Choosing a cloud communication platform used to be a fairly straightforward undertaking. But these days, there’s a lot more to consider than just features and pricing. The deciding factor is often based around data privacy regulations and who actually controls your data.
The General Data Protection Regulation (GDPR) set the tone back in 2018, which completely changed how European businesses handle anything remotely related to personal data – cloud communications included.
Those who are non-compliant face penalties reaching €20 million or 4% of annual global revenue, whichever is higher.
An even murkier factor is cloud sovereignty. The US Cloud Act enables American law enforcement to compel US-based companies to hand over data that is stored abroad, even those belonging to non-US citizens.
For businesses, it has become a concrete governance and risk issue. A few industry experts share how cloud communication decisions are being impacted going forward.
Our Experts
- Srinivas Chippagiri: Senior Member of Technical Staff at Tableau
- Andrei Romanescu: Chief Marketing Officer at LumaDock
- Colleen Barry: Head of Marketing at Ketch
- Finlay Wellington: Founder of Wellington Web Co
- Jon English: VP of Product at VQ Communications
- Julian Gage: Founder of Engage Compliance
- Michael Machado: Chief Information Security Officer at RingCentral
- Jake Madders: Co-founder of Hyve Managed Hosting
- Karl Mendez: Managing Director of CWCS Group
- Jad Jebara: CEO of Hyperview DCIM
- Jonathan Wright: Partner at Hunton Andrews Kurth
- Nilesh Chavda: Digital Strategy Lead at VIP Apps Consulting
- Ken Barth: CEO of Catalogic Software
Srinivas Chippagiri, Senior Member of Technical Staff at Tableau

“GDPR and data sovereignty are huge topics right now when companies decide how to handle cloud communications. This is especially true if sensitive info is involved. These days everyone wants to know exactly where their data lives, who can see it, and if you can really prove you’re following all the rules and compliance guidelines.
Look at Microsoft’s EU Data Boundary. They guarantee data from their services stays inside the EU. AWS is getting in the game too by launching a European Sovereign Cloud out of Germany to help companies stick to stricter data residency and access controls. At this point, it’s not just governments paying attention but every big company is thinking about it.
What people want are actual guarantees and not just promises. They want to ensure companies are keeping data local and making sure it’s safe. They want detailed audit logs and effective retention policies. It needs to be very clear about who touches the data. Now throw AI into the mix, and things get trickier. And just like that, voice recordings and chat logs will be used to train models unless you’re careful and set hard boundaries.
So, don’t just treat cloud communications like some regular productivity software. Assume you’re managing regulated data right from the start. And always put compliance and trust at the centre of your decisions.”
Andrei Romanescu, Chief Marketing Officer at LumaDock

“Data sovereignty in cloud has shifted from a compliance exercise to a procurement filter. Two years ago a buyer asked “are you GDPR-compliant?” and accepted a tickbox answer. In 2026 they ask “which specific AZ does my data sit in, who owns the facility, what is the legal entity and can I get a data-residency clause in the contract?”
The answers decide if a deal closes. But here’s whats pushing it: ChatGPT-style tools sending EU customer data through US infrastructure, the Schrems II legal fog around US transfer mechanisms, growing pressure from the EU AI Act on US-based managed AI services and a rise in customer audits asking about sub-processor lists. Buyers don’t have time to track the case law so they outsource the worry to providers that can guarantee a single jurisdiction end-to-end.
We opened Paris in September 2025 specifically because customers asked for an EU-resident AZ outside any 14-Eyes data-sharing arrangement. Helsinki and Madrid followed. Each launch was demand-led. The site decisions came AFTER the customer signal.”
Colleen Barry, Head of Marketing at Ketch

“GDPR and data sovereignty are now central drivers of how organisations design and choose cloud communication systems. Instead of treating data as freely movable, companies must decide where data is stored, processed, and transmitted, and ensure it aligns with regional laws. This shifts architecture toward region aware routing, localised data processing, and strict controls on cross border transfers. Under GDPR, even metadata in communication tools is sensitive, so enterprises adopt data minimisation, encryption in transit and at rest, and stronger access governance.
Data sovereignty pushes further, especially in sectors like government, finance, and healthcare, where regulators require that certain datasets never leave national boundaries. This leads to the rise of sovereign cloud models and hybrid architectures where sensitive workloads stay local while less sensitive communication flows through global infrastructure. From a product strategy view, vendors are now evaluated not just on performance but on compliance transparency, auditability, and ability to offer regional isolation.
In practice, this also changes communication tool selection, favouring platforms with built in residency controls, flexible key management, and detailed logging. Ultimately, compliance is no longer a constraint but a design principle shaping resilient, trust driven cloud communication ecosystems.
Organisations that ignore these requirements face higher legal risk, increased latency tradeoffs, and reduced trust from customers operating in regulated markets globally over time now.”
Finlay Wellington, Founder of Wellington Web Co

