In many firms the in-house server room still counts as the safest option. On closer inspection that picture rarely holds: security updates are delayed, backups are seldom tested, and remote access by service providers goes unnoticed. A single support session from a third country may already qualify as a data transfer under privacy law, regardless of where the data is stored.
Conversely, a European data centre alone is not sovereignty. What matters is whether operations, key management and support are legally and organisationally independent, and whether changing provider remains a plannable exercise at all.
For mid-sized firms we recommend three sober steps: fix location and access model contractually, provide for encryption with your own keys, and set down an exit strategy in writing. That turns a gut feeling into a verifiable decision.