Your Data. Your Rules. Your Law.
European Data Storage. Managed by European Law
Storing data in Europe is no longer just a best practice. It is a legal obligation, a competitive advantage, and — when approached correctly — a source of operational confidence rather than anxiety. Sanbrick was built precisely for this environment.
The regulatory landscape
European data law is not what it was five years ago
Three frameworks now shape how organisations must think about storage infrastructure — and none of them are optional.
GDPR
In force since 2018
General Data Protection Regulation
GDPR establishes clear obligations around how personal data is stored, accessed, and protected. For storage infrastructure specifically, it requires:
Technical security measures
Article 32 — encryption, access control, integrity verification.
Data residency clarity
Demonstrate where personal data is held and under which jurisdiction.
Audit trail capability
Access logs and processing records, available and exportable for authorities.
The right to erasure
Personal data must be technically deletable — traceably and verifiably.
GDPR fines reach up to 4% of global annual turnover — and enforcement has accelerated year on year since 2020.
NIS2
In force October 2024
Network & Information Security Directive
NIS2 replaces the original directive with far broader scope — extending cybersecurity obligations to many mid-sized companies previously unaffected.
Risk management measures
Technical controls proportionate to risk, including storage security.
Business continuity & backup
Documented recovery is now a regulatory requirement, not just practice.
Incident reporting
Significant incidents reported to national authorities within 24–72 hours.
Supply chain accountability
Obligations extend to technology suppliers and service providers.
If your organisation falls within NIS2 scope — and many do — your storage architecture is now a compliance matter.
CLOUD Act
US law since 2018
The risk European businesses rarely discuss
The US CLOUD Act grants US authorities the ability to compel US-based cloud providers to disclose data on their servers — regardless of where those servers are physically located, and regardless of GDPR.
EU data centre ≠ EU jurisdiction
A US provider hosting in Europe may still be subject to US legal orders.
A documented legal conflict
Between US and EU jurisdiction — one no contractual clause has resolved.
A board-level risk
For sensitive commercial, legal, or personal data.
Entirely eliminable
By storing data on European infrastructure, under European law exclusively.
This is not a hypothetical scenario. It is a documented jurisdictional conflict — eliminated entirely by European infrastructure.
The same software. Hardware you can trust.
Five data storage questions every CEO must be able to answer
These are not IT questions. They are governance, compliance, and business-continuity questions that land — ultimately — on the CEO’s desk.
Do you know, precisely, where your data is?
Most organisations cannot answer this with certainty once cloud providers, sub-processors and regional failover are involved.


Can you prove compliance in an audit?
GDPR and NIS2 audits are not theoretical. Authorities request access logs, processing records, and evidence of technical controls — on demand, in exportable format.
Who has access to your data — and do you control it?
"We set it up correctly at the start" is not an acceptable answer when user roles, contractors, and systems change continuously.


If something goes wrong, how quickly do you recover?
The industry average for full data recovery following a ransomware incident is 49 days. For most organisations, that is not a recovery scenario — it is a business-ending one.
Do you know what your storage will cost in year three?
Cloud storage costs grow with your data — and not linearly. Modest cloud bills frequently become three to five times higher within a few years, with no practical exit route.