“Running Wellington Web Co, I’ve noticed a real shift in how businesses think about data over the last few years. Clients are no longer just asking whether a service works, they’re asking where their data is stored, who has access to it and what happens to it once it’s uploaded.
From my experience working with websites, cloud infrastructure and cybersecurity, GDPR has pushed businesses to take a much more proactive approach to data management. At the same time, growing concerns around AI, third party software and international data transfers have made data sovereignty a much bigger consideration than it was a few years ago.
For many small businesses, compliance isn’t really the driving factor. Trust is. Customers want confidence that their information is being handled responsibly and businesses want to avoid unnecessary risk. As a result, we’re seeing more organisations pay attention to their hosting providers, cloud platforms and security practices when making technology decisions.
The companies that treat privacy and security as part of their overall customer experience rather than a regulatory box ticking exercise are often the ones best positioned for long term growth.”
Jon English, VP of Product at VQ Communications

“GDPR kickstarted the discussion around data storage locations and who has access. That line of questioning has expanded beyond compliance into a broader discussion surrounding digital sovereignty, with many organisations realising that simply hosting data in a particular geography does not necessarily mean they control the infrastructure, encryption keys or management plane behind it.
We’re seeing growing interest in hybrid and self-hosted communication models, especially across government, defence, critical infrastructure and highly-regulated industries that struggle to stay compliant in cloud-exclusive infrastructure.
There’s rarely one solution that fits all, with organisations becoming more selective about which workloads remain in the cloud and which within environments where they have sole control. Communication platforms are increasingly part of that discussion because they often carry some of an organisation’s most sensitive information.
The result is a shift away from a purely cloud-first mindset towards a more balanced approach that combines the flexibility of cloud services with the security and sovereignty benefits of self-hosted infrastructure.”
Julian Gage, Founder of Engage Compliance

“Three main pieces to consider here:
- Region choice: companies now use EU-based databases for Teams, Slack and Zoom by default, and refuse vendors who cannot keep messages, call recordings and transcripts inside the EU.
- AI usage: whether or not to switch on AI notetakers, transcription and copilots that send voice and chat data to US models. Many of my clients are turning these off, or heavily restricting them, until the data flow is contractually pinned down.
- US-owned services (even if stored in the EU/UK) mean that US government can likely access your data should they care about doing so.
The effect is that legal and procurement teams will write-up data residency, subprocessor and government-access terms straight into contracts do a transfer impact assessment before signing, and ignore service providers who answer with marketing one-pagers instead of signed commitments. One example: Microsoft’s EU Data Boundary and sovereign cloud offerings exist because buyers forced the issue.”
Michael Machado, Chief Information Security Officer at RingCentral

“Organisations aren’t spending time deciding whether to move to the cloud; that decision has been made. They’re spending more time understanding how their data is handled once it gets there. GDPR requirements and data sovereignty concerns have set a new standard for cloud providers.
Customers want clear answers about how data is handled, where it resides, who has access to it, and what safeguards are in place. That’s been increasingly true over recent years, and this trend is continuing as AI capabilities become more deeply embedded into communications platforms.
The nature of impact is different for the customer and the vendor sides. The question of where data resides, who can access it, and jurisdiction topics, join existing buyer criteria such as features, user experience, and cost. Being able to provide a wider set of answers and more operational flexibility for customers is a competitive differentiator. This influences vendor obligations, strategic decisions, technical architectures, and cost structures.
Key considerations include which regulations apply to the vendor, its customers, target industries, and geographic markets; what measures support go-to-market success and customer adoption beyond regulatory requirements; and which partners and suppliers can provide the capabilities needed both today and in the future.
It also raises questions about whether regionalisation and segmentation are technically and commercially viable, how additional requirements affect operating costs and pricing, and whether they slow the pace at which vendors can deliver product enhancements to specific customer segments.”
Jake Madders, Co-founder of Hyve Managed Hosting

“As data volumes grow and workloads move across distributed cloud platforms, simply knowing where data is stored is not enough. Organisations must also understand which laws apply to that data and whether their provider can guarantee it will not be transferred across jurisdictions without visibility or consent.
This challenge is intensifying as the regulatory landscape continues to shift. GDPR remains a foundation, but post-Brexit transfer rules and rulings such as Schrems II have raised the bar on accountability. Cloud governance can no longer be treated as a one-off compliance exercise; it requires continuous oversight, particularly in highly regulated sectors like healthcare or banking, where data storage and processing controls are non-negotiable.
In practice, data sovereignty must be embedded early into a cloud infrastructure strategy. That means identifying which workloads carry regulatory or operational risk, and selecting managed hosting services that provide the necessary transparency, control and legal certainty.
This is where having a trusted hosting partner becomes critical. Businesses need providers who understand the nuances of data sovereignty and the wider cloud compliance landscape and can translate those requirements into infrastructure decisions that support both regulation and day-to-day operational performance.
Unlike hyperscalers, who are compelled under US law to give up customer data when requested, or whose data routing can be difficult to trace, a local regional managed hosting service offers the transparency and legal certainty that regulated industries require.”
Karl Mendez, Managing Director of CWCS Group

