To blog overview
Data Sovereignty
11 min read

CX leader's guide to EU data sovereignty.

Last updated 4 September 2026

Jordy van Gent
VP Revenue Marketing at Puzzel
The CX leader's guide to EU data sovereignty

Data sovereignty has moved out of legal and into the boardroom. Here's what contact centre leaders need to know.

TL;DR

Data sovereignty is becoming a key requirement when choosing a contact centre platform, especially for organisations handling sensitive customer data.

  • The US Cloud Act is the core issue. Data held by US-incorporated technology companies can be accessed by US authorities — regardless of where the servers physically sit, including data centres in the EU.

  • AI raises the stakes. Many AI vendors train models on user data unless explicitly configured otherwise, and some route AI inference through US infrastructure in real time.

  • Six questions separate trustworthy vendors from the rest: Covering jurisdiction, AI training, processing location, sub-processors, support access, and EU AI Act readiness. Ask for written answers.

  • Puzzel is incorporated in Norway, never uses customer data to train AI models, and operates a European-only support team.

Introduction: the question your next procurement will ask

Something shifted in European boardrooms over the past 18 months. Data sovereignty, once a concern confined to legal teams and compliance officers, has moved into the procurement conversation. CX leaders are now being asked by their own leadership and by the regulators overseeing their industries. This question would have seemed technical three years ago: where does our customer data live, and who can access it?

The answer matters more than it ever has. The US Cloud Act means that data held by US-based technology companies, regardless of where it is physically stored, can be accessed by US government authorities. The EU AI Act is rewriting the rules on how AI models can be trained and deployed. And in regulated industries like financial services, energy, and the public sector, data residency is shifting from best practice to procurement mandate.

For contact centre leaders, this creates a specific and urgent problem. Your contact centre platform touches almost every sensitive data point in your business: customer conversations, payment records, service interactions, and agent performance data. It is the highest-volume touchpoint you operate. If that platform routes data through US infrastructure, or uses your customer interactions to train third-party AI models, you carry a risk that procurement teams and boards are beginning to ask you to account for.

In this guide, you'll learn what data sovereignty means in practice for contact centres, why the US Cloud Act creates risk even for EU-hosted platforms, and six specific questions to put to any vendor in procurement. You'll also find a practical checklist for boards, procurement teams, and contract reviews.


What is data sovereignty, and why does it matter now?

The basics

Data sovereignty refers to the idea that data is subject to the laws of the country or region in which it is collected or stored. For European organisations, this means customer data handled within the EU is protected by GDPR and EU law, but only if that data stays within the EU's legal jurisdiction.

The complication arises when your technology vendor is incorporated in, or operates infrastructure through, the United States. This is because the US Cloud Act grants US law enforcement the ability to compel US-incorporated companies to hand over data held on their servers, regardless of where those servers are located. A contact centre platform built on US infrastructure, or owned by a US parent company, is therefore subject to US legal reach, even if the data centre is outside of the US (in Frankfurt, for example).

This is not a hypothetical risk. It is the reason European public sector organisations are explicitly restricting US-vendor procurement in some markets, and why financial regulators are beginning to scrutinise cloud supply chains with greater rigour.

The AI dimension

The second and more immediate concern for contact centre leaders is AI. Most major AI vendors, including the largest language model providers, train their models on user data unless explicitly configured otherwise. The default assumption for many platforms is that your customer conversations, your agent interactions, and your quality management data are all potential training material.

This is not theoretical. CX leaders in financial services and the public sector are already asking vendors in discovery conversations: Will our data be used to train your models? The honest answer from many US-based AI vendors is: not by default, but our model architecture means data may pass through US-controlled infrastructure at some point in the pipeline.

The EU AI Act adds a further layer. AI systems classified as high-risk, which include many customer service applications, must comply with transparency, data governance, and accuracy requirements that US-built AI products are only now beginning to address.

Which industries are most affected?

Financial services, public sector, and energy and utilities are currently the most exposed. Still, the direction of travel is towards all regulated industries treating data sovereignty as a standard procurement criterion.

