Operator Independence
The requirement that no foreign entity can be compelled to access or disclose data, which goes beyond where the bytes are stored to who controls the operator.
Residency asks where data sits. Sovereignty asks who could be compelled to hand it over, and the answer can differ from the answer to the first question. A data centre in one country operated by a company incorporated in another may be subject to that other country's legal process, which is what motivates several national and sector-specific requirements.
The controls that address it are stronger than region selection. Operational independence: administration performed by personnel within the jurisdiction, with foreign access technically prevented rather than contractually discouraged. Cryptographic separation: keys held by the customer or a local escrow, so the operator cannot decrypt regardless of compulsion — which is the only control that holds if the legal argument is lost. Legal structure: a locally incorporated entity with the contractual and technical position to refuse.
The implication for design is that customer-managed keys with an external key store stop being an optional feature and become the mechanism by which the requirement is met. And where a provider's own management plane can access data — as several managed services necessarily can — that path has to be assessed rather than assumed away.