The General Data Protection Regulation (GDPR), introduced by the European Union in 2018, is considered the most far-reaching regulation in the field of data privacy and has inspired more than a hundred countries (the count was 145 in September 2021)1 to adopt similar laws. New legislation regarding data sovereignty could have an even greater impact on your business operations, especially if effective data management strategies and tactics have not been implemented.
Data sovereignty is the legal concept that data is subject to the sovereign laws within which it is collected and stored. For example, imagine you buy a pair of running shoes from a Dutch online store called Rotterdam Runners. The collection, ownership, and use of the data generated by the online purchase are subject to both Dutch and EU data sovereignty regulations. These rules protect privacy by preventing unauthorized entities from accessing the data.
Next, let's assume Rotterdam Runners has an online webshop on a Public Cloud infrastructure, where they—like nearly two-thirds of all European Public Cloud users—use a Public Cloud from a US-based company. US data and communications companies are subject to the 2018 U.S. CLOUD Act, which stipulates that companies must be able to provide stored customer or subscriber data upon court order, from any server they own or manage—regardless of the physical location of that server.2 So, even if the server of the American Public Cloud provider hosting the Rotterdam Runners website is located in Amsterdam, it no longer complies with EU data sovereignty rules due to this U.S. CLOUD Act.
Public Cloud and data sovereignty rules therefore seem to be at odds. However, it is not necessary for companies like Rotterdam Runners to make the drastic decision to stop using Public Cloud services.
Not all data is equal, and some data is not subject to privacy legislation. For this reason, it is good to classify data to see which data requires which level of protection. According to Carnegie Mellon University guidelines, data can be divided into three categories3:
- Public – open data for general use, not subject to privacy regulations.
- Secret – highly confidential data, administrative data, top-secret and state secrets that require the highest level of security and are usually subject to strict regulations.
- Confidential – data subject to privacy rules, such as personally identifiable information (PII), business data, and intellectual property. This is often the default choice for data not explicitly classified as public or restricted.
Based on these three data categories, the Public Cloud seems ideal for public data, such as the public part of the Rotterdam Runners website or inventory data. Only the storage of confidential data in the Public Cloud, such as your address and payment details, causes problems for Rotterdam Runners regarding data sovereignty and privacy.
How can organizations like Rotterdam Runners and your own collect and use confidential data while remaining compliant with local data sovereignty rules? One option is a Private Cloud. A Private Cloud is managed by and owned by a single organization, with data stored on local servers. However, managing and owning various local data centers is costly and complex, especially for multinational organizations. And smaller businesses, like Rotterdam Runners, often lack the IT staff to maintain their own Private Cloud.
Another option is a sovereign Cloud. This can be seen as a semi-private Cloud that combines the best functionality of a Public and Private Cloud. Sovereign Clouds are smaller, multi-tenant environments managed by an experienced, local Cloud provider. They comply with local data storage and data sovereignty rules without the overhead and complexity of owning and managing your own local data centers.
Because all data—including metadata—is kept locally in a sovereign Cloud, only local law applies and foreign powers have no access. This way, your organization has total control over its data. Furthermore, a sovereign Cloud makes data migration to other countries easier, a topic that will be covered later in this series.
This series consists of four blog articles: we will post a new one every week.
- Global Data Privacy Laws 2021: Despite COVID Delays, 145 Laws Show GDPR Dominance – Pg3, SSRN, Graham Greenleaf, University of New South Wales, Faculty of Law, September 2021
- Wikipedia, Cloud Act, August 2022
- Carnegie Mellon University, Guidelines for Data Classification, February 2021