  • Financial services: FCA Consumer Duty requires evidence-based outcomes for every customer interaction. Regulators are increasingly asking about data supply chains. UK and EU banking customers have explicit data residency expectations.

  • Energy and utilities: Ofgem and equivalent European regulators require auditability, complaint-handling records, and the protection of vulnerable customer data to a high standard. Infrastructure that routes through non-EU jurisdictions creates audit and compliance risk.

  • Public sector: Central and local government, NHS, housing associations, and charities handling public funding are operating under tightening restrictions on US-cloud procurement in several European markets.

  • Healthcare and insurance: Both carry special category personal data under GDPR. Any contact centre platform handling patient or policyholder conversations must meet the highest data protection standards.

What to look for (and what to ask your vendor)

Most technology vendors will tell you they take data seriously. The question is whether they can provide specific, verifiable answers to specific questions. The following framework gives you the right questions to ask and explains what a good answer looks like.

1. Where is data stored, and under whose legal jurisdiction?

Ask for the precise location of all data centres that will hold your organisation's data. Then ask: Is your company incorporated in, or subject to the jurisdiction of, the United States? A vendor can host data in Dublin but still be legally compelled to hand it over under the US Cloud Act if the parent company is US-incorporated.

What good looks like: a vendor whose parent company is incorporated in Europe, with data centres in the EU and/or EEA, and no contractual or technical dependencies on US-controlled infrastructure.

2. Will your AI use our data to train models?

Ask this directly and in writing. Many vendors have opaque data processing agreements that technically permit model training unless explicitly opted out. You want a clear contractual commitment that your customer interaction data will not be used for AI model training by the vendor or any third-party service they use.

What good looks like: a written Data Processing Agreement that explicitly prohibits use of your data for AI model training, with no carve-outs for anonymised or aggregated data.

3. What certifications do you hold, and what are you working towards?

ISO 27001 is the baseline for information security management. SOC 2 Type II demonstrates that security controls have been independently audited over time. EU AI Act readiness is increasingly important for AI-heavy platforms. Ask for current certifications and a roadmap for upcoming ones.

What good looks like: ISO 27001 certification, SOC 2 in progress or complete, GDPR compliance documentation, and a clear EU AI Act readiness position.

4. What does your follow-the-sun support model look like?

Some vendors provide 24/7 support by routing customer data to support teams in different geographies, including the US and Asia-Pacific. This means your data can be accessed by support engineers outside the EU in the course of a support ticket. Ask explicitly: Can you guarantee that no support or operations staff outside the EU/EEA will have access to our data?

What good looks like: a European-only support model, with no data access by non-EU staff, and contractual guarantees to that effect.

5. How are you preparing for the EU AI Act?

The EU AI Act came into force in 2024, and major provisions applied from 2025 onwards. Contact centre AI, including agent assist, quality management, and automated classification, may fall into high-risk categories. Ask vendors what they have done to prepare, and whether their AI systems are compliant with the Act's transparency, accuracy, and human oversight requirements.

What good looks like: a named EU AI Act compliance position, with documented controls for high-risk AI use cases and human oversight mechanisms built into the platform.

A vendor that cannot answer these questions specifically and in writing is not a vendor you can trust with your customers' data.

The case for a European-first platform

Choosing a European platform is not about nationalism or protectionism. It is a rational decision based on risk, accountability, and fit. Here is what a genuinely European-first architecture delivers that US vendors cannot.

Legal clarity

When your data is held by a European company, the legal framework governing it is clear: GDPR. There is no US Cloud Act overhang, no cross-border jurisdictional ambiguity, and no risk of a US court order compelling disclosure. For regulated industries, this is not a nice-to-have. It is a prerequisite.

AI that respects your data

European AI companies are building under the constraints of the EU AI Act from the ground up, not retrofitting compliance onto systems designed without it. This means stricter data governance, clearer model documentation, and explicit prohibitions on using your customer data for model training. For a contact centre leader deploying AI at scale, this is the difference between a vendor you can trust and one you have to audit continuously.

No follow-the-sun data exposure

A European vendor with European operations does not need to route your support tickets through a team in the US at 02:00 UTC. Your data stays in the hands of people operating under the same legal framework as you. For financial services and public sector organisations, especially, this matters.

