Data compliance
The enforceable side of the Organisational layer: the applicable laws, jurisdictions, contracts, licences, policies, decision rights and supplier commitments that set what an organisation may and must do with data.
Technical control only matters when the organisation has authority to exercise it and can evidence the obligations that govern it. Compliance does not by itself prove sovereignty.
Data compliance is one of the two complementary lenses through which this toolkit describes the Organisational layerThe four layersThe three rights apply across Data, Software, Hardware and an Organisational layer described through data compliance and data ethics.Read more →. It is broader than regulatory compliance alone.
It covers the enforceable framework around data:
- applicable law, regulation and jurisdiction;
- contracts, data-processing agreements, licences and exit terms;
- policies, responsibilities, decision rights and duties;
- supplier and subprocessor commitments, plus the evidence needed to verify them.
That framework both limits and enables action. It can require retention, restrict a use or protect the rights of affected people. It can also give an organisation the authority to obtain continuity material, approve an integration, revoke supplier access or leave a service. A technical capability is not enough when the organisation lacks the right to exercise it; reassuring contract language is not enough when the capability cannot be exercised in practice.
Data compliance therefore applies to PossessPossessThe right to obtain, retain and control what continuity requires.Read more →, UseUseThe right to operate, inspect, authorise, integrate and change a capability without discretionary supplier approval.Read more → and DisposeDisposeThe right to revoke, delete, transfer, replace or exit without stranded data or unacceptable operational loss, and to prove the result.Read more →. Every conclusion remains tied to the service and release, deployment, operating model, contract and governance baseline, customer-control boundary and evidence period being reviewed.
Governance operates across both data compliance and data ethics. It assigns applicability, authority and responsibility, approves policy, records evidence and exceptions and provides review and escalation.
This toolkit neither gives legal advice nor certifies compliance. Compliance also does not settle whether a permitted action is responsible. That is the role of data ethicsData ethicsA separate governance perspective on the Organisational layer: asking whether the exercise of scoped authority is proportionate, fair, transparent and justifiable to the people and communities affected.Read more →.
Common misconceptions
If we comply with the law, our data is sovereign.
Compliance and sovereignty answer different questions. A service can meet its legal duties while still withholding a usable export, independent operation or an enforceable exit.
Keeping data in the EU makes us compliant.
Location is only one fact. Applicable law, roles, purposes, access, international transfers, contracts and the rights of affected people still need a scoped assessment.