Skip to content

What it really means to own your data

You cannot hold legal title to data. But strip ownership to its core and three rights remain: to possess, use, and dispose. Those you can hold, and that is data sovereignty.

Cover for What it really means to own your data
Updated: Jun 25, 2026

Can you prove you own your data?

Ask an organisation whether it owns its data and the answer comes quickly: of course, it is our data, about our people, collected for our own purposes. Proving it is another matter, and a simple test shows why.

Take a Dutch municipality. It holds the personal records of its residents: names, addresses, benefit details, the everyday data a town needs to run. The municipality plainly “has” that data. The systems it runs on, though, belong to external cloud vendors, and that is no thought experiment: Dutch municipalities are reported to be locked into Microsoft without a realistic way to switch (Tweakers, 2025), part of a public sector that has grown heavily dependent on American cloud providers (RTL Nieuws, 2025).

Now put that to the test. Suppose a resident exercises their right to have every copy of their record erased, and the council has to certify it is gone, across the vendor’s live systems, its backups, and any sub-processors it uses. Or the council decides to switch suppliers and has to take the data with it, proving the old copy was destroyed. Can it do either on its own authority, and demonstrate it? Where the answer is no, the data is theirs in name, but the controls that would prove it sit inside someone else’s platform.

That gap between holding data and controlling it is the whole question, and it hangs on the meaning of one short word: “own”. A word you plan to act on needs a definition built to take that weight: what Deming called an operational definition, “one that people can do business with” (Deming, 1986).

Ownership is three rights

Strip ownership down to its core and three rights remain: the right to possess something, to use it, and to dispose of it. The triad is old law: the US Supreme Court has described property rights in a thing as “the right to possess, use and dispose of it” (United States v. General Motors Corp., 1945), and the classic analytical account of ownership counts possession, use and disposition among its core incidents (Honoré, 1961). Hold all three and you own it; lose any one and you do not.

Data complicates this, because there is no legal title to hold. Legally, no one owns data. Across EU, English, Belgian, French and German law there is currently no general property or ownership right in digital data (Determann, 2019; Geiregat, 2022), and even the EU Data Act, in the same analysis of its draft, “is not intended to create exclusive ownership of data, properly speaking”. Information-systems researchers arrive at the same verdict: data “cannot be classified as private or common goods”, because “there are no legally binding concepts regarding their ownership” (von Scherenberg et al., 2024). Whether there should be such a right is argued both ways (Drexl, 2017; Zech, 2016). For now there is not, and the absence is not neutral: without a deliberate legal assignment, data accrues to whoever is in a position to exclude others from it (Purtova, 2015).

So the title you assume you hold does not exist. The three rights, though, still do, as practical control rather than property law. You can possess your data by keeping your own copy on infrastructure you choose; use it by running what you like on it, moving it, combining it; and dispose of it by deleting it and proving it is gone. The catch is that the rights have to hold across the whole stack: the hardware the data runs on, the software that processes it, and the data itself. Lose a layer and the rights leak away there, which is exactly the municipality’s problem. It has the data; the hardware and software underneath belong to someone else.

Holding those three rights, across those three layers, on your own terms, has a name.

So what is data sovereignty?

The name is data sovereignty. Sovereignty means self-determination: deciding for yourself how something is used. Applied to data, it is the ability of a person or organisation to govern how their own data is used, which is to say, to hold the three rights and actually enforce them.

Jarke, Otto and Ram define it as “the self-determination of individuals and organizations with regard to the use of their data” (2019). A more recent review is blunter about its purpose: data sovereignty is “an instrument to keep control over an actor’s data asset” (von Scherenberg et al., 2024). Recent work pushes it past control alone, describing sovereignty through protection (baseline rights), participation (who shares responsibility) and provision (the mechanisms that preserve those rights during and after sharing) (Abbas et al., 2024). The weight is on use and on who decides, not on possessing a thing. That is why “own your data” is a good slogan only if “own” means the three rights, not a deed.

The term is not settled. A review of 341 publications found no agreed definition, noting instead “a considerable degree of divergence and an occasional lack of clarity about intended meanings of data sovereignty” (Hummel et al., 2021). One common usage is purely jurisdictional, treating data sovereignty as “the concept that data is subject to laws and regulations of a particular nation” (Docter & Fuchs 2020, quoted in von Scherenberg et al., 2024). Which laws reach your data matters, but it is a different question from whether you can actually exercise the three rights. The model below shows how those rights are kept in practice.

