Every data sovereignty programme written before this year rests on an assumption nobody thought to write down: that data has a location because people have a location. The records sit in a system, the system sits in a data centre, the people who touch it sit in an office, and the office sits in a country. From that chain you could draw a map, sign a hosting statement and answer an auditor. Five months of dispersed working has broken every link in that chain, and the result is that most organisations are operating a sovereignty position they can no longer evidence. Not a worse one, necessarily. An unknown one.
What the map no longer shows
Walk through it honestly. The workforce accesses systems from several hundred homes, some of them in different countries from the entity that employs them. Support and administration are being delivered remotely by people who used to be escorted into a server room. Departments bought software in April with a corporate card because the alternative was not working, and each of those tools has its own hosting arrangement and its own list of sub-processors. Meeting recordings and transcripts are accumulating in whichever region the platform defaulted to. Board papers and payroll files have been exported, mailed, printed and stored on devices in residential buildings. Health information about employees has been collected at a scale no privacy notice anticipated. None of that appears on the data flow diagram produced for last year's audit, which is a picture of buildings. The reckoning is not that the rules changed. It is that sovereignty was being managed as a procurement attribute — where is the server — when it was always an operational question about who touches the data, from where, under whose law, and what happens if that access is withdrawn.
Four surfaces, and hosting is only one
The practical fix is to stop asking one question and start asking four, for each significant system and data category. Where does it rest. The traditional question: storage location, backup location, replica location, and the location of the logs and metadata, which is routinely different and routinely forgotten. Who can reach it. The access path: which named people and which third parties can technically retrieve the data, from which countries, through which support and administration channels. This is where five months of change has concentrated, and it is the surface almost nobody has re-examined. Who can compel it. Legal reach: which authorities can require disclosure, directly or through the provider's parent company, and what your provider commits to doing when they ask. Hosting location influences this and does not determine it. What happens if it stops. Operational continuity: whether you could keep running if a provider, a route or a licence became unavailable, and how long the switch would take. This is the surface the year has actually stress-tested, and it belongs in the sovereignty conversation rather than being parked in business continuity. A programme that bought only the first surface has purchased an answer to the least interesting question.
The category that did not exist in January
Employee health data is the genuinely new problem, and it is being handled worse than anything else. Since March, employers have been recording temperature readings at entrances, collecting test results, taking travel and contact declarations, running symptom questionnaires and maintaining lists of cases and close contacts. Most of this lives in spreadsheets held by facilities and human resources, or in an application procured in a fortnight, with no retention rule, no access restriction beyond a shared folder, and no privacy notice that honestly describes it. It is the most sensitive category of personal data most organisations have ever held about their staff, it was collected under emergency conditions, and it will still be there in three years unless somebody decides otherwise. Give it an owner, a lawful basis written down, a minimum access list, a retention period and a deletion date. That single exercise will do more for your privacy posture than another hosting review.
Re-survey the facts before you rewrite the policy
The instinct after a disruption is to reissue the policy. Resist it. The policy is probably fine; the facts underneath it are wrong. A six-week exercise is enough. Establish where people are actually working and under which entity's contract. List the tools adopted since February and who is contractually behind each one. Identify every category of data now being accessed from outside its original jurisdiction, including by support staff and administrators. Find the health data. Find the exports: the reports that leave the system every week and land in someone's mailbox. Then record a position for each significant data category — acceptable, acceptable with conditions, or not acceptable — with a named owner and a date. Positions with owners survive staff changes. Principles do not.
| Surface | Facts to re-establish |
|---|---|
| Rest | Primary, backup, replica, log and metadata destinations. |
| Reach | Named people, support parties and access locations. |
| Compulsion | Contracting/control entities and disclosure commitments. |
| Continuity | Tested recovery, export and substitution arrangements. |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Practical Guidance for Data Sovereignty Strategy
- Rebuild the data map around people and access paths, not buildings. The question is who can reach it from where, and the answer changed in March.
- Inventory every tool adopted since February, with its contracting entity and sub-processors. Emergency purchases are now permanent infrastructure whether or not anyone decided that.
- Treat employee health data as its own category with an owner, a basis, a retention period and a deletion date. It is the highest-sensitivity data you acquired this year and the least governed.
- Include logs, backups, metadata and recordings in the location analysis. They are frequently in a different region from the production data and are what an inspection actually asks for.
- Add continuity to the sovereignