Skip to main content
The Mediamatic Brief Call +356 9909 9007 WhatsApp

MediaMatic news

Who Really Controls Your Business Data?

TL;DR: “Digital sovereignty” sounds abstract until you see what’s actually happened when it played out for real. A US tech company suspending a foreign official’s account over sanctions isn’t hypothetical; it happened in 2025. This piece sets out the actual mechanism behind that risk, a real precedent, and the four concrete ways it can become your problem, not a government’s.

We’ve written about this from two angles already: the legal background in our guide to data sovereignty for Maltese SMEs and what it means for businesses that only trade locally in why small businesses in Malta and Gozo should take notice of Germany dropping Microsoft. This one answers the question of both of those left open: why is this actually a risk, and what does it look like when it goes wrong?

The Legal Mechanism, in One Paragraph

Most people assume that if their data sits on a server in Dublin or Frankfurt, EU law governs it – end of story. It doesn’t, not entirely. Under the US CLOUD Act, a US-headquartered company can be compelled by US authorities to hand over data it controls, wherever that data physically sits. The order is aimed at the company, not the building. So a server in the EU, owned and operated by a US company, doesn’t put your data outside US reach. That tension with GDPR is real and unresolved, and it’s the whole subject of our first guide on this if you want the detail.

The Precedent: What Actually Happened

This stopped being theoretical in 2025. After the Trump administration imposed sanctions on the International Criminal Court’s chief prosecutor, Karim Khan, over an executive order in February that year, reports from the Associated Press said Microsoft suspended his email account, forcing him to move to a different provider entirely. Microsoft’s president disputed that framing, saying the company never fully cut services. What isn’t disputed is that the ICC took the underlying risk seriously enough to start planning a move away from Microsoft altogether, towards OpenDesk, the open-source platform built under Germany’s digital sovereignty programme.

Whichever version of events you accept, the pattern is the same: access to your own tools and data can, in principle, be affected by a decision made by a foreign government about someone else entirely, for reasons that have nothing to do with you or your business. That’s the actual risk. Not that a provider is unreliable, but that the decision to cut you off, or not, doesn’t sit with you.

Four Ways This Actually Becomes Your Problem

Access is cut off through no fault of your own. As above. It’s rare, but it’s no longer hypothetical, and there’s no reliable way to know in advance whether your business, sector or country could end up on the wrong side of a future decision like it.

Compliance exposure you didn’t know you had. Under GDPR, you’re the data controller for your customers’ and staff’s personal data, even when it’s technically held by a cloud provider. If that provider is compelled to hand data over, the awkward question of whether there’s been a breach and whose responsibility it is can land on you as much as on them.

No leverage if terms or pricing change. The quieter, far more common version. If your booking system, till software and payroll all sit with foreign-owned providers, and one of them changes its pricing, drops a feature or gets acquired, you have very little room to push back if moving your data elsewhere isn’t straightforward.

A blocked tender or contract. More relevant if you supply into the public sector or larger EU-regulated organisations, but real: European procurement increasingly asks where data is processed and who controls it, and a supplier with no ready answer can lose out on that basis alone.

What This Isn’t

This isn’t a reason to panic, and it isn’t a reason to migrate off Microsoft or Google next week. For the overwhelming majority of small businesses in Malta and Gozo, nothing in this piece will ever actually happen to you directly. The realistic risk isn’t a dramatic data seizure. It’s the quieter version: not knowing your exposure, not being able to get your own data out if you needed to, and having no answer ready if a client, insurer or regulator ever asks the question.

Frequently Asked Questions

Has this actually affected a business, or is it still theoretical?
It’s happened at least once, to the International Criminal Court’s chief prosecutor in 2025, following US sanctions. Microsoft disputes exactly how far the disruption went, but the underlying exposure it revealed is not in dispute.

Could this happen to an ordinary Maltese business?
It’s unlikely, and there’s no evidence of it happening to a small business specifically. The point isn’t that it’s likely for you; it’s that the decision doesn’t sit with you, which is worth knowing even if the probability is low.

What’s the actual takeaway if I’m not planning to switch providers?
Know what you’re exposed to. That means knowing who owns your providers, whether you can export your own data, and what your contract actually promises, rather than assuming it’s covered.

Is this the same issue as GDPR compliance generally?
Related, not identical. GDPR is about lawful handling of personal data. This is about a specific legal mechanism, the CLOUD Act, that can put a US-owned provider’s obligations to US authorities in tension with your GDPR obligations as the data controller.

Where do I start if I want to understand my own exposure?
Our guide to data sovereignty for Maltese SMEs covers the practical checks, encryption key control, contract review, and knowing who legally owns your providers in more depth.

A Practical Takeaway

The businesses that handle this well aren’t the ones migrating everything out of caution. They’re the ones who know, in plain terms, what runs their business, who owns it, and whether they could get their own data back if they ever needed to. That’s a sensible standard for any business on the islands, not a corporate exercise.

If you’d like a straightforward, no-jargon look at your own exposure across the tools you actually use, get in touch and we’ll talk it through.

Your next step

Need a clearer digital plan?

Talk to MediaMatic about the right website, content or automation approach for your business.

Discuss your next step