The anatomy of control: seven moving parts

To make self-determination over data use concrete enough to check, von Scherenberg et al. (2024) break it into seven interacting parts. The numbers below match the figure.

The seven interacting aspects of data sovereigntyA data provider and a data consumer build trust and negotiate a contractual agreement that sets access and usage conditions. A data infrastructure enforces that agreement and governs access to the data asset, which is modified by data value-chain and lifecycle activities. Trust is the foundation of every relationship.The anatomy of controlSeven interacting aspects of data sovereignty2Data providerholds the right to control the asset3Data consumerwants to use, share or reuse ittrust4Contractual agreementsets access and usage conditionsenforces6Data infrastructureenforces the agreement (access and usage control)governs access to1Data assetwhat control is retained overmodified by5Data value chain and lifecycle activitiescreate → store → use → share → archive → destroy7Trust: the foundation of every relationshiprequired by everyone, strengthened by the infrastructure
The seven interacting aspects of data sovereignty. Adapted from von Scherenberg, Hellmeier & Otto (2024), CC BY 4.0.

Start with the municipality. At the centre is the data asset (1): the residents’ dataset, the thing to be kept under control. Two parties have an interest in it. The data provider (2) holds the right to control that asset: the municipality. The data consumer (3) wants to use, share or reuse it: a university research partner asking for part of the data for a study, say. The cloud vendor enters the model further down, as the operator of the infrastructure the data lives on.

Before any data changes hands, the two need trust (7), which sits under every relationship in the model. Trust alone binds no one, so the provider and consumer put it in writing, in a contractual agreement (4) that sets out who may touch the data and what they may do with it.

A contract, though, is only a promise; consent given through terms no one negotiates is a thin kind of control (Rhoen, 2016). What enforces it is the data infrastructure (6), the technical layer that applies the agreed conditions in practice; for the municipality, that layer is run by its cloud vendor. Two of the three layers from earlier live here: the hardware and the software are the infrastructure through which control over the data is exercised, or lost. Enforcement comes in two kinds:

  • Access control decides who may reach the data at all.
  • Usage control decides what may be done with it once access is granted: how it may be processed, combined, or passed on.

A municipality that can see who logged in has access control. One that can also guarantee a research partner may compute a statistic but never copy the raw records elsewhere has usage control too. Building that enforcing layer is exactly what infrastructure efforts like Gaia-X and the International Data Spaces (IDS) set out to do: apply policies that travel with the data after it leaves the provider’s systems (Zrenner et al., 2019; Otto & Jarke, 2019).

Control also cannot be a one-time check at hand-off. It has to hold across the full lifecycle (5): as data is created, stored, used, shared, archived and finally destroyed. This is what makes the erasure request such a good test. A guarantee that lapses the moment data is copied to a backup or handed to a sub-processor is not much of a guarantee.

The shift is from paper to enforcement: what counts is control that travels with the data, at every layer.

What data sovereignty is not

Three neighbouring ideas get mistaken for it, and separating them out sharpens the definition.

Data protection (GDPR). The GDPR sets a legal floor for personal data: it defines the rights people have over data about them (access, correction, erasure) and the duties of those who process it, a legal instrument in its own right rather than a privacy rule by another name (Lynskey, 2014). For personal data it pulls in the same direction as data sovereignty. It is not the same thing: the GDPR covers one category of data and a fixed set of rights, whereas data sovereignty is about controlling the use of all your data, personal or not.

Data residency and localization. Both are about geography. Residency is where data happens to be stored or processed; localization is a legal requirement that data generated in a country stay inside its borders (IBM). They tell you where the data sits, not whose law reaches it or who decides how it is used. The municipality’s records could live on servers in the Netherlands and still fall under a foreign provider’s home law; physical location alone does not settle whose law reaches the data (Hon et al., 2016), even as states increasingly reassert control over what sits inside their borders (Glasze et al., 2023). Location and control are separate questions.

