Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Data sovereignty is more than a pin on a map

Storing data locally won't guarantee sovereignty without governance, resilience and operational control.

Data sovereignty is more than a pin on a map

Data sovereignty has emerged as a critical issue for governments and organizations as they reconsider their dependence on foreign-owned IT infrastructure. However, discussions surrounding this concept have often centered on data storage locations, overlooking crucial legal, operational, and resilience factors that truly determine organizational control.

The term "data sovereignty" is frequently misused, with data residency and sovereignty being conflated, despite their differences. Residency pertains to the physical location of data, while sovereignty encompasses legal jurisdiction, operational control, resilience, governance, and risk management. Recent concerns about reliance on foreign-owned digital infrastructure have heightened the urgency of digital independence and control over critical technology.

Major vendors, especially US-based hyperscalers, are responding by offering "sovereign" alternatives focused on data storage locations. Yet, this approach risks oversimplifying sovereignty to a geographical question. The core issue lies in understanding who may access the data and who ultimately controls the supporting infrastructure.

Misunderstandings lead to "data sovereignty washing," where simplified claims fail to reflect legal or operational realities. Despite existing legal mechanisms for requesting information across jurisdictions, data residency alone doesn't grant immunity from lawful access or eliminate international cooperation. For instance, the US CLOUD Act enables US authorities to request data from US service providers, even when stored outside the US, regardless of the organization's location.

Many countries have enacted legislation allowing authorities to access data for law enforcement or national security purposes, often backed by cross-border agreements. Enterprises should recognize that treating location as their sole sovereignty strategy overlooks its broader implications. Threat actors prioritize data value over geography, meaning organizations may invest heavily in migrating data without addressing their most significant security risks.

Rather than focusing on data location, organizations should prioritize understanding their unique threat models. Different entities, such as local retailers, multinational banks, defense contractors, and government departments, have varying priorities regarding sensitive information. Factors like regulatory compliance, data residency, resilience against cyberattacks, intellectual property protection, and dependence on specific technology providers vary across sectors and businesses.

Instead of merely asking about data storage locations, leaders should delve into who controls the infrastructure, dependency on individual cloud providers, service availability, and control over critical systems. If any of these aspects raise operational or regulatory concerns, adjusting the strategy becomes prudent. While striving for absolute data localization may enhance availability and data recovery, it could inadvertently reduce resilience.

Relying on a single jurisdiction for critical data may limit options for geographically distributed data copies, reducing recovery possibilities. In such cases, emphasizing resilience alongside sovereignty is essential. Organizations must balance availability, confidentiality, and integrity, recognizing that sometimes strategic distribution outperforms rigid localization.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

More from Thursday 13 August →