Contents
white lines

A question during the annual review

The meeting had been scheduled for the annual review: sales performance, terms and conditions, new lines of finance. Then, just before the end, the client asked a question the adviser hadn’t anticipated: ‘You now process our payment data via the cloud. Where exactly is it stored? And who at your company has access to it?’

The adviser promises to look into it. Back at the office, the question triggers something that goes beyond the individual enquiry: the realisation that providing a precise answer is more difficult than one’s first instinct might suggest.

The rumour that is holding back many cloud decisions

In many organisations, there is a widespread assumption that DORA requires the exact physical server address of every data record to be specified at all times. This assumption is one reason why some organisations cling to their own data centres, even though migration would make economic sense.

This assumption exaggerates the actual requirement. DORA Article 30(2)(b) stipulates that contracts with third-party ICT service providers must specify the locations of data processing as regions or countries, not as server addresses.

Even this specification is less definitive in practice than it sounds. Within a selected EU zone, a request can be processed in any Member State, whilst only the stored data remains stationary.1 An institution can therefore formally and correctly specify ‘EU’ and still not know in advance in which Member State an individual request will actually be processed.

wellen

Digital sovereignty begins in the cloud

Increasing complexity, regulation and geopolitical dependencies
are posing challenges for banks. This white paper shows
how institutions are implementing sovereign, compliance-secure
and manageable cloud architectures.
Read now

Ownership is the wrong category

It is precisely here that many internal discussions confuse two concepts: ownership and control. Neither German nor European law recognises property rights in data in the same way as those applicable to a machine. What does exist are access rights, exploitation rights and powers of control, distributed amongst several parties simultaneously.2

From this realisation, five questions can be derived which allow one to honestly assess one’s own position.

Five questions that shed light on control

white lines

1. What data are we talking about – and whose data is it?

Raw data, processed data and derived data such as scores or model embeddings have different security levels. Equally important is the data subject. In the case of a bank, this is usually its own clientele; in the case of a debt collection agency, it is the debtor, who has never consented to the processing. Anyone who cannot answer this question will also be unable to answer the following four properly.

2. Who has access – and can the organisation identify them all without exception?

Access means: being able to read the data, both internally and externally, including the staff of a third-party service provider and its subcontractors.

3. Who is permitted to utilise the data?

Utilisation is the level at which data becomes a value driver, through analytics, through data fabric architectures, and through model training. This is precisely where conflicts arise that are rarely acknowledged. A feature developed for fraud detection is later proposed for credit decisions. A unified customer data set increases usability but obscures which consent individual details originally stemmed from.

A case from Brussels illustrates that technical availability and legal permissibility are two distinct issues: the European Data Protection Supervisor found that, when using Microsoft 365, the European Commission had not sufficiently specified which personal data might be processed and for what purposes.3 A technically unified platform therefore does not replace the obligation to justify each purpose individually.

4. Who controls the region, erasure and disclosure?

This level corresponds to the requirements of DORA Article 30, supplemented by the insight from the previous section: the contractually specified region is an assurance, not a physical guarantee for every single instance of processing.

5. Who can carry out audits – and will the institution get its data back in case of doubt?

Here, the supervisory authority itself provides the clearest figures. Major institutions have, on average, just over 100 critical external contracts, ranging from 2 to over 1,400.4 Around 82 per cent of critical external services are difficult or impossible to substitute, and around 95 per cent of these cannot be recovered at short notice in an emergency.4

A test run by the European supervisory authorities demonstrates just how demanding the required transparency actually is: Of the 947 registers assessed, covering a total of 3,447 financial firms, only 6.5 per cent passed all quality checks in full; the vast majority of errors found related to missing mandatory details such as identification codes or country information.5 A right of audit that is stipulated in a contract but not correctly recorded in a firm’s own register remains ineffective in practice.

Anyone who relinquishes control over their own data is giving up part of their own value creation.

Susanne KochwagnerDirector | Cloud Transformation | msg for banking

Control rather than self-sufficiency

These five questions are not a call for a complete withdrawal from the cloud. Claudia Plattner, President of the Federal Office for Information Security, has publicly stated that dependence on foreign cloud solutions and AI models cannot be eliminated in the short term, as the digitalisation of the economy and public administration is too deeply embedded in these providers.6 At the same time, economic studies warn of the macroeconomic costs of enforced self-sufficiency. 7 The real management task is not to avoid every dependency, but to recognise it, assess it and be able to manage it in an emergency.

Being able to answer all five questions does not guarantee digital sovereignty. However, failing to answer even one of them leaves a gap that will become apparent sooner or later: in a meeting with a client, at a supervisory board meeting or during the next BaFin audit.

The next step

These five questions highlight where responsibility for data lies today. They do not, however, reveal anything about the extent to which an organisation has become dependent on a particular technology. This is precisely the subject of the next article in this series: Cloud dependency as a choice, not a fate.

What this series of articles is about

This series of articles has been created to build decision-making capacity amongst CIOs and COOs, members of executive boards, supervisory boards and advisory boards, who are increasingly confronted with this topic without always having the tools to ask the right questions. It will not provide simple answers.

The series explores the various dimensions of digital sovereignty: from the issue of data sovereignty and technical dependencies to operational resilience and governance.

The aim is always the same: to be able to make informed and, therefore, well-founded decisions.

The next article delves into the first operational dimension: Who really owns a financial institution’s data, and which five key questions can help clarify this?

Sources
  1. 1. Microsoft Learn, Produktdokumentation Azure OpenAI Service, "Data Zones" (Stand 2025): Verarbeitung kann innerhalb der gewählten EU-Zone in jedem Mitgliedstaat erfolgen; nur gespeicherte Daten bleiben ortsfest.
  2. 2. Ryan, M.; Gürtler, P.; Bogucki, A. (2024): "Will the real data sovereign please stand up?", International Journal of Law and Information Technology 32.
  3. 3. Europäischer Datenschutzbeauftragter (EDPS), Entscheidung vom 8. März 2024 zum Einsatz von Microsoft 365 durch die Europäische Kommission.
  4. 4. Europäische Zentralbank, horizontale Analyse des Outsourcing-Registers bedeutender Institute, veröffentlicht Februar 2025, Referenzdatum 31. Dezember 2023.
  5. 5. EBA, EIOPA, ESMA: DORA-"Dry Run"-Bericht, Stichtag 17. Dezember 2024.
  6. 6. Claudia Plattner, Präsidentin des BSI, Interview vom 12. August 2025.
  7. 7. Bauer, M.; Erixon, F., ECIPE (10. Juni 2024); Mamchych, M. et al., Bruegel (25. März 2026) – beide als ökonomische Einordnung mit eigener Interessenlage zu lesen, nicht als neutrale Aufsichtsanalyse.
WORDPRESS_URL: https://admin.banking.vision/wp-json