Digital (or technological) sovereignty. This is the wider idea: control over the whole digital stack an organisation relies on, from infrastructure and hardware to software and data (Floridi, 2020; Pohle & Thiel, 2020). Data sovereignty is the data part of that picture. The labels are slippery in practice: “digital”, “technological” and “cyber” sovereignty get used both as synonyms and as separate layers (Couture & Toupin, 2019), so it is safest to treat data sovereignty as the data-focused slice of the wider debate, not a fixed rung in a hierarchy.

Why this matters now

The risk is not new; the urgency is. In February 2025 the United States sanctioned the International Criminal Court’s chief prosecutor; by May, his Microsoft email had reportedly gone dark and he had moved to the Swiss provider Proton Mail (Computer Weekly, 2025). Microsoft denied ever cutting services to the court itself (heise online, 2025), though it had earlier confirmed that a sanctioned official was disconnected from its services (iBestuur, 2025). Whatever the precise mechanics, the episode was a wake-up call. The court has since confirmed it is replacing Microsoft Office with openDesk, the open-source workplace suite built for Germany’s public sector (The Register, 2025), and the affair put the question in the sharpest possible terms: if a foreign provider can be compelled to switch you off, you do not fully control your own tools.

That exposure is structural. Under the US CLOUD Act, a US-based provider can be ordered to produce data in its control wherever in the world that data sits, an EU data centre included (Daskal, 2015; Cross-Border Data Forum). This is not hypothetical. Asked under oath before a French Senate commission of inquiry into public procurement on 10 June 2025 whether he could guarantee that French citizens’ data would never be transmitted to the US government without French authorities’ agreement, Microsoft France’s director of public and legal affairs answered that he could not: “Non, je ne peux pas le garantir” (“No, I cannot guarantee that”), while noting that this had never yet happened (Sénat, 2025). A contractual pledge to keep data inside the EU, which Microsoft also offers, does not change that answer, because it cannot override US law.

Sovereignty has meanwhile become a product category: Microsoft, for one, announced “comprehensive sovereign solutions” for European organisations in June 2025 (Microsoft, 2025). There is by now a name for the distance between that label and the thing, modelled on “greenwashing”: sovereignty washing, a sovereignty claim asserted as a standard that turns out hollow in substance and unworkable in practice (Adler-Nissen & Eggeling, 2024). Whatever such offerings deliver technically, a “sovereign cloud” badge does not, on its own, change which law can reach the provider: the Dutch technologist Bert Hubert calls the hyperscalers’ “sovereign” editions fairy tales that cannot be sanction-proof while US law still reaches the company running them (Hubert, 2025).

That reach is not even limited to data you entrust a provider to host. In May 2026 Microsoft, with other US firms, handed a committee of the US Congress the names and related records of Dutch officials at the competition and data-protection regulators, in response to a subpoena tied to an inquiry into Europe’s platform rules (NOS, May 2026). This was a congressional subpoena, not the CLOUD Act, and the records came from the firms’ own corporate systems rather than anything they host for the Dutch state; under US law the firms had to comply. The mechanism differs, but the lesson is the same: data about you that sits in a US company’s hands is within reach of US law, with no Dutch authority in the loop. The responsible state secretary called it “ontzettend onwenselijk” (extremely undesirable).

The dependence is also broad. More than half of the Dutch central government’s most important public-cloud services are bought from Amazon, Microsoft and Google (Algemene Rekenkamer, 2025). A January 2026 NOS investigation found that 67% of roughly 16,500 examined public-sector and vital-sector domain names are linked to at least one US cloud service (NOS, January 2026). That is a DNS-level signal rather than a count of dependent organisations, but a telling one. Across the European market, the US “hyperscalers” (the biggest cloud providers: Amazon, Microsoft and Google) hold roughly 70% of it, while European providers’ share has fallen from 29% in 2017 to about 15% in 2024 (Synergy Research Group, 2025).

None of this is only about contracts. Information-systems and marketing research shows “lock-in” also forms as skill-based habit and status-quo inertia, with dependence settling into assumptions long before it appears in a procurement document (Murray & Häubl, 2007; Limayem et al., 2007; Polites & Karahanna, 2012); our own research finds the same pattern in regulated organisations (Everaars, 2024). The economics are no subtler: with switching costs, incumbents can “invest then harvest”, winning customers cheaply and charging the locked-in later (Klemperer, 1987, 1995). Lock-in lives in muscle memory as much as in the master services agreement, and both have to be unpicked.

