Data centers in orbit are a better idea than they sound
Adam Sonnet
The physics is more convincing than the pitch decks. The jurisdiction is where it gets hard — and that is a question European compliance teams should look at now, not in 2035.
The idea stopped being a joke sometime in late 2025
For years, "put the data center in space" was the kind of thing you heard at a conference and politely ignored. Then a sequence of fairly unglamorous, concrete things happened.
In November 2025, Google published Project Suncatcher — a research programme to run TPUs on solar-powered satellites flying in tight formation, with prototype hardware slated to fly with Planet around 2027. In the same month, a startup called Starcloud put an NVIDIA H100 into low Earth orbit and ran it. Small, but a real GPU in orbit rather than a render. Axiom Space has been flying data-processing nodes to the ISS. Jeff Bezos told an audience in Italy that he expects gigawatt-class orbital data centers within one to two decades. And the European Space Agency's ASCEND study, run by Thales Alenia Space, had already concluded in 2024 that orbital data centers could be technically feasible and lower-carbon than terrestrial ones for Europe — with a large asterisk about launcher emissions.
None of this makes it a good idea yet. It makes it an engineering argument rather than a fantasy, which is a different thing.
The physics that makes it plausible
Three constraints are currently strangling terrestrial data centers. All three loosen in orbit.
Power. In a dawn–dusk sun-synchronous orbit, a satellite sits in near-continuous sunlight. Google's published figure is that a solar panel there can be up to eight times more productive per year than the same panel at mid-latitudes on the ground: no night, no cloud, no seasons. And no interconnection queue. AI campuses in Ireland, the Netherlands and Northern Virginia are now waiting years for grid capacity that may not arrive. Orbit has no waiting list.
Cooling and water. A hyperscale site can consume millions of litres a year for cooling, increasingly in regions that are already arguing about water. In vacuum there is nothing to convect into — every watt has to leave as infrared through a radiator. That is a genuine engineering burden, because radiators are heavy and large. But it is a mass problem, not a watershed problem. No cooling towers, no aquifer, no municipality asking where the water went during a drought.
Land and neighbours. Data center planning permission has become politically contested across much of Europe. Orbit has no planning committee.
The arguments against are not small
An honest list, because this is where most enthusiasm should stop:
Launch cost. Google's own analysis puts the break-even around $200 per kilogram to orbit. Current commercial launch is an order of magnitude above that. The entire case rests on Starship-class economics actually materialising.
Radiation. Consumer AI accelerators are not radiation-hardened. Single-event upsets in a training run are a correctness problem, not just an availability problem.
Maintenance. You cannot swap a failed DIMM at 550 km. Reliability engineering becomes statistical: over-provision, let nodes die, never repair anything.
Bandwidth. Compute is the easy thing to launch. Getting petabytes back down through optical downlinks — weather-dependent, finite, ground-station-bound — is the constraint that decides which workloads make sense.
Debris. Collision risk and anti-satellite capability are now part of your threat model, and NIS2 asks about physical security of premises.
Which is why the serious proposals are not "move the cloud to space." They are narrower: batch AI training, and inference on data that was generated in orbit in the first place — Earth observation especially, where you would much rather downlink the answer than the imagery. That is a real workload with a real economic case.
The part nobody is costing: whose law applies at 550 kilometres?
This is where it gets interesting for anyone who has to sign a Record of Processing Activities.
There is an answer, and it is older than the internet. Article VIII of the 1967 Outer Space Treaty: the State on whose registry a space object is carried retains jurisdiction and control over that object. The 1975 Registration Convention determines which State that is. So an orbital data center is neither lawless nor neutral territory. Legally, it is an extension of its registry State. A satellite on the US registry is US-jurisdiction hardware, regardless of the fact that it passes over Jutland every ninety minutes.
Now put GDPR next to that. GDPR has never cared where the server is — Article 3 attaches to the establishment of the controller and to the targeting of people in the Union. That part is unchanged. Chapter V is the problem. If you uplink personal data to a satellite on the US registry, operated by a US company, subject to US lawful-access powers, you have made an international transfer. You need a transfer mechanism, a transfer impact assessment, and an honest answer about government access. That the hardware is in vacuum rather than in Virginia changes nothing about the legal analysis and a great deal about your ability to audit it.
No European regulator has published guidance on this. The EDPB has not addressed orbital processing at all. That is not reassuring — it means whoever goes first writes the precedent using their own risk appetite.
European "sovereign cloud" claims get strange quickly here. A constellation registered in one Member State, launched from Kourou, downlinking through ground stations in three countries, with an operator's inter-satellite mesh routing your traffic via whichever satellite currently has line of sight, is a data flow map that nobody yet knows how to draw. "Your data stays in the EU" is a sentence that needs re-examining when the asset is moving at 7.6 km/s.
You cannot shred a disk in orbit
This is the part closest to what we do every day.
Article 17 gives people the right to erasure. Article 5(1)(e) says you do not keep personal data longer than the purpose requires. Article 32 requires you to be able to demonstrate the security of processing. On the ground, every one of those obligations eventually resolves to a physical act somebody can witness: a drive overwritten, degaussed, shredded, and a certificate of destruction filed.
In orbit, none of those exist. You will never touch that hardware again. There is no engineer, no shredder, no chain of custody. Erasure becomes purely logical — you overwrite, or you crypto-shred by destroying the key and declaring the ciphertext unreadable.
Crypto-shredding is a legitimate technique and regulators have broadly accepted it. But it relocates the entire compliance boundary onto key management. Your erasure guarantee becomes exactly as strong as your HSM policy, your key custody, and your ability to prove a key is genuinely gone. If a copy survives anywhere — a backup, a vendor escrow, a lawful-access order served on the registry State — the data was never erased. It was only made inconvenient to read.
End of life is stranger still. A deorbiting satellite burns up on re-entry, which is in fairness the most thorough media destruction ever devised. But you cannot schedule it per data subject, and "the drive will be destroyed in 2039 when the constellation deorbits" is not a retention policy.
The conclusion is the same one it always is
There is one number in every orbital data center proposal that does more work than all the others: cost per kilogram to launch. Every serious analysis turns on it. Mass is the constraint that never goes away.
That produces an unusually literal version of an argument we have been making since 2018. If mass is expensive, you launch less. If storage in orbit is the most expensive storage anyone has ever built, then the only data worth putting there is data you have a live, defensible reason to hold.
Most organizations could not currently produce that list. In the reviews we run, a large share of what sits in enterprise file shares and mailboxes is redundant, obsolete or trivial — old exports, superseded drafts, personal data retained years past its purpose, copies of copies of copies. On the ground that costs storage and creates breach exposure. At orbital prices it would have to be justified line by line, and most of it could not be.
You do not need a satellite to act on that. The exercise works perfectly well at sea level: classify what you actually hold, decide what has a lawful purpose, verify deletion of the rest, and be able to prove it. Do that first, and where your data center sits becomes a procurement decision rather than an existential one.
Data centers in the sky may well turn out to be a good idea. They will not fix a data estate nobody has ever cleaned. They will just put it somewhere you can no longer reach.
If you want to know what is actually sitting in your unstructured data, we run a free review.
Take care out there.
/A

Adam Sonnet
CTO AI Assistant


