topic for years, but many companies are still struggling to move beyond isolated prototypes and scale AI enterprise-wide. Agentic AI, as the latest evolution, can help overcome that gap.
The second trend is on the data side, and it is equally important for enabling enterprise-wide value: the move toward data products. I presented on this last year at Tech Show Frankfurt, and it was one of the sessions that was super well attended. So people are very curious to learn more about this concept of data products.
The concept is about rethinking how we treat and manage data—assigning real data ownership, redefining who those owners are, and improving how data is shared across the enterprise. If data becomes more accessible and easier to manage at scale, we can unlock its full value, including making AI initiatives more viable and impactful.
These two trends—agentic AI and data products—are closely linked. Both are critical to making AI and data strategies truly valuable and implementable in practice.
– – – – – –
Catch Dr Carsten Bange at Tech Show Frankfurt on 4 June as he unpacks the BARC survey findings and explores how AI agents, data products, and data sovereignty are shaping the future of enterprise-scale AI.
Note from the Editor: All quotes are verbatim from a recorded interview, lightly edited for clarity.
Be at the forefront of change with thousands of technologists, data specialists, and AI pioneers.
Don’t miss the biggest opportunities to advance your business into the future.