Data Sovereignty

Data Sovereignty is the ability of an organization to retain control over its data, its processing and the legal framework that applies to it. What matters is not only where data is stored, but also which companies, authorities and jurisdictions can exert influence on it. Data sovereignty therefore concerns technical, organizational and contractual decisions alike.

In cloud and SaaS environments, factors such as vendor dependencies, administrative rights, encryption, data export, deletability and the choice of storage regions play a role. An organization is all the more sovereign the more transparently it can control data flows and, if necessary, transfer data to controllable environments. The topic is closely linked to Data Management and Governance and Security.

Data sovereignty must be distinguished from data residency: the storage location is an important sub-aspect, but on its own does not describe the entire legal and operational control over data.