Retarus study: Email sovereignty often barely more than an aspiration

Fewer than half of EU-based companies able to take decisive action should a serious emergency arise

July 28, 2026 //

Eighty percent of European companies believe they generally have their email communications under control. Yet at the same time, about half of them report being dependent on providers based outside the EU. These findings were revealed in a recent Retarus study carried out in collaboration with Researchscape in Germany, France, and Spain. What's more, 56 percent of the respondents fear their data may thus be subject to extraterritorial laws, such as the U.S. CLOUD Act.

Maintaining control over the company‘s email communication involves far more than simply relying on stable systems and smooth processes. It also encompasses the capacity to manage processes independently, assess legal risks, and retain the ability to act independently of third parties should an emergency situation arise. However, the recent study reveals that only 61 percent of the companies surveyed are able to implement their policies independently, and a mere 49 percent are capable of managing or migrating email accounts without relying on their service provider.

Sovereignty primarily still only an aspiration

While 89 percent of the companies surveyed consider sovereignty a strategic priority, an impressive 94 percent also identify it as a decisive factor in selecting a service provider. The study, nevertheless, exposes a widespread misconception: Many companies mistakenly equate hosting data in Europe with ensuring data protection and greater control. However, the location of the data is not the only critical factor. Equally significant are the legal framework the vendor is subject to and, consequently, who has the right to demand access to data and under which conditions. Although 77 percent of the organizations surveyed report that they have certified, verifiable contractual guarantees regarding storage location and access, 22 percent of respondents admit that these guarantees are only partially effective.

Regulatory pressure makes verifiability non-negotiable

The introduction of regulations such as NIS2 and DORA has fundamentally raised the bar for compliance. Companies are required to demonstrate the effectiveness of their security measures, document processes in full, and promptly provide evidence in the event of an audit. Given this context, 92 percent of those surveyed now consider comprehensive, transparent reporting to be essential, while 88 percent express a desire to be able to actively manage their email traffic through their own policies. The reality is that only 41 percent of companies are in a position to respond to an audit request at short notice. In the majority of cases, extensive preparation is required. Processes have to be reconstructed and information needs to be compiled. In addition, 52 percent of companies report that they have to either access their data or prepare it for audit purposes three to five times per year.

Local support essential in energencies

The study also confirms that support is no longer considered a minor service component, with 84 percent of the companies surveyed indicating that local support is essential or very important, and 83 percent expecting their service provider to be accessible and responsive. Local support takes on even greater importance in the context of sovereignty – sensitive data and metadata remains within the EU, and external staff are not granted access to critical information. Quick response times are also essential. In the event of a disruption, prompt communication with a qualified contact person plays a crucial role in determining whether an incident can be contained or starts to escalate. Nearly 46 percent of the companies surveyed stated that insufficient local support would be a decisive factor in switching providers.

“Nowadays, system architectures are significantly more complex than just a few years ago. This gives rise to risks and dependencies with implications many companies have not yet fully recognized. But what escapes your notice is also beyond your control when an emergency arises. That’s why companies are well-advised to design email infrastructures that allow them to act independently, remain operational, and respond autonomously at all times – regardless of their provider,” says Martin Hager, CEO and founder of Retarus. “Companies urgently need to critically review their dependencies and carefully examine whether transparency, control, and verifiability are objectively guaranteed in practice, and not just on paper.”

However, the growing awareness of issues related to sovereignty, control, and compliance is still far too seldom coverted into tangible measures in everyday business practice. As long as the basic prerequisites for genuine autonomy are not completely pervasive within companies, organizational behavior and security levels are hardly likely to change. Companies with real aspirations to achieve long-term legal certainty and operational independence would be well advised to turn to European providers that combine local data processing and management with proven, verifiable compliance standards.

To access the full study report, “Retarus Enterprise Email Report 2026 – Sovereignty”, please click here.

Find out how resilient your email is here with our self-assessment test: “Benchmark: How Sovereign Is Your Email?”

Methodology:
The findings are based on an online survey conducted by the international market research firm Researchscape International involving 149 respondents, conducted between February 14th  and March 2nd, 2026. The respondents were based in France, Germany, and Spain.  Only individuals working at companies in NIS2-relevant industries which had already achieved or were working toward NIS2 compliance were eligible to participate. In addition, respondents had to hold a management position in their respective IT departments.