53
(Mishra 2015). First, implementing a similar policy means increasing costs
due to the relocation of data centres and services in Europe, and subverting global economic trends. Moreover, digital sovereignty could not be a
panacea vis-à-vis the issue of security. As the Estonian project of creating a
virtual data embassy shows, centralising data may enhance the level of
vulnerability, while delocalisation, as the sharding procedure in the context of cloud computing services demonstrates, can actually strengthen
system resilience. Lastly, initiatives aiming to preserve digital sovereignty
are often criticised as ways to conceal a form of protectionism (Mishra
2015; Millard 2015; C. Kuner et al. 2015). Digital sovereignty would not
merely lead to a balkanisation of the digital realm for the sake of preserving European fundamental rights, but also to allow European companies
to fill the economic gap distancing them from American and Asiatic technology giants.
While Europe is seeking to strengthen its digital sovereignty, however,
analogous trends are emerging also elsewhere. In 2018, for example, the
US introduced the CLOUD Act, a new legislation enabling US law
enforcement authorities to require US corporations to disclose data, independently of their physical location (Abraha 2019). The statute was purposefully adopted as a response to a case in which Microsoft contested a
search warrant aiming to gather data stored on its Irish servers (Svantesson
and Gerry 2015). Microsoft lamented that, under the Electronic
Communications Privacy Act 1986, the US government was not explicitly
authorised to serve extraterritorial warrants. The introduction of the
CLOUD act in 2018 mooted the dispute against Microsoft, which had
meanwhile reached the US Supreme Court (Abraha 2019). The new statute empowers US law enforcement authorities to require data in the ‘possession, custody and control’ of a US corporation, notwithstanding such
information may be physically located outside the US (Abraha 2019).
Data localisation is not just a US and European phenomenon. In 2017,
in the context of the increasing trade war with the US, China passed a new
National Intelligence Law obliging companies to collaborate with Chinese
intelligence agencies (Yang 2019). This legislation produced strong criticism in the US (Lian 2019; The White House 2019; cf. Doffman 2019).
Yet it reveals a drift towards growing fragmentation of the digital space to
impose national sovereignty, which raises significant challenges for cloud
computing.
3 COMPETING JURISDICTIONS: DATA PRIVACY ACROSS THE BORDERS
(Mishra 2015). First, implementing a similar policy means increasing costs
due to the relocation of data centres and services in Europe, and subverting global economic trends. Moreover, digital sovereignty could not be a
panacea vis-à-vis the issue of security. As the Estonian project of creating a
virtual data embassy shows, centralising data may enhance the level of
vulnerability, while delocalisation, as the sharding procedure in the context of cloud computing services demonstrates, can actually strengthen
system resilience. Lastly, initiatives aiming to preserve digital sovereignty
are often criticised as ways to conceal a form of protectionism (Mishra
2015; Millard 2015; C. Kuner et al. 2015). Digital sovereignty would not
merely lead to a balkanisation of the digital realm for the sake of preserving European fundamental rights, but also to allow European companies
to fill the economic gap distancing them from American and Asiatic technology giants.
While Europe is seeking to strengthen its digital sovereignty, however,
analogous trends are emerging also elsewhere. In 2018, for example, the
US introduced the CLOUD Act, a new legislation enabling US law
enforcement authorities to require US corporations to disclose data, independently of their physical location (Abraha 2019). The statute was purposefully adopted as a response to a case in which Microsoft contested a
search warrant aiming to gather data stored on its Irish servers (Svantesson
and Gerry 2015). Microsoft lamented that, under the Electronic
Communications Privacy Act 1986, the US government was not explicitly
authorised to serve extraterritorial warrants. The introduction of the
CLOUD act in 2018 mooted the dispute against Microsoft, which had
meanwhile reached the US Supreme Court (Abraha 2019). The new statute empowers US law enforcement authorities to require data in the ‘possession, custody and control’ of a US corporation, notwithstanding such
information may be physically located outside the US (Abraha 2019).
Data localisation is not just a US and European phenomenon. In 2017,
in the context of the increasing trade war with the US, China passed a new
National Intelligence Law obliging companies to collaborate with Chinese
intelligence agencies (Yang 2019). This legislation produced strong criticism in the US (Lian 2019; The White House 2019; cf. Doffman 2019).
Yet it reveals a drift towards growing fragmentation of the digital space to
impose national sovereignty, which raises significant challenges for cloud
computing.
3 COMPETING JURISDICTIONS: DATA PRIVACY ACROSS THE BORDERS
