The internet is a network that is designed to be interconnected, borderless, and international. Regular interactions with digital systems often involve physical and software components that come from all over the world.
But even though components of the internet are international by definition, hardware that enables connections still has a physical location: a server or a data center is located somewhere on the planet and is owned by an organization that is physically incorporated somewhere in the world and is subject to its legal jurisdiction.
Global supply chains are embedded in the infrastructure of digital connections. Reading this blog on the Axway website means: using a local computer with components designed, manufactured, and assembled in several countries across two or three different regions of the world, a browser likely created by a U.S.-based organization, installed on this computer connects to a router produced overseas, which hands the request to the local provider; the local provider delivers the request to the DNS server, then routes the request to the global network with data traveling using physical cables that likely cross several jurisdictions, until it finally reaches the content server.
Count the number of countries and jurisdictions that the data crosses only to read this blog.
Each of those jurisdictions has its own rules about who can access, store, and control the data passing through it. The organization that owns the hardware at any point in that chain is subject to its own local legal framework, regardless of where the data originated or where you are reading this blog.
How AI triggered risks
For about a decade, we have existed in the world of the Internet of Things (IoT). Physical objects actively and continuously receive and transmit data: a car sending data to the manufacturer, a smartwatch generating biometric data; even establishments like hospitals and factory floors now constantly produce data. Over the years, these physical devices transmitted so much data that it was impossible to process without significant manual effort and use in full to make meaningful conclusions. The volume of data provided a degree of data insulation. Having large datasets and standard analytics tools meant that reaching a meaningful conclusion would require a deliberate, targeted effort.
This status quo changed with the onset of artificial intelligence.
Artificial intelligence (AI) has become a tool to process much larger volumes of data and to continue processing continuously as new data is generated. In the pre-AI era, producing more data complicated analysis. With AI, more data opens more opportunities for definite conclusions. Volume stops being a barrier and becomes an advantage.
Before AI, data access was a security concern, but accessing the data wasn’t fully equal to processing, analyzing, and using the data. With AI, access to data automatically translates directly into insight, leverage, and advantage.
Suddenly, the interconnected web of hardware and software that is powered by the global supply chain and invokes a series of cross-jurisdictional connections to read a blog on a web page becomes a concern. If someone can gain access to private data due to their legal right to exercise jurisdiction, the question of who owns data streams becomes practical.
It is that practical reality that three concepts that are related but distinct attempt to address: data residency, data sovereignty, and digital sovereignty.
What is digital sovereignty?
Digital sovereignty is full end-to-end jurisdictional control over the entire technology stack. This concept provides full independence from external providers outside of the jurisdiction where an organization operates.
Digital sovereignty is not limited to data, but encompasses everything that relates to data, mainly physical hardware and the software that operates the hardware: servers, all components of these servers, software like firewalls and load balancers, or external SaaS and applications.
For private enterprises, Axway recommends considering digital sovereignty not as a goal with a 100% completion bar, but instead as a spectrum, where the most critical parts of the stack can be sovereign, while leaving less critical parts external. Consider concepts of data residency and data sovereignty when making decisions on the digital sovereignty strategy.
What is data residency?
Data residency is the physical, geographic location of a data storage unit.
While digital sovereignty is the broadest concept, data residency, on the contrary, is the narrowest and most limited concept out of the three presented in this blog. Data is stored on a server, and this server is located somewhere in the world: in Frankfurt in Germany, or in Virginia in the United States, or Singapore, or elsewhere.
The physical location of the server and the data that it stores do not, however, solely define jurisdictional control. If a server is located in one country, but the organization that owns the server is incorporated in a different country, the government of the server owner can still exercise its jurisdiction over the stored data.
Data residency is a real and relevant concept. It is a part of the jurisdictional picture but doesn’t provide a full picture. The physical location of data is only one of the variables that determine the jurisdictional authority. But this is not the only component. The legal extraterritorial jurisdiction, or the authority of a government to exercise jurisdiction beyond its territorial borders, frequently applies to data centers even if the server is located outside of the territory of that government.
Data residency does not provide legal protection from the jurisdiction of the government, where the organization that owns the data center is incorporated.
What is data sovereignty?
Data sovereignty defines legal authority over data, and, specifically, which governments or jurisdictions can gain the legal right to access data or have control over data. Data sovereignty is a part of the wider concept of digital sovereignty scale, and data sovereignty takes the data residency concept a step further by adding the question of legal jurisdiction to the question of physical location. Where data residency determines the physical location of a server that stores the data, data sovereignty identifies who governs the data. Sometimes, these two concepts provide two different answers.
The primary determining factor for data sovereignty is the jurisdiction of incorporation of the enterprise that owns the server. A global cloud provider owns a server in Germany and is incorporated in the United States of America: data residency belongs to Germany, but the United States can claim jurisdiction over the server and the data it stores, citing the cloud provider’s U.S.-based identity and U.S. federal legislation, the 2018 Clarifying Lawful Overseas Use of Data (CLOUD) Act.
The origin of incorporation is the primary factor in determining jurisdiction, and details depend on local law and legal process. The United States CLOUD Act, for example, extends the jurisdiction of U.S. federal law to all U.S. persons, but also provides a wide net of potential circumstances that can exclude data from U.S. jurisdiction or limit the court process for issuing and dismissing subpoenas to access the data.
Data sovereignty: data access and continuity of service
Sovereignty over data has two distinct dimensions: access control and continuity of service.
Data access control is the legal power to issue a subpoena, or another kind of legal document, that legally compels persons and entities under the jurisdiction of certain national law to provide access to data stored on its infrastructure. This aspect is governed by the extraterritorial jurisdictional reach of home governments regardless of data residency. An organization storing sensitive data on infrastructure that is owned by a foreign-incorporated provider cannot fully exclude the possibility that this data will be subpoenaed by the home government.
The second aspect is the continuity of service, or which government has jurisdiction, or authority, to order the suspension or termination of services that are provided by entities under the regulation of this government. This is a concern that is separate from data access. Continuity of service is not about who can subpoena the data, it is about which government can intentionally disrupt access to systems through a legal action outside of an organization’s control.
Out of these two dimensions of data sovereignty, service continuity is a more attainable goal. Full data access insulation, or ensuring that no government can use legal action to access data, is a more demanding and complex task (if achievable at all). Achieving more control over who can terminate and suspend services can be done with a correct strategy.
Approaching digital sovereignty and data sovereignty strategy
Strategies for digital and data sovereignty define the specifics of data residency, or where an organization chooses to host its data.
Approaching sovereignty over digital systems in general and data sovereignty in particular is a risk management strategy and a cost-benefit analysis. Two diagnostic questions determine infrastructure and vendor decisions: the sensitivity of data and the operational criticality of each system.
Full independence can come at a serious cost. The simple reality is that the information technology supply chain is too global to make full digital sovereignty an achievable target. By engaging in full digital sovereignty, an organization effectively chooses to cut itself off from this global supply chain and all the benefits that it provides, while also carrying all the costs associated with local-only shopping.
The 100%-sovereign approach increases the total cost of ownership and, depending on geographic location and jurisdiction, can skyrocket the costs of acquisition, adoption, maintenance, and modernization. Organizations can make cost-benefit choices about what to keep sovereign and where it makes financial and operational sense to forego sovereignty and use the benefits of the global supply chain.
See also: Balancing data autonomy and security to deploy AI agents without increasing business risk
Not all organizational data and not all operational systems are created equal; some data and some systems are more critical than others and require more attention than others. The source code of a core product and a public webpage are both data, but they require different kinds of insulation and control. Same with systems: some systems support non-essential workflows, and some systems support critical day-to-day organizational operations. Like critical and non-critical data, systems can be triaged differently across low- and high-sovereignty environments.
For non-sensitive and unregulated data, data sovereignty might be less of a concern than other factors like cost and service availability, and choosing an environment that doesn’t provide full data sovereignty can be a sensible choice. For sensitive and regulated data, where the possibility of external access is highly undesirable and a disruption in service continuity can be a critical risk, choosing a sovereign environment (either with a local provider or fully on-premises) might be worth the additional costs.
Together, these two diagnostics produce a tiered approach to selecting infrastructure and vendors. Highly sensitive and regulated data, along with mission-critical operational systems, should be safe from disruptions and unwanted access and require solutions with high sovereignty: sovereign cloud providers incorporated in the jurisdiction of your operations, minimizing exposure to legal action from abroad. The most sensitive data and the data that is critical for competition might need to find their residence on-premises.
But full data sovereignty has the potential to drive up TCO if all data is stored with full sovereignty or fully internally. Where a low level of sensitivity or criticality allows, external hosting, including vendors from across borders, can be a viable and preferred solution.
Learn how Axway approaches digital sovereignty
