Possess · Use · Dispose
Data sovereignty
The practical ability to exercise Possess, Use and Dispose across Data, Software, Hardware and Organisational layers within a defined customer-control scope.
Data Sovereignty Toolkit
Everything here is free to read, copy and print. No sign-up. Start with the self-check, then use the concepts, checklists, vendor questions and AI prompts to investigate where control is strong and where dependencies or responsibilities still need attention.
No resources match that combination yet. Clear a filter to see more.
What data sovereignty is and the ideas it rests on.
Possess · Use · Dispose
The practical ability to exercise Possess, Use and Dispose across Data, Software, Hardware and Organisational layers within a defined customer-control scope.
Possess · Use · Dispose
A practical lens for sovereignty: the layer-neutral rights to Possess, Use and Dispose, rather than a claim that data has simple legal title.
Possess · Use · Dispose
The three rights apply across Data, Software, Hardware and an Organisational layer described through data compliance and data ethics.
Possess · Use · Dispose
A set of data services and operating practices that makes selected data discoverable, integrated, governed and usable for purposes such as reporting, exchange, automation and AI. It may be centralised, distributed or federated.
Possess · Use · Dispose
The enforceable side of the Organisational layer: the applicable laws, jurisdictions, contracts, licences, policies, decision rights and supplier commitments that set what an organisation may and must do with data.
Possess · Use · Dispose
A separate governance perspective on the Organisational layer: asking whether the exercise of scoped authority is proportionate, fair, transparent and justifiable to the people and communities affected.
Shorter definitions the concepts refer to.
Print a checklist, take the vendor questions into a call or paste a prompt into your AI.
Checklist
Twelve checks that tell you whether you could actually move off a critical supplier, before you need to. Print it, take it into a stand-up, and mark honestly.
Vendor questions
The questions that make a supplier prove data sovereignty, and what a real answer versus an evasive one sounds like. Copy them into an RFP, or read them down a vendor call.
AI prompt
Maps practical control, dependencies and evidence gaps across data, software, infrastructure and organisational arrangements, then ranks the risks that matter most.
AI prompt
Maps lock-in across data, software, infrastructure and organisational arrangements and ties each dependency to evidence, an exit impact and a tested reversal path.
AI prompt
Separates four contested terms, states the definition used for each and shows which facts are necessary but insufficient without inventing one universal hierarchy.
AI prompt
Reviews ownership, exit, jurisdiction and change-control clauses so you look for enforceable rights rather than reassuring language.
AI prompt
Maps the stated technical, operational and legal paths to plaintext, distinguishes key policy from custody and identifies the evidence still missing.
AI prompt
Turns "we could leave in principle" into an executable runbook and exposes gaps in data, software, infrastructure, authority and supplier support.
AI prompt
Turns practical control gaps and missing evidence into concrete "if X, then we cannot Y" risks and a board-ready summary without hiding uncertainty in a score.
AI prompt · challenge us
Invites an AI to steelman and then challenge Hoist IT's public sovereignty claims, distinguishing useful simplification from house choices and unresolved gaps.
Copyright 2026HOIST IT. All Rights Reserved