At the moment, there is a very real tension that’s building in the world of business communication. On one end, you’ve got global VoIP providers. These are companies who have spent years building seamless borderless calling infrastructure for remote and global teams to work as efficiently as if they were in the same room.

On the other side, you’ve got governments who believe that this data floating around in the cloud needs to land somewhere specific – preferably somewhere they can access.

This is the age of cloud sovereignty. And if you’re running a business that relies on a hosted phone system, it’s a topic you need to understand.

 

What Is Cloud Sovereignty?

 

In a nutshell, cloud sovereignty refers to a country’s right to control data that is generated within its borders. That would be control over where that data is stored, who can access it and, most importantly, which laws govern it.

Now, in the past, this was completely invisible to most businesses. They would sign up for their VoIP service, make their calls and move forward with business as usual, usually giving zero thought to where their call records were actually sitting.

Most of the time, it was in a data centre in the United States, operated by a handful of giant American tech companies. And that started to make some governments feel uncomfortable.

 

How A Court Ruling In Luxembourg Changed Your Phone System

 

The European Union has possibly been the most aggressive actor here. The General Data Protection Regulation (GDPR) was really just the opening act.

As the EU pushed for more European technological sovereignty, it translated into a lot of pressure on communication providers to keep European data on European soil.

The Schrems II ruling in 2020 was a significant turning point. It invalidated the Privacy Shield framework that had allowed relatively easy data transfers between the EU and US – and it sent compliance teams at every major cloud provider scrambling.

For VoIP platforms specifically, where metadata like call times, durations and participant numbers can be just as sensitive as the content itself, it created quite the headache.

 

The UK’s Post-Brexit Tightrope Walk

 

It gets a bit interesting here for UK businesses in particular. Post-Brexit, the UK is no longer bound by EU data rules. However, it still needs to maintain an “adequacy decision” which is essentially the EU’s approval in saying that UK data protection standards are good enough to allow data flows between the two regions.

The UK government has been working to loosen data protection rules to make trade easier, particularly with the US. And every time that conversation resurfaces, it raises new questions about whether the EU might revoke adequacy status. Should that happen, it would be a disaster for UK-based VoIP providers serving European customers.

 

Data Localisation Has Now Gone Global

 

It isn’t just Europe. India has introduced data localisation requirements for certain categories of sensitive data. Russia has enforced laws requiring personal data on Russian citizens to be stored domestically – that was back in 2015 already. China’s data security framework makes it nearly impossible for foreign cloud providers to operate without local infrastructure or a domestic partnership.

For a global VoIP providers, it’s a serious operational challenge. Trying to build and maintain data centres in multiple jurisdictions is expensive and highly complex.

 

What Does This All Mean For VoIP Providers?

 

All of this legislation has to land somewhere. For VoIP providers, it happens to land squarely on their infrastructure, their sales pitches and their legal team’s desk.

 

Costs Of Infrastructure Are Climbing

 

The days of running a lean, centralised cloud architecture are getting harder to justify. Providers who want to serve enterprise customers in regulated markets need regional infrastructure. Which means capital expenditure on data centres or commercial agreements with local cloud partners.

For the smaller or mid-size VoIP providers, it’s a significant barrier to growth. They cannot absorb these costs as a specialist comms platform trying to compete on price compared to the likes of AWS and Google Cloud.

 

Compliance Complexity Is Becoming A Selling Point

 

However, those providers who invested early in compliant regional infrastructure are finding it’s become a real differentiator. Enterprise procurement teams, especially those in finance, legal and healthcare with regulatory layers stacked on general data laws, are asking much harder questions about data residency than they did a couple of years ago.

If a VoIP provider can prove with an audit trail that UK call data stays in the UK while German data stays in Germany, it’s a pretty compelling message for a certain kind of buyer.

 

The Lawful Intercept Minefield

 

Another dimension of cloud sovereignty that doesn’t get talked about enough is lawful intercept obligations. Most countries require communications providers to hand over call data to law enforcement, under certain conditions.

So when your infrastructure is distributed across multiple jurisdictions, figuring out which country’s legal process takes precedence becomes rather complicated.

 

What Businesses Should Be Asking Their VoIP Providers Now

 

If you are in charge of of the communications infrastructure within your company, now is the right time to ask your provider direct questions. Where is your call data stored? What would happen if the UK’s adequacy decision changes? How is data subject access requests handled across jurisdictions?

These aren’t questions designed to trick your provider. They are things that your provider should have legitimate answers for. If they don’t, that in itself is quite useful.