The answer starts with architecture
Sovereignty is not a setting. It is an architectural decision.
One made before any purchase — and one that determines everything that follows. Two principles underpin a genuinely sovereign data infrastructure.
Ownership Over Access
Renting infrastructure from a foreign provider is not sovereignty, however the marketing describes it. Owning or directly controlling the physical and legal chain of custody of your data is.
Jurisdiction Over Geography
A server physically located in Europe, operated by a company subject to non-European law, does not remove jurisdictional risk. What matters is which law actually governs the provider.
These two principles are the foundation on which SanbrickOS was built.
From regulation to practice
What Sanbrick covers
| Regulatory requirement | What it demands | How Sanbrick addresses it |
|---|---|---|
| GDPR Art. 32 — Technical security | Encryption, access control, integrity assurance | AES-256 encryption at rest, role-based access control, integrity verification built into SanbrickOS |
| GDPR — Right to erasure | Verifiable, traceable deletion of personal data | Granular data management with documented, auditable deletion processes |
| GDPR — Audit readiness | Access logs and processing records for authorities | Full audit trail of all access events, exportable on demand |
| NIS2 — Risk management | Technical controls proportionate to risk | Configurable security policies, network segmentation support, access hardening |
| NIS2 — Business continuity | Documented backup and recovery capability | Immutable backups, same-day recovery, high-availability configurations |
| NIS2 — Incident response | Detect, contain, and report incidents promptly | Real-time monitoring, alert management, incident documentation support |
| Data residency | Data held within EU jurisdiction | Infrastructure on European soil, operated by a Portuguese company under EU law exclusively |
| CLOUD Act exposure | Data outside reach of non-European legal orders | No dependency on US-based providers or their infrastructure at any layer |
GDPR Art. 32 — Technical security
- What it demands
- Encryption, access control, integrity assurance
- How Sanbrick addresses it
- AES-256 encryption at rest, role-based access control, integrity verification built into SanbrickOS
GDPR — Right to erasure
- What it demands
- Verifiable, traceable deletion of personal data
- How Sanbrick addresses it
- Granular data management with documented, auditable deletion processes
GDPR — Audit readiness
- What it demands
- Access logs and processing records for authorities
- How Sanbrick addresses it
- Full audit trail of all access events, exportable on demand
NIS2 — Risk management
- What it demands
- Technical controls proportionate to risk
- How Sanbrick addresses it
- Configurable security policies, network segmentation support, access hardening
NIS2 — Business continuity
- What it demands
- Documented backup and recovery capability
- How Sanbrick addresses it
- Immutable backups, same-day recovery, high-availability configurations
NIS2 — Incident response
- What it demands
- Detect, contain, and report incidents promptly
- How Sanbrick addresses it
- Real-time monitoring, alert management, incident documentation support
Data residency
- What it demands
- Data held within EU jurisdiction
- How Sanbrick addresses it
- Infrastructure on European soil, operated by a Portuguese company under EU law exclusively
CLOUD Act exposure
- What it demands
- Data outside reach of non-European legal orders
- How Sanbrick addresses it
- No dependency on US-based providers or their infrastructure at any layer
The right hardware
Data sovereignty begins with software. It is completed by hardware
Sanbrick appliances are purpose-built to run SanbrickOS — pre-configured and validated for European compliance environments. Three series cover the full range of organisational requirements.
Small business & SOHO
SanbrickOS in a compact format for edge deployments, branch offices and local data environments. The right architecture when simplicity, proximity to operations and direct support matter more than scale.
Mid-market
1U performance for workloads where rack footprint, speed and simplicity all count. Supports 2.5″ SATA, SAS and NVMe — the natural fit for fast file and block services without the complexity of larger chassis.
Enterprise & critical infrastructure
The primary Sanbrick appliance for enterprise workloads — available in three configurations, each optimised for a distinct storage profile: core capacity, high density, or all-flash performance.
Prefer to run SanbrickOS on your own hardware? That is equally supported.
Frequently asked questions
Questions, answered
No. If the provider operating that data centre is a US company (or a subsidiary of one), US authorities can still compel disclosure regardless of where the servers physically sit. Jurisdiction follows the provider, not the building.
No. Sanbrick is a Portuguese company operating exclusively under European law, with no US corporate ownership or US-based infrastructure dependency.
NIS2 scope is broader than the original directive and now includes many mid-sized companies in sectors like healthcare, education, energy and digital infrastructure. If in doubt, a compliance review can confirm your status.
By declaration means a policy document asserts compliance. By architecture means the technical controls — encryption, access logs, deletion — are enforced by the platform itself, independent of whether anyone remembers to follow the policy.
Most migrations use SanbrickOS replication to seed data in the background, with a short cutover window. Timelines vary by data volume, but a phased migration plan is standard practice.
Book a compliance review with a Sanbrick engineer — no obligation. We map your current exposure against GDPR, NIS2 and CLOUD Act risk and recommend next steps.

Your Data. Your Rules. Your Law.
Sanbrick — European Data Storage & Backup Software Solutions. Portuguese engineering. European standards. Local support.