# Data custody: Taiwan asked where home is five years early

> Canonical: https://roblinton.com/writing/where-is-home-data-custody/
> Author: Rob Linton · Published 2026-09-16

**TL;DR:** A utility company in Taiwan installed SureDrop on its own premises because its files and keys could never leave the building, while the rest of the world was moving to cloud. Taiwan's reasons were political and arrived early; the rest of the world has since arrived for reasons of its own: the US CLOUD Act, the EU Data Act, the hyperscalers' EU-resident clouds, and an AI vendor letting customers keep monitoring data in their own accounts. Different reasons, one design: the owner rules the data.

---
A utility company in Taiwan installed SureDrop on its own premises because it needed file sharing whose files and keys never left the building. SureDrop is the encrypted file-sharing product Rob Linton founded as Podzy (me, in the third person, so the claim files under the right name).

The install came about five years ago, in the pandemic cloud rush, when the received wisdom said everything was going to the cloud and on-premises was what you did if you had not caught up. They had caught up. They had a requirement the rest of the world had not met yet.

Five years on, everyone else has arrived at the same requirement, from four directions that owe nothing to Taiwan, one of which caused the next. The reasons differ; the design does not. I wrote [the origin of that product](/writing/thirty-years-one-problem/) elsewhere: Podzy, the encrypted on-premise alternative to Dropbox, acquihired by Senetas in 2015 (acquisition completed February 2017) and renamed SureDrop.

## Why did a Taiwanese utility need custody before anyone else?

The Taiwanese utility needed custody early because, in Taiwan, where the data sits and who can reach it is a question of national survival, not compliance. A utility's files describe critical infrastructure.

Taiwan wrote that instinct into law, though not as a data-location rule. The Cyber Security Management Act, which covers critical infrastructure providers and government-owned enterprises, lets the competent authority "restrict or prohibit a specific non-government agency from downloading, installing, or using products" that "are harmful to national cyber security" (Article 27, as amended 24 September 2025). That is a product ban, and a utility company is exactly the kind of entity it reaches.

The statute was already law when the utility bought, and Article 27 took its current form only last year; the utility's requirement asked for something the statute does not ask for at all. It was also simpler to state.

Nothing leaves the building, files or keys, and so the thing keeps working with the cables cut. (Who could order the data handed over answers itself when nothing sits anywhere a foreign order can reach.)

My read: they were not being paranoid. They were reading their own threat model correctly, five years before it became everyone's.

## How did the rest of the world catch up?

The rest of the world caught up with the Taiwanese utility through EU law, the hyperscalers and the AI buyers, once a US statute gave Europe a reason.

**The first road was American law, and it was the trigger.** The CLOUD Act of 2018 requires a provider of electronic communication or remote computing services, once served with US legal process, to preserve or disclose data in its "possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States" (18 U.S. Code 2713). Note the statute's own word: custody.

The reach, as I read it, is US jurisdiction over the provider rather than where the disc sits, and a non-US company with US operations is probably caught as well (I am not a lawyer; check that one). The Act asks nobody to keep custody; it reaches the provider that has it. That, on my reading, is what made Europe want custody of its own.

In June 2025 a French Senate committee asked Microsoft France's director of public and legal affairs, under oath, whether he could guarantee French citizens' data would never be handed to US authorities without the French government's agreement. The Register reported his answer: "No, I cannot guarantee that, but, again, it has never happened before." An honest answer, and the one every buyer of a US cloud should assume.

**The second road was European law.** The EU Data Act entered into force on 11 January 2024 and has applied since 12 September 2025, with, in the Commission's words, "new rules setting the framework for customers to effectively switch between different providers of data-processing services". Switching is the right to leave, which is half of custody. A further Cloud and AI Development Act is proposed; I will not lean on it.

