Skip to content

Data Sovereignty Toolkit

An open toolkit for practical data sovereignty

Everything here is free to read, copy and print. No sign-up. Start with the self-check, then use the concepts, checklists, vendor questions and AI prompts to investigate where control is strong and where dependencies or responsibilities still need attention.

Layer
Right

Concepts

What data sovereignty is and the ideas it rests on.

Possess · Use · Dispose

Data sovereignty

The practical ability to exercise Possess, Use and Dispose across Data, Software, Hardware and Organisational layers within a defined customer-control scope.

Possess · Use · Dispose

Ownership, the three rights

A practical lens for sovereignty: the layer-neutral rights to Possess, Use and Dispose, rather than a claim that data has simple legal title.

Possess · Use · Dispose

The four layers

The three rights apply across Data, Software, Hardware and an Organisational layer described through data compliance and data ethics.

Possess · Use · Dispose

A data platform

A set of data services and operating practices that makes selected data discoverable, integrated, governed and usable for purposes such as reporting, exchange, automation and AI. It may be centralised, distributed or federated.

Possess · Use · Dispose

Data compliance

The enforceable side of the Organisational layer: the applicable laws, jurisdictions, contracts, licences, policies, decision rights and supplier commitments that set what an organisation may and must do with data.

Possess · Use · Dispose

Data ethics

A separate governance perspective on the Organisational layer: asking whether the exercise of scoped authority is proportionate, fair, transparent and justifiable to the people and communities affected.

Terms

Shorter definitions the concepts refer to.

Tools

Print a checklist, take the vendor questions into a call or paste a prompt into your AI.

For

Vendor questions

Questions to ask a vendor before you sign

The questions that make a supplier prove data sovereignty, and what a real answer versus an evasive one sounds like. Copy them into an RFP, or read them down a vendor call.

AI prompt

Find the vendor lock-in in an architecture

Maps lock-in across data, software, infrastructure and organisational arrangements and ties each dependency to evidence, an exit impact and a tested reversal path.

AI prompt

Review who can access unencrypted data

Maps the stated technical, operational and legal paths to plaintext, distinguishes key policy from custody and identifies the evidence still missing.

AI prompt · challenge us

Challenge our claims

Invites an AI to steelman and then challenge Hoist IT's public sovereignty claims, distinguishing useful simplification from house choices and unresolved gaps.

Copyright 2026HOIST IT. All Rights Reserved