Skip to content
← Back to the toolkit
PossessUseDisposeDataSoftwareHardwareOrganisational

Data sovereignty

The practical ability to exercise Possess, Use and Dispose across Data, Software, Hardware and Organisational layers within a defined customer-control scope.

Sovereignty asks whether you can keep operating and keep control when a supplier, deployment, contract or geopolitical condition changes.

Data does not fit neatly within property law. This toolkit therefore uses ownershipOwnership, the three rightsA practical lens for sovereignty: the layer-neutral rights to Possess, Use and Dispose, rather than a claim that data has simple legal title.Read more →as a practical lens and makes no claim of legal title. Three layer-neutral rights define the lens: the ability to PossessPossessThe right to obtain, retain and control what continuity requires.Read more →, UseUseThe right to operate, inspect, authorise, integrate and change a capability without discretionary supplier approval.Read more → and DisposeDisposeThe right to revoke, delete, transfer, replace or exit without stranded data or unacceptable operational loss, and to prove the result.Read more →.

Apply each right to DataDataThe records themselves, plus their history, metadata and audit trail.Read more →, SoftwareSoftwareThe code, keys, formats and interfaces that act on the data.Read more →, HardwareHardwareThe physical machines, where they run and who can reach them.Read more → and OrganisationalOrganisationalThe contracts, licences and governance that decide who is permitted to act.Read more → arrangements. Looking at them together prevents one reassuring fact, such as a usable export, from hiding a dependency elsewhere. A contract, responsibility or governance decision can still block a capability that the technology supports.

The Organisational boundary

The Organisational layer is described through two complementary lenses. Data complianceData complianceThe enforceable side of the Organisational layer: the applicable laws, jurisdictions, contracts, licences, policies, decision rights and supplier commitments that set what an organisation may and must do with data.Read more → covers the applicable laws, jurisdictions, contracts, licences, policies, decision rights, duties and supplier commitments that make an action enforceable. Data ethicsData ethicsA separate governance perspective on the Organisational layer: asking whether the exercise of scoped authority is proportionate, fair, transparent and justifiable to the people and communities affected.Read more → asks whether exercising that scoped authority is proportionate, fair, transparent and justifiable to the people and communities affected. Governance applies both through ownership, policy, evidence, review and escalation.

This means sovereignty is not unlimited. Technical control does not authorise an unlawful or irresponsible use. At the same time, compliance alone does not establish sovereignty: a compliant service can still prevent an independent export, operation or exit. Keep compliance findings, ethical considerations and practical-control findings distinct; this toolkit certifies none of them.

Scope and evidence

A sovereignty conclusion is useful only for the stated service or release, deployment, operating model, agreements, customer-control boundary and review date. Evidence from one situation cannot prove another. Gaps and uncertainty should stay visible rather than disappearing behind a general label.

That produces a more useful question than “are we sovereign?”: what can we actually do in this situation, what evidence supports that, and which choices still depend on someone else?

Common misconceptions

Data sovereignty is a compliance status or certificate.

It is a practical question about what an organisation can control in a defined situation, not a legal verdict, score or certification.

If the data sits in the EU, it is sovereign.

Location is one fact. Operators, keys, software, contracts, decision authority and applicable jurisdiction can still prevent you from exercising control.

Put this to work

Related concept

Ownership, the three rights

A practical lens for sovereignty: the layer-neutral rights to Possess, Use and Dispose, rather than a claim that data has simple legal title.

Related concept

The four layers

The three rights apply across Data, Software, Hardware and an Organisational layer described through data compliance and data ethics.

Related article

What it really means to own your data

You cannot hold legal title to data. But strip ownership to its core and three rights remain: to possess, use, and dispose. Those you can hold, and that is data sovereignty.

Copyright 2026HOIST IT. All Rights Reserved