Your maps know too much — why GIS belongs on European soil
Spatial data is some of the most sensitive data an organization holds, and the rules — and the world — around cloud hosting have changed. Here's why where your GIS lives matters, and how we've answered the question at OrbGIS.
Ask someone what their organization's most sensitive dataset is and they'll usually say the HR system or the customer register. Ask a GIS specialist and you get a different answer. Your maps know where the water mains run, where the power grid connects, which buildings house social services, where every school and pumping station and server room sits. A municipal GIS is, in practice, a detailed operating manual for a community — and utilities, planners and agencies hold the same kind of material for their own infrastructure.
That's the backdrop for a question more and more European organizations are asking their software vendors: where, exactly, does our data live — and whose laws apply to it?
What EU law actually says#
The legal side starts with the GDPR. Personal data may only leave the EU/EEA under specific safeguards, and the last decade has shown how fragile those safeguards can be. The Safe Harbor agreement was struck down by the EU Court of Justice in 2015. Its successor, Privacy Shield, fell in the Schrems II ruling in 2020. The current EU–US Data Privacy Framework is in place, but it rests on the same political foundations as its predecessors — and it is already being challenged. Building a decade-long platform decision on an arrangement with that track record is a risk many public organizations are no longer willing to take.
The deeper problem is that this isn't only about where servers stand. The US CLOUD Act allows American authorities to compel US-based providers to hand over data they control — regardless of which country it's stored in. A US hyperscaler's data center in Stockholm is still, legally, within reach of US law. That's the tension European regulators and courts keep circling: geography doesn't resolve jurisdiction.
Meanwhile the requirements on the European side keep tightening. The NIS2 directive raises the bar for security and incident handling across essential services and public administration — and makes organizations responsible for their supply chain, cloud vendors included. "We assumed our provider had it covered" is no longer an answer.
The geopolitical layer#
For years, data residency was treated as a compliance checkbox. The past few years have made it a strategic question. Trade disputes, sanctions and rapidly shifting alliances have reminded everyone that access to digital infrastructure can become leverage — and that a dependency which feels theoretical today can become very practical overnight. Across Europe, governments and public-sector bodies are re-evaluating how much of their critical tooling runs on infrastructure that answers to another jurisdiction. "Digital sovereignty" has moved from conference keynote to procurement requirement.
GIS sits unusually high on that risk list, precisely because of what the data describes. Losing access to your mapping platform in a crisis is bad; having detailed infrastructure data exposed to a foreign jurisdiction is worse.
And in Sweden specifically#
Swedish public organizations carry obligations of their own on top of the EU rules. The public access and secrecy legislation (offentlighets- och sekretesslagen) restricts how classified information may be handled when IT operations are outsourced, and the security protection act (säkerhetsskyddslagen) applies where data touches activities of importance to Sweden's security — which detailed infrastructure mapping can absolutely do. Public guidance bodies have spent years warning about exactly the cloud arrangements described above, and many municipalities have concluded that the safest reading is the simplest one: keep sensitive data with providers that answer only to Swedish and EU law.
This article is not legal advice — transfer rules and security legislation depend on your data and your situation. But the direction of travel is unmistakable.
How OrbGIS answers the question#
We didn't bolt sovereignty onto OrbGIS afterwards; the platform was built this way from day one.
- Everything runs in Sweden. The entire platform — application, databases, tile serving, file storage — runs on Swedish cloud infrastructure. Your data doesn't leave the country, full stop.
- A Swedish company under EU law. OrbGIS is 100% Swedish-owned. There is no foreign parent company for another jurisdiction's laws to reach through.
- No hyperscaler in the chain. Our stack has no dependency on US cloud providers — not for compute, not for storage, not for delivery.
- Even the AI features stay in Europe. The AI assistance in OrbGIS runs on Swedish, EU-hosted inference — not on API calls that route your content across the Atlantic.
- People you can actually ask. Compliance reviews come with questions. You'll get answers from the people who build and run the platform, not a ticket queue.
For our users this rarely makes headlines — it just means the procurement review goes smoothly and the security officer sleeps well. Which is exactly how it should be.
If your organization is rethinking where its spatial data should live, we'd be glad to talk. Or see for yourself how it works — try OrbGIS free.
Get new articles by email
One email when we publish something new — nothing else.