Ownership, the three rights
A practical lens for sovereignty: the layer-neutral rights to Possess, Use and Dispose, rather than a claim that data has simple legal title.
The three rights turn a broad idea into practical questions that can be examined separately and tied to evidence.
Data does not fit neatly within property law. Instead of treating “ownership” as legal title, this toolkit asks which concrete rights a customer can exercise across every layer.
Possess
Possess is the right to obtain, retain and control what continuity requires. Depending on the layer, that can mean a usable and restorable data copy, runnable software and source rights, visibility and durable access to the substrate or enforceable contractual and governance authority.
Possess is more than knowing where bytes sit. The material must be complete enough to continue within the stated service, deployment, operating and customer-control scope.
Use
Use is the right to operate, inspect, authorise, integrate and change a capability with tools and partners of the customer’s choosing, without discretionary supplier approval. Access, policy control, auditability and the ability to change are ways in which Use becomes practical, not separate ownership claims.
Use is never unlimited. In the Organisational layerThe four layersThe three rights apply across Data, Software, Hardware and an Organisational layer described through data compliance and data ethics.Read more →, data complianceData complianceThe enforceable side of the Organisational layer: the applicable laws, jurisdictions, contracts, licences, policies, decision rights and supplier commitments that set what an organisation may and must do with data.Read more → describes the rules, agreements and authority that apply, while data ethicsData ethicsA separate governance perspective on the Organisational layer: asking whether the exercise of scoped authority is proportionate, fair, transparent and justifiable to the people and communities affected.Read more → makes responsible-use concerns visible to customer governance. Keep those perspectives distinct from the practical question of whether the capability can be used.
Dispose
Dispose is the right to revoke, delete, transfer, replace or exit without stranded data or unacceptable operational loss, and to prove the result. It covers more than a file export: data must remain usable, software and infrastructure must be replaceable, supplier access and copies must be addressed and transition obligations must be enforceable.
Apply each right to Data, Software, Hardware and Organisational arrangements. Keep gaps explicit: control in one area does not show that the customer can act independently everywhere else.
Common misconceptions
We own our data because the contract says it is ours.
A label is worth little if you cannot obtain continuity material, operate without discretionary supplier approval, leave without stranded assets and prove the result.