Your Data. Your Rules. Your Law.

European Data Storage. Managed by European Law

Storing data in Europe is no longer just a best practice. It is a legal obligation, a competitive advantage, and — when approached correctly — a source of operational confidence rather than anxiety. Sanbrick was built precisely for this environment.

The regulatory landscape

European data law is not what it was five years ago

Three frameworks now shape how organisations must think about storage infrastructure — and none of them are optional.

GDPR

In force since 2018

General Data Protection Regulation

GDPR establishes clear obligations around how personal data is stored, accessed, and protected. For storage infrastructure specifically, it requires:

Technical security measures

Article 32 — encryption, access control, integrity verification.

Data residency clarity

Demonstrate where personal data is held and under which jurisdiction.

Audit trail capability

Access logs and processing records, available and exportable for authorities.

The right to erasure

Personal data must be technically deletable — traceably and verifiably.

GDPR fines reach up to 4% of global annual turnover — and enforcement has accelerated year on year since 2020.

NIS2

In force October 2024

Network & Information Security Directive

NIS2 replaces the original directive with far broader scope — extending cybersecurity obligations to many mid-sized companies previously unaffected.

Risk management measures

Technical controls proportionate to risk, including storage security.

Business continuity & backup

Documented recovery is now a regulatory requirement, not just practice.

Incident reporting

Significant incidents reported to national authorities within 24–72 hours.

Supply chain accountability

Obligations extend to technology suppliers and service providers.

If your organisation falls within NIS2 scope — and many do — your storage architecture is now a compliance matter.

CLOUD Act

US law since 2018

The risk European businesses rarely discuss

The US CLOUD Act grants US authorities the ability to compel US-based cloud providers to disclose data on their servers — regardless of where those servers are physically located, and regardless of GDPR.

EU data centre ≠ EU jurisdiction

A US provider hosting in Europe may still be subject to US legal orders.

A documented legal conflict

Between US and EU jurisdiction — one no contractual clause has resolved.

A board-level risk

For sensitive commercial, legal, or personal data.

Entirely eliminable

By storing data on European infrastructure, under European law exclusively.

This is not a hypothetical scenario. It is a documented jurisdictional conflict — eliminated entirely by European infrastructure.

The same software. Hardware you can trust.

Five data storage questions every CEO must be able to answer

These are not IT questions. They are governance, compliance, and business-continuity questions that land — ultimately — on the CEO’s desk.

1.

Do you know, precisely, where your data is?

Most organisations cannot answer this with certainty once cloud providers, sub-processors and regional failover are involved.

With Sanbrick — Your data resides on infrastructure you own or directly control, in a location you define. No ambiguity.
2.

Can you prove compliance in an audit?

GDPR and NIS2 audits are not theoretical. Authorities request access logs, processing records, and evidence of technical controls — on demand, in exportable format.

With Sanbrick — SanbrickOS maintains full audit trails of all data access events, exportable for regulatory reporting. Built into the platform, not retrofitted.
3.

Who has access to your data — and do you control it?

"We set it up correctly at the start" is not an acceptable answer when user roles, contractors, and systems change continuously.

With Sanbrick — Granular, role-based access control managed through SanbrickOS. Permissions are auditable, adjustable, and logged at every change.
4.

If something goes wrong, how quickly do you recover?

The industry average for full data recovery following a ransomware incident is 49 days. For most organisations, that is not a recovery scenario — it is a business-ending one.

With Sanbrick — Same-day recovery capability, immutable backups ransomware cannot encrypt, and high-availability configurations that eliminate single points of failure.
5.

Do you know what your storage will cost in year three?

Cloud storage costs grow with your data — and not linearly. Modest cloud bills frequently become three to five times higher within a few years, with no practical exit route.

With Sanbrick — Predictable cost model. Organisations using SanbrickOS report savings of up to 244% over five years versus equivalent cloud storage. Model year five in year one.

The answer starts with architecture

Sovereignty is not a setting. It is an architectural decision.

One made before any purchase — and one that determines everything that follows. Two principles underpin a genuinely sovereign data infrastructure.

Ownership Over Access

Renting infrastructure from a foreign provider is not sovereignty, however the marketing describes it. Owning or directly controlling the physical and legal chain of custody of your data is.

Jurisdiction Over Geography

A server physically located in Europe, operated by a company subject to non-European law, does not remove jurisdictional risk. What matters is which law actually governs the provider.