“GDPR changed the compliance conversation, but in cloud communications the pressure point is now much more specific: businesses want to know exactly where their voice traffic is processed, where call recordings are stored, and critically, who is handling their data and from where.
At Stripe21, we’re a UK-based VoIP and SIP trunking provider, and that matters more than it used to. Our support team is based in the UK, our infrastructure is UK-hosted, and when a customer asks where their data sits, we can answer that clearly and contractually. That’s becoming a genuine differentiator as businesses tighten their procurement criteria around data residency.
Under UK GDPR, businesses are the data controller for their communications, call recordings, messaging metadata, collaboration traffic. The choice of provider directly affects their compliance position, and vague answers about multi-region cloud infrastructure no longer cut it.
Post-Brexit, UK GDPR runs parallel to EU GDPR, and organisations with cross-border operations need providers who understand both. But for UK-focused businesses, the priority is increasingly straightforward: UK data, UK infrastructure, UK support. Sovereignty isn’t just a legal requirement anymore, it’s a buying decision.”
Jad Jebara, CEO of Hyperview DCIM

“Regulation doesn’t just change compliance strategies; it changes infrastructure itself. Data sovereignty legislation is now one of the most significant forces reshaping how organisations design and manage their data centre estates, and the EU’s forthcoming Cloud and AI Development Act will push that further still.
The pressure is pushing businesses away from simple, centralised cloud deployments towards hybrid and multi-region architectures with hard physical data boundaries. The infrastructure problem is becoming more complex. More sites, more interdependencies, more jurisdictions to satisfy simultaneously.
The answer to that complexity is real-time visibility and transparency across your entire
estate. You cannot manage what you cannot see, and you certainly cannot prove it to a regulator or a customer if you can’t see it either.
That’s the shift I think many organisations haven’t fully grasped yet. Auditability is no longer just a compliance obligation. It’s becoming a commercial differentiator. Enterprises are choosing infrastructure partners based on their ability to demonstrate physical data control with evidence, not just contractual promises. The ones who can show exactly where data lives, in real time, are winning deals. The ones who can’t are losing them regardless of price.
Sovereignty laws have made transparency not just a compliance issue but a commercial advantage.”
Jonathan Wright, Partner at Hunton Andrews Kurth

“GDPR and growing data sovereignty concerns are increasingly shaping how organisations approach cloud communications, particularly where sensitive or regulated data is involved. Attention is now focused on practical issues such as where data is stored, how it is transferred across borders, which jurisdictions may have access to it, and whether cloud providers can demonstrate compliance with evolving privacy and security requirements.
In response, organisations are applying greater scrutiny to cloud vendors, with more robust due diligence, tighter contractual safeguards, and stronger security expectations across service arrangements. In some cases, this is also influencing decisions around regional hosting models and data localisation.
As frameworks such as GDPR continue to evolve alongside wider regulation such as NIS2 and DORA, cloud solutions are increasingly assessed not just on cost and functionality, but on their ability to meet regulatory and governance requirements.”
Nilesh Chavda, Digital Strategy Lead at VIP Apps Consulting

“Lending and leasing businesses are under growing pressure to reassess their cloud
communication platforms as GDPR enforcement reaches record levels and DORA extends its reach across financial services technology suppliers. Cumulative GDPR fines have reached €7.1 billion as of January 2026, with European sovereign cloud spending projected to grow 83% this year.
For lending and leasing businesses, where data is stored, which legal jurisdiction governs it,
and whether a provider can demonstrate regulatory compliance are now procurement
requirements. We are seeing businesses in this sector actively reviewing cloud vendor
relationships as a result.
The businesses managing this effectively have built data governance into their technology procurement process from the outset rather than addressing it after a contract has been signed.”
Ken Barth, CEO of Catalogic Software

“GDPR turned data sovereignty from a best practice into a legal obligation. Since 2018, organisations handling European communications data have faced a concrete compliance question: where does this data actually live, and who can access it?
The answer is reshaping how businesses select and configure cloud communications infrastructure. Procurement decisions that once centred on price and features now include jurisdiction. Which legal framework governs my provider’s servers? Can the provider guarantee that call records, messages, and metadata stay within a defined geographic boundary? These questions now sit at the centre of cloud communications strategy.
The practical shift is visible in architecture decisions. Some organisations are moving toward hybrid cloud models, keeping sensitive communications data on private infrastructure while using public cloud for less regulated workloads. Others are going further, deploying their own cloud environments to retain full control over where data is stored and who can access it. Both approaches reflect the same underlying pressure: public cloud convenience is harder to justify when jurisdictional ambiguity carries regulatory risk.
Enforcement activity is increasing and providers who cannot answer data residency questions with contractual specifics are losing enterprise business to those who can.”




