The complexity of data sovereignty in a multi-polar world

Issue 6 2023 Infrastructure


Andrew Cruise.

“The importance of data sovereignty and security creates complexity in a world where sharing such information across borders generates huge social and economic benefits,” says Andrew Cruise, Managing Director of Routed. It is clear that in the digital age, data sovereignty is becoming more important, as data is increasingly generated and collected through a variety of channels, including e-commerce, social media platforms and mobile devices.

Essentially, data sovereignty is a phrase that describes the principle that a country has the authority and right to govern and control the data generated within its borders. Thus, the concept of data sovereignty gives governments the power to regulate the collection, storage, processing, and distribution of any data that originates within their borders.

Obviously, this will have an impact on cross-border data flows and international data-sharing agreements. Remember that different countries adopt different data sovereignty policies, but broadly, they are about demanding that data generated within the country be kept within the borders for security or regulatory purposes.

Complicating the situation is the recognition that data access and the sharing of such information across borders generates social and economic benefits of somewhere between 2,5% and 4% of GDP. In addition, data transfers of this nature also enable a wide variety of other critical activities, such as the sharing of essential information related to crime prevention, scientific research and innovation, anti-fraud and money-laundering activities, disaster management and even climate change.

It is worth paying close attention to data sovereignty, not only from the point of view of safeguarding private data, but also to avoid liability issues related to legal violations associated with a failure to protect personal information.

A major reason for the complexity around data sovereignty is that the laws governing it vary greatly from country to country, as do cloud service providers’ agreements concerning privacy policies and user rights. Therefore, organisations operating across multiple countries or regions must understand each country’s regulations to comply with all applicable laws.

In fact, ultimately, there are multiple differing definitions of exactly what constitutes ‘data sovereignty’, and it is vital that we obtain some form of industry-wide collaboration in defining and upholding the principles of data sovereignty.

Recognising the complexities of data sovereignty, VMware notes that the answer lies in sovereign cloud deployment, as this is an option that is inherently more secure and offers better data integrity and data assurance.

To this end, VMware is making efforts to promote Sovereign Cloud Partnerships and the criteria they use to select providers, but at the same time, it seeks to limit the number of providers in each region - thus ensuring the rarity of the ‘cloud sovereignty’ badge.

Among VMware’s requirements are for such service providers to have locally sited data centres and, in terms of data security, for them to be ISO and payment card industry data security standard (PCI-DSS) compliant - both areas where Routed has met requirements.

It already segregates management networks from production networks, storage traffic from a host strategy, and even separates host traffic from public-facing web traffic. In addition, we have multi-factor authentication (MFA) in place and have been leveraging the principle of least access from the very beginning. Routed has been highly conscious of implementing security best practices on its infrastructure from the outset.

Moreover, while the company may have secured our back end, poor security measures further down the value chain, like leaving ports open on firewalls, are difficult to mitigate against. However, when it comes to issues of data resilience and data integrity, this requires that backup and replication products be available to assist in a disaster recovery scenario.

Ultimately, there is no one true definition of what data sovereignty is, but it will always entail data locality within sovereign borders, data security and data integrity.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Cyber resilience – protect, defend, recover
Infrastructure
The challenge with AI is that threats are getting harder to detect. As a result, plans in 2024 are not just about detection and prevention, but about recovery.

Read more...
Powering business resilience and field operations
Infrastructure Products & Solutions
[Sponsored] The Anker 757 Portable Power Station emerges as a strategic asset for businesses looking to overcome power instability and the demand for operational efficiency in remote and field-based environments.

Read more...
Top bets for backup and business continuity
Infrastructure
Become your organisation’s data pioneer and spearhead data governance and protection of critical data. Challenge why best practices are not adopted or in place, while highlighting the inherent risks this poses.

Read more...
Next-gen solar-powered switches
Infrastructure
Duxbury Networking has introduced its range of solar unmanaged switches, which are ideal for any environment requiring reliable Power-over-Ethernet (PoE) capabilities, such as IP phones, cameras, and access points.

Read more...
Navigating South Africa's cybersecurity regulations
Sophos Information Security Infrastructure
[Sponsored] Data privacy and compliance are not just buzzwords; they are essential components of a robust cybersecurity strategy that cannot be ignored. Understanding and adhering to local data protection laws and regulations becomes paramount.

Read more...
Creating a cybersecurity strategy in a world where threats never sleep
Information Security Infrastructure
[Sponsored Content] The boom of Internet of Things (IoT) technology and the chaos that surrounded the sudden shift to work-from-home models in 2020 kick-started the age of cybercrime. In that period, incidents rose by 600%, affecting every industry and showing no signs of slowing down.

Read more...
Gallagher Security’s achieves SOC2 Type 2 recertification
Gallagher News & Events Integrated Solutions Infrastructure
Gallagher has achieved System and Organization Controls (SOC2 Type 2) recertification after a fresh audit of the cloud-hosted services of its integrated security solution, Command Centre. The recertification was achieved on 21 December 2023.

Read more...
Cyberattacks the #1 cause of business outages
Editor's Choice Information Security Infrastructure
The latest survey by Veeam Software shows that 92% of organizations will increase their spending on data protection by 2024 to achieve cyber resilience due to continued threats of ransomware and cyberattacks.

Read more...
Nology races to end 2023
Editor's Choice News & Events Infrastructure
Nology ended 2023 with an event highlighting its various products and services to the local market, followed by a few laps around the Kyalami Indoor Karting track.

Read more...
Cybersecurity integrated with data protection
Technews Publishing News & Events Infrastructure
Last year's VeeamOn Tour conference in South Africa was a smaller version of the annual global Veeam conference, aimed at the company's regional partners and customers.

Read more...