Why data centre location won’t save wealth managers’ sovereignty

Why data centre location won't save wealth managers' sovereignty

Digital sovereignty in wealth management is not decided by where a data centre sits, but by who retains control over data, technology and advisory logic, according to a new white paper on digital sovereignty in the financial sector.

Fincite CEO and co-founder Friedhelm A. Schmitt explains what this shift means for banks and wealth managers.

The KPMG (2026) study frames digital sovereignty not as autarky, but as the ability to self-determine and manage digital value and supply chains despite existing dependencies. It describes the concept as a leadership and architectural principle rather than a market-ready product, meaning a “sovereign” label on a cloud service does not automatically create sovereignty.

The research identifies four dimensions: infrastructure and operational sovereignty, technological sovereignty, data sovereignty and governance sovereignty, with cybersecurity acting as a cross-cutting function throughout. Fincite notes that losing control in any one dimension can create systemic dependencies that become an existential threat under regulatory or geopolitical pressure. The study’s core message is that sovereignty cannot be bought, only built.

Fincite highlights why a data centre’s location is not proof of legal sovereignty. Extraterritorial laws such as the US CLOUD Act and FISA §702 can enable government access to data physically held within the EU, particularly where a US nexus or US routing exists.

Data residency only answers where data sits, not who can be compelled to hand it over. The study contrasts two approaches that look similar on paper: “Compliance First”, where data is EU-hosted with provider-managed keys, and “Competence First”, where the institution holds its own cryptographic keys via tools such as Confidential Computing and Hold Your Own Key.

Fincite stresses that whoever holds the keys controls access, meaning an institution can be fully EU-hosted and contractually sound while still lacking real control over its data.

Schmitt goes further than the study itself, pointing to governance sovereignty, the fourth dimension, as the question of who decides which data feeds into a decision and who can verify a recommendation remains comprehensible.

In wealth management, Fincite argues this is an advisory responsibility issue, not merely an IT one. The real black box, in Schmitt’s view, is the logic converting client data into investment recommendations, particularly where that logic sits within fragmented, proprietary systems controlled by a single provider.

Fincite argues this points toward modular, interchangeable architecture over monolithic platforms, with open standards and interfaces replacing black-box solutions. DORA’s Article 28 reinforces this, requiring tested exit strategies for critical ICT services, not just contractual exit clauses, a bar Fincite says institutions with non-portable advisory logic cannot clear.

Fincite develops fincite • cios, a modular, API-first WealthTech platform compatible with existing core banking systems, allowing components like onboarding, portfolio construction and reporting to be swapped independently.

For more, read the full story here.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.