The four layers
The three rights apply across Data, Software, Hardware and an Organisational layer described through data compliance and data ethics.
A strong technical setup can still be unusable when an agreement, decision process or responsibility prevents the customer from acting.
The three rightsOwnership, the three rightsA practical lens for sovereignty: the layer-neutral rights to Possess, Use and Dispose, rather than a claim that data has simple legal title.Read more →provide a consistent way to ask practical questions in each layer: what can the customer possess, use and dispose of, and what still depends on someone else?
Data
Records, history, metadata, relationships, keys, audit trails and export artefacts. A list of current records is not a complete continuity copy when the context needed to interpret, restore or audit them remains behind.
Software
Code, runtimes, formats, interfaces and dependencies, together with the ability to inspect or change them. Open formats help, but continuity also depends on runnable artefacts, build inputs, licences and a proven replacement path.
Hardware
Machines, networks and the physical or cloud substrate, including their locations, operators and applicable jurisdictions. Ownership of a machine is only one fact; durable access, operating authority and the ability to move the same workload also matter.
Organisational
The institutional layer through which a customer is permitted and expected to act. It is described through data complianceData complianceThe enforceable side of the Organisational layer: the applicable laws, jurisdictions, contracts, licences, policies, decision rights and supplier commitments that set what an organisation may and must do with data.Read more → and data ethicsData ethicsA separate governance perspective on the Organisational layer: asking whether the exercise of scoped authority is proportionate, fair, transparent and justifiable to the people and communities affected.Read more → as complementary lenses.
Data compliance covers applicable law and jurisdiction, contracts, licences, policies, decision rights, duties, supplier relationships and commitments and the evidence that supports them. Data ethics asks whether exercising that authority is proportionate, fair, transparent and justifiable to affected people and communities. Governance operates across both: it assigns ownership and responsibilities, approves policy, records evidence and exceptions and provides review and escalation.
The Organisational layer determines whether the customer has the authority, responsibilities and supplier support needed to use a technical capability in practice. Examine it alongside the technical layers rather than treating an export button, licence clause or ethics statement as sufficient on its own.
A supplier can span several layers, so dependencies should not be forced into one category. Describe each dependency in its actual context and keep missing evidence and unresolved responsibilities visible.
Common misconceptions
Owning the hardware means we control the data.
A licence, contract or governance decision at the Organisational layer can still prevent the customer from obtaining, using, moving or deleting what sits on that hardware.