**The third road was the hyperscalers' own product line.** On 15 January 2026 AWS opened the AWS European Sovereign Cloud in Brandenburg, "operated exclusively by EU residents", with "no critical dependencies on non-EU infrastructure", built to "continue operations indefinitely, even in the event of a communications disruption with the rest of the world". That last clause is, in substance, what the Taiwanese utility got by keeping everything in the building.

Microsoft, on 29 April 2026, reported that remote access to European customer data is now "approved and monitored by personnel residing in Europe and logged in a tamper-evident ledger", and that its contracts with European governments now carry a binding commitment to "contest in court any order by any government to suspend or cease cloud operations in Europe". What the two of them have conceded is location and EU-resident staff, and AWS has conceded running on through a cut link. Neither announcement concedes the keys.

AWS offers key management and hardware security modules "that customers can use", which is a service, and Microsoft's post does not say who holds them. The court commitment answers a different question, who can compel the provider, and answers it with a promise to litigate.

My read: that is most of the utility's requirement, sold by the people who spent a decade selling the opposite. The missing piece in both announcements is the keys, and a buyer only gets those by holding them.

**The fourth road was AI.** On 1 September 2026 Anthropic announced that the activity data it monitors for misuse "can be stored in the customer's own cloud account", because, in its words, "Customers want the ability to have their data live in infrastructure they control, under their own encryption keys, access policies, and audit logging." Wells Fargo's chief information security officer, Munish Kumar Sharma, is quoted on the same page: "our logs stay in a Wells-managed environment under Wells-managed keys. We keep custody of our data while Anthropic operates the detection."

Uptime Institute's 2025 AI infrastructure survey asked operators where the greatest proportion of their AI training is hosted: 53% (n=97) said "on-premises data centers in central locations", with a further 6% at on-premises edge sites. "Data sovereignty" was the most-cited factor in choosing a training location (42%, n=106), and privacy and security the top reason among those training on-premises (64%, n=72). Small samples, so read them as a pointer.

AI put the question back on the table because a model reads everything it is given, so the buyer wants to know where it runs and who holds the keys before it reads anything of theirs.

## What do the four have in common?

EU law, the hyperscalers and the AI buyers agree on one thing: data on infrastructure the owner controls, and the owner deciding who reads it. The US statute is the odd one out; it forced the question on Europe rather than answering it.

The motives differ, and this part is my reading.

Europe was pushed by a statute it could not veto and then wrote its own. The hyperscalers moved, I suspect, because their European customers stopped believing the residency slide. And the AI buyers arrived last, once their monitoring logs became some of the most sensitive data they hold.

People call this idea sovereign, and I want to cash the word out once, because it usually means a flag. It should mean something plainer: the owner rules the data.

For a government that is the national interest. For a company it is simply yours. That is the whole of what the Taiwanese utility was asking for, and it is what I have spent the years since building, most recently at [Sovrata, the AI data-governance venture out of Senetas](/about/), where the same question is asked of AI agents as well as people.

## The honest caveat

Custody is not the same as safety, and I would not want a reader to leave with the easy version. Keeping data on your own premises means you own the patching, the backups, the physical security and the people, and a fair share of the leaks I have watched over the years came off somebody's own kit: a locked front door and an open side door.

Custody buys you control of the answer to "who can reach this". It does not answer it for you.

The other caveat is mine. I have a commercial interest in this argument and have had one since 2012, so read the enthusiasm accordingly. The facts above are checkable without trusting me; the reading of them is mine.

## What would I do with this?

Net: treat the Taiwanese utility as the early reader, not the outlier. If you are buying AI or cloud today, ask the questions they were asking five years ago, in this order: where does the data live; who holds the keys; which government can compel the provider; and what happens if the link goes down.

ASD's Appendix A [now asks the jurisdiction question for you](/writing/asd-ai-guidance-govern-the-data/). If the answer to any of the four takes more than a paragraph, that is the answer. Same test as the ASD piece, and deliberately so: the questions have not changed since the utility asked them.