Data sovereignty

The principle that data is subject to the laws and legal processes of the jurisdiction where it is stored, and sometimes of jurisdictions with authority over whoever holds it.

Data sovereignty is about whose law applies to data. Once data is stored in a country, that country’s courts, regulators and law enforcement can generally reach it through their own legal processes. Sovereignty can also follow the organisation rather than the location: the US CLOUD Act of 2018 allows US authorities to require communication and cloud service providers subject to US jurisdiction to disclose data in their possession, custody or control even when it is stored outside the United States. One data set can therefore fall under several legal systems at once.

Sovereignty is the legal consequence of data residency, which is where the data sits. Some countries go further with data localisation laws that require certain categories of data to remain in-country. Organisations respond with region selection, terms in the data processing agreement, and technical measures such as encryption with keys held by the customer. Where the provider holds the keys, it may be able to produce readable data despite the encryption. The data controller remains accountable for where personal data is placed.

Exam relevance: a scenario is likely to describe cloud storage in another country, a foreign legal demand, or conflicting national laws. Candidates are expected to separate the physical question (residency) from the legal question (sovereignty), and to consider who holds the encryption keys.