Alignment with where regulation is going

The EU's direction of travel is clear: tighter data sovereignty requirements, stricter AI governance, and higher penalties for non-compliance. A platform built for European trust today will be easier to operate compliantly in three years. A platform built to US standards, retrofitted for GDPR, will require constant compliance work as the regulation evolves.

How Puzzel approaches data sovereignty

Puzzel is a European company, built in Norway, operating across the UK, Nordics, and Benelux. Our infrastructure and our approach to data have been shaped by European values and European regulation from day one. Not as a response to compliance pressure, but as a structural characteristic of how we build.

Where your data lives

  • Private cloud data centre, Oslo. Our core infrastructure is hosted in our own private cloud data centre in Oslo, not on shared hyperscaler infrastructure. This gives us direct control over physical security, access, and data routing.

  • UK and European Azure options. For organisations requiring UK or EU-hosted cloud infrastructure, we offer dedicated Azure deployment within those regions. 

AI built for European trust

  • Your data does not train our models. Puzzel's AI systems, including Co-Pilot, Conversational Intelligence, Virtual Agent Suite, and Quality Management, do not use your customer interaction data for AI model training. This is a contractual commitment, not just a policy.

  • EU AI Act readiness. Puzzel is actively preparing for EU AI Act compliance across all AI products. Our AI systems are designed with human oversight, transparency, and explainability as core requirements, not as additions to meet a regulatory deadline.

Security credentials

  • ISO 27001 certification

  • SOC 2 Type II 

  • GDPR-native architecture

  • European-only support and operations team

  • Regular penetration testing and security audits

More details can be found in our Trust Centre


European by design, not by default

Our Nordic heritage shapes the way we think about trust: practically, transparently, and without drama. We do not lead with "European" as a marketing claim. We lead with product quality, agent outcomes, and customer results. Data sovereignty is the structural proof point that sits behind all of it.

"Your customers' data stays where your business operates. Puzzel is built, hosted, and supported in Europe, so you never have to choose between capability and compliance."

What to do next: a practical checklist

Whether you are in an active procurement, reviewing an existing contract, or preparing for a board conversation on data governance, the following steps will help you move from awareness to action.

If you are in procurement

  • Add data sovereignty questions to your RFP or vendor questionnaire (see the six questions above for the full list)

  • Request written confirmation of data residency, model training policy, and support model geography

  • Ask for ISO 27001 and SOC 2 certificates, not just claims

  • Review the vendor's Data Processing Agreement specifically for AI data use clauses

  • Ask whether the vendor or any of its AI sub-processors are incorporated in the US

If you are reviewing an existing contract

  • Request a data flow diagram from your current vendor: where does your data go, and who touches it?

  • Ask whether your data has been used for AI model training, and get a written answer

  • Check your DPA for AI carve-outs, as many older agreements predate generative AI and do not cover it

  • Identify your renewal date and begin a structured evaluation at least 12 months in advance

If you are preparing a board conversation

  • Frame data sovereignty as a risk management conversation, not a technology one

  • Reference your industry's regulatory context: FCA Consumer Duty, Ofgem, GDPR, and the direction of travel

  • Quantify the exposure: how many customer interactions does your platform handle? What data does it hold?

  • Present the sovereignty question as part of your AI strategy, not a separate compliance discussion

Conclusion

Data sovereignty is no longer a niche compliance requirement. It is becoming a standard procurement criterion, a boardroom risk question, and a genuine competitive differentiator for organisations that get it right.

For CX leaders, the contact centre platform is the highest-stakes data decision you will make. It handles the most volume, touches the most sensitive interactions, and increasingly runs the AI that shapes your customers' experience. Getting this decision right requires more than a vendor that ticks a GDPR checkbox. It requires a platform built for European trust, with European infrastructure, European legal accountability, and AI developed under European constraints.

Puzzel exists to make that choice straightforward. If you would like to understand how our platform would work for your organisation, we would welcome the conversation.

 

 


Frequently asked questions about EU data sovereignty

Stay updated on the latest CX insights, events, and more