Ask most wellness businesses where their client data lives and the answer comes back quickly: “It’s in the EU.” It sounds like a complete answer. It rarely is. In the era of GDPR and now NIS2, the more useful question is not where the data sits, but who can reach it — and those two things are not the same.
Residency is not sovereignty
Data residency describes the physical location of your records: a server in Frankfurt, a data centre in Dublin. Data sovereignty describes who has legal and practical authority over those records. You can have perfect residency — every byte inside the EU — and still not have sovereignty, because the company operating the infrastructure answers to a legal system on another continent.
This distinction matters most for a wellness practice precisely because of what you hold. Appointment histories, intake forms, notes on a client’s condition, payment details — this is intimate information people trusted you with. GDPR agrees it is sensitive: health data is a “special category” under Article 9, carrying a higher bar for lawful processing and protection. If you cannot say clearly who is able to access it, you have a gap in your duty of care, not just your paperwork.
The CLOUD Act reach
Here is the part that surprises people. The US CLOUD Act allows US authorities to compel a US-owned cloud provider to disclose data — even when the servers holding that data sit inside the EU. Ownership of the provider, not the location of the disk, is what determines reach. So “it’s hosted in Europe” can be true while your client records remain reachable by a foreign jurisdiction through the vendor who runs the machines.
The concentration makes this concrete. According to the European DIGITAL SME Alliance and n-ix, three US firms hold roughly 65% of the European cloud market. For a large share of European wellness businesses, the “EU cloud” they rely on is operated by a company subject to that extraterritorial reach. That is not a scandal; it is simply the structure of the market, and it is worth understanding before you promise a client their file never leaves your control.
What NIS2 changed
NIS2, the EU’s updated cybersecurity directive, reached full effect across the Union in 2026. It brings audits and a 24-hour incident-reporting obligation, fines up to EUR 10 million or 2% of turnover, and — the detail that tends to focus attention — the possibility of personal liability for management. Germany’s BSI issued an early fine of EUR 850,000 for weak incident detection, per reporting from Reed Smith and Freshfields. Whether your business is directly in scope or pulled in through a supply chain, the direction is unmistakable: regulators now expect you to know, and to be able to prove, who touches your data.
An honest caveat
None of this means the large US clouds are unsafe or that you must rip everything out tomorrow. They are engineering-heavy, resilient, and appropriate for a great many workloads. For some businesses the convenience and breadth genuinely outweigh the sovereignty question, and it would be dishonest to pretend otherwise. The point is narrower: you should make that trade deliberately, with eyes open, rather than discover the reach of a foreign statute after an incident. Sovereignty is a decision, and default arrangements quietly make it for you.
Closing the gap by holding your own stack
One way to make the answer simple is to remove the intermediary who can be compelled. A self-hosted platform keeps the client data, the customer relationship and the billing inside infrastructure you govern, in your own jurisdiction — not as a tenant on a system someone else operates. VBWD is built for exactly this: a full-stack, self-hosted SDK — one Python backend core serving a Vue/TypeScript web front end plus native iOS and Android SDKs — with a plugin architecture (booking, payments, memberships, catalogue, CMS, chat) that toggles features on and off without a restart. Because you run it, “who can see the data” has a short and truthful answer.
It is source-available under BSL 1.1, free for commercial use while annual VBWD-attributable sales stay below the value of 6.7 BTC a year, and the same modern architecture that helps with sovereignty also does the heavy lifting so a small studio can run the technology of a large multi-location group. It is younger than the twenty-year incumbents, and trades some accumulated edge-case maturity for auditability, speed and control — a good trade for many wellness businesses, not for all. For a fuller treatment of the regulatory backdrop, VBWD’s write-up on sovereign-by-default commerce for the NIS2 era is a useful companion.
If your practice is wrestling with any of this — the booking system that fights you, the client data you’re not sure you truly control, the fees that grow every year — the useful next step is concrete: see it running for your own business. Request an enterprise installation and bring the numbers you want to improve.
Sources: European DIGITAL SME Alliance and n-ix (cloud concentration, CLOUD Act reach); Reed Smith and Freshfields (NIS2, BSI fine); EU GDPR Article 9.