Some of this loss of control is home-grown. In Dutch mental healthcare, the detailed record of a patient’s treatment does not stay with the clinic that holds it; it flows to a few central bodies, and the line between who treats, who pays, and who holds the data blurs. For years, providers sent patients’ outcome questionnaires (Routine Outcome Monitoring, scoring how depressed, anxious or suicidal someone is) to a central data vault, run by a benchmark foundation and paid for by the health insurers so they could buy care on its results. Patients were never asked to consent, though this was personal data leaving the clinic for an outside party (van Os, 2019). The Autoriteit Persoonsgegevens, the Dutch data-protection regulator, found in December 2019 that this had processed personal data “zonder wettelijke grondslag” (without a legal basis); the foundation’s successor was reprimanded and the original dataset destroyed (Akwa GGZ, 2019).

It happened again at the regulator. When the Nederlandse Zorgautoriteit began collecting intimate questionnaire data on mental-health patients nationwide, an investigation found it had not, at first, spelled out to that same privacy regulator what it was gathering, noting the sensitive questionnaire only as a technical entry deep in an annex (NOS, 2023). A court allowed the collection in 2025, holding the pseudonymised data were not personal data in the regulator’s hands (Rechtbank Midden-Nederland, 2025), a finding the claimants reject. Each case turns on its own facts. Together they pose the sovereignty question in domestic form: who can reach the data, and how they read it, settled by how it is concentrated and on what terms it is shared, not by which country the servers sit in. The government has landed in the same place, defining digital autonomy in its December 2025 vision by control rather than by location, the ability to choose your own technology and to switch suppliers (Rijksoverheid, 2025).

Regulation, at least, is pulling in the right direction. The EU’s data strategy (COM(2020) 66 final) set the course. The Data Governance Act (Reg. (EU) 2022/868) has applied since 24 September 2023, and the Data Act (Reg. (EU) 2023/2854), applicable since 12 September 2025, obliges cloud providers to make switching away easier.

There is a way out

Breaking free of hyperscaler lock-in can look “close to impossible”. It is not; it is a matter of doing it in the right order. You do not break dependence by ripping everything out at once, and resistance to wholesale system change is itself well documented (Kim & Kankanhalli, 2009). You do it in stages: begin on a hyperscaler but on a platform built to move, shift to a European provider when you are ready, and run on your own hardware where it matters most. Each step keeps operations running, moving the platform rather than rebuilding it from scratch.

That is the work we do at HOIST IT. We do not “grant” sovereignty or sell it as an add-on; we help regulated organisations reach it for themselves, on “mature” data platforms designed to run anywhere and to stand up in days, not months. We are putting that approach into practice right now with AMALT, a learning-analytics platform for the Dutch Ministry of Defence that we are building together with Next Learning Valley, TNO and NLR, designed to deliver training to 200,000 soldiers under NATO security requirements.

From owning to proving

Which brings us back to where we started. “Can you prove you own your data?” now rests on a definition you can do business with: “owning” means control you can actually exercise and demonstrate.

Enforcement is the test of control. It has to be designed into the platform from the start; by the time the data already lives somewhere else, the options have narrowed.

Sovereignty is not a feature. It is the foundation.

That is the flag worth raising over your own data. Host anywhere, own everything.

What’s next in this series

That is the definition. The next two parts get practical. Part 2 looks at the layer that decides whether you can exercise any of these rights: the contract you sign first and read last. Part 3 turns to architecture and tooling: the data spaces, infrastructure and standards behind it.

References

Further reading

Revision history
  • — Added the domestic dimension to "Why this matters now": control also leaks at home, shown through Dutch mental-healthcare data flows (the ROM/SBG benchmark case and the NZa zorgvraagtypering case) and the government's December 2025 framing of digital autonomy as control, not location.
  • — Added Microsoft's sworn French Senate testimony, the May 2026 case of Dutch officials' data handed to a US congressional committee, and the "sovereignty washing" framing (Adler-Nissen & Eggeling, 2024).
  • — Published.
HOIST IT

Atoomweg 63, 3542 AA Utrecht

Blog

Copyright 2026HOIST IT. All Rights Reserved