These two principles are the foundation on which SanbrickOS was built.

From regulation to practice

What Sanbrick covers

Regulatory requirementWhat it demandsHow Sanbrick addresses it
GDPR Art. 32 — Technical security Encryption, access control, integrity assurance AES-256 encryption at rest, role-based access control, integrity verification built into SanbrickOS
GDPR — Right to erasure Verifiable, traceable deletion of personal data Granular data management with documented, auditable deletion processes
GDPR — Audit readiness Access logs and processing records for authorities Full audit trail of all access events, exportable on demand
NIS2 — Risk management Technical controls proportionate to risk Configurable security policies, network segmentation support, access hardening
NIS2 — Business continuity Documented backup and recovery capability Immutable backups, same-day recovery, high-availability configurations
NIS2 — Incident response Detect, contain, and report incidents promptly Real-time monitoring, alert management, incident documentation support
Data residency Data held within EU jurisdiction Infrastructure on European soil, operated by a Portuguese company under EU law exclusively
CLOUD Act exposure Data outside reach of non-European legal orders No dependency on US-based providers or their infrastructure at any layer

GDPR Art. 32 — Technical security

What it demands
Encryption, access control, integrity assurance
How Sanbrick addresses it
AES-256 encryption at rest, role-based access control, integrity verification built into SanbrickOS

GDPR — Right to erasure

What it demands
Verifiable, traceable deletion of personal data
How Sanbrick addresses it
Granular data management with documented, auditable deletion processes

GDPR — Audit readiness

What it demands
Access logs and processing records for authorities
How Sanbrick addresses it
Full audit trail of all access events, exportable on demand

NIS2 — Risk management

What it demands
Technical controls proportionate to risk
How Sanbrick addresses it
Configurable security policies, network segmentation support, access hardening

NIS2 — Business continuity

What it demands
Documented backup and recovery capability
How Sanbrick addresses it
Immutable backups, same-day recovery, high-availability configurations

NIS2 — Incident response

What it demands
Detect, contain, and report incidents promptly
How Sanbrick addresses it
Real-time monitoring, alert management, incident documentation support

Data residency

What it demands
Data held within EU jurisdiction
How Sanbrick addresses it
Infrastructure on European soil, operated by a Portuguese company under EU law exclusively

CLOUD Act exposure

What it demands
Data outside reach of non-European legal orders
How Sanbrick addresses it
No dependency on US-based providers or their infrastructure at any layer

The right hardware

Data sovereignty begins with software. It is completed by hardware

Sanbrick appliances are purpose-built to run SanbrickOS — pre-configured and validated for European compliance environments. Three series cover the full range of organisational requirements.

Neutron Series

Small business & SOHO

SanbrickOS in a compact format for edge deployments, branch offices and local data environments. The right architecture when simplicity, proximity to operations and direct support matter more than scale.

Pulsar Series

Mid-market

1U performance for workloads where rack footprint, speed and simplicity all count. Supports 2.5″ SATA, SAS and NVMe — the natural fit for fast file and block services without the complexity of larger chassis.

Magnetar Series

Enterprise & critical infrastructure

The primary Sanbrick appliance for enterprise workloads — available in three configurations, each optimised for a distinct storage profile: core capacity, high density, or all-flash performance.

Prefer to run SanbrickOS on your own hardware? That is equally supported.

Frequently asked questions

Questions, answered

No. If the provider operating that data centre is a US company (or a subsidiary of one), US authorities can still compel disclosure regardless of where the servers physically sit. Jurisdiction follows the provider, not the building.

No. Sanbrick is a Portuguese company operating exclusively under European law, with no US corporate ownership or US-based infrastructure dependency.

NIS2 scope is broader than the original directive and now includes many mid-sized companies in sectors like healthcare, education, energy and digital infrastructure. If in doubt, a compliance review can confirm your status.

By declaration means a policy document asserts compliance. By architecture means the technical controls — encryption, access logs, deletion — are enforced by the platform itself, independent of whether anyone remembers to follow the policy.

Most migrations use SanbrickOS replication to seed data in the background, with a short cutover window. Timelines vary by data volume, but a phased migration plan is standard practice.

Book a compliance review with a Sanbrick engineer — no obligation. We map your current exposure against GDPR, NIS2 and CLOUD Act risk and recommend next steps.

Your Data. Your Rules. Your Law.

Sanbrick — European Data Storage & Backup Software Solutions. Portuguese engineering. European standards. Local support.