The complexity of data sovereignty in a multi-polar world

Issue 6 2023 Infrastructure


Andrew Cruise.

“The importance of data sovereignty and security creates complexity in a world where sharing such information across borders generates huge social and economic benefits,” says Andrew Cruise, Managing Director of Routed. It is clear that in the digital age, data sovereignty is becoming more important, as data is increasingly generated and collected through a variety of channels, including e-commerce, social media platforms and mobile devices.

Essentially, data sovereignty is a phrase that describes the principle that a country has the authority and right to govern and control the data generated within its borders. Thus, the concept of data sovereignty gives governments the power to regulate the collection, storage, processing, and distribution of any data that originates within their borders.

Obviously, this will have an impact on cross-border data flows and international data-sharing agreements. Remember that different countries adopt different data sovereignty policies, but broadly, they are about demanding that data generated within the country be kept within the borders for security or regulatory purposes.

Complicating the situation is the recognition that data access and the sharing of such information across borders generates social and economic benefits of somewhere between 2,5% and 4% of GDP. In addition, data transfers of this nature also enable a wide variety of other critical activities, such as the sharing of essential information related to crime prevention, scientific research and innovation, anti-fraud and money-laundering activities, disaster management and even climate change.

It is worth paying close attention to data sovereignty, not only from the point of view of safeguarding private data, but also to avoid liability issues related to legal violations associated with a failure to protect personal information.

A major reason for the complexity around data sovereignty is that the laws governing it vary greatly from country to country, as do cloud service providers’ agreements concerning privacy policies and user rights. Therefore, organisations operating across multiple countries or regions must understand each country’s regulations to comply with all applicable laws.

In fact, ultimately, there are multiple differing definitions of exactly what constitutes ‘data sovereignty’, and it is vital that we obtain some form of industry-wide collaboration in defining and upholding the principles of data sovereignty.

Recognising the complexities of data sovereignty, VMware notes that the answer lies in sovereign cloud deployment, as this is an option that is inherently more secure and offers better data integrity and data assurance.

To this end, VMware is making efforts to promote Sovereign Cloud Partnerships and the criteria they use to select providers, but at the same time, it seeks to limit the number of providers in each region - thus ensuring the rarity of the ‘cloud sovereignty’ badge.

Among VMware’s requirements are for such service providers to have locally sited data centres and, in terms of data security, for them to be ISO and payment card industry data security standard (PCI-DSS) compliant - both areas where Routed has met requirements.

It already segregates management networks from production networks, storage traffic from a host strategy, and even separates host traffic from public-facing web traffic. In addition, we have multi-factor authentication (MFA) in place and have been leveraging the principle of least access from the very beginning. Routed has been highly conscious of implementing security best practices on its infrastructure from the outset.

Moreover, while the company may have secured our back end, poor security measures further down the value chain, like leaving ports open on firewalls, are difficult to mitigate against. However, when it comes to issues of data resilience and data integrity, this requires that backup and replication products be available to assist in a disaster recovery scenario.

Ultimately, there is no one true definition of what data sovereignty is, but it will always entail data locality within sovereign borders, data security and data integrity.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Service robot technology for residential complexes
Suprema AI & Data Analytics Infrastructure Residential Estate (Industry)
Suprema has signed a three-party memorandum of understanding (MOU) with Hyundai Motor Group Robotics LAB and Hyundai Engineering & Construction (Hyundai E&C) to collaborate on advancing residential complexes through service robot technology.

Read more...
Genetec launches Cloudlink 2210
Genetec Infrastructure Surveillance
New cloud-managed appliance addresses the practical challenges when adopting a cloud-managed model at scale, including storage costs, support for devices that do not enable direct-to-cloud connectivity, and the need to maintain local operation during connectivity disruptions

Read more...
AI projects are failing at alarming rates
AI & Data Analytics Infrastructure
As organisations around the world accelerate their investments in artificial intelligence, digital transformation and data analytics, a growing number of industry experts are warning that many companies are still approaching these initiatives in fundamentally flawed ways.

Read more...
Understanding the Shared Responsibility Model
Infrastructure Security Services & Risk Management
While the cloud can certainly be a growth enabler in many ways, it can also introduce new security risks. Companies want to have a clear understanding of where their security duties end and where their cloud service provider’s begin.

Read more...
Cloud security in visitor management and access control
SA Technologies Access Control & Identity Management Infrastructure Residential Estate (Industry) Commercial (Industry)
Cloud has become the default platform for modern security operations, from visitor management portals and remote access control to incident logging, reporting, analytics, and integrations. But “in the cloud” does not mean “someone else is securing it for us”.

Read more...
New commercial and technical appointments at Veeam
News & Events Infrastructure
Veeam Software has announced two senior appointments in its South African business as it continues to invest in local market growth and partner and customer engagement.

Read more...
Access as a Service is inevitable
Technews Publishing SMART Security Solutions ATG Digital Access Control & Identity Management Infrastructure
When it comes to Access Control as a Service (ACaaS), most organisations (roughly 90% internationally) plan to move, or are in the process of moving to the cloud, but the majority of existing infrastructure (about 70%) remains on-premises for now.

Read more...
Privacy by design or by accident
Security Services & Risk Management Infrastructure
Africa’s data future depends on getting it right at the start. If privacy controls do not withstand real-world conditions, such as unstable power, fragile last-mile connectivity, shared devices, and decentralised branch environments, then privacy exists only on paper.

Read more...
Access trends for 2026
Technews Publishing SMART Security Solutions RR Electronic Security Solutions Enkulu Technologies IDEMIA neaMetrics Editor's Choice Access Control & Identity Management Infrastructure
The access control and identity management industry has been the cornerstone of organisations of all sizes for decades. SMART Security Solutions asked local integrators and distributors about the primary trends in the access and identity market for 2026.

Read more...
Protecting high-value data from AI
CASA Software Infrastructure Information Security Products & Solutions
As artificial intelligence accelerates the speed and sophistication of cyberattacks, protecting high-value data, such as financial records, legal files, patient data, intellectual property, and compliance records, has never been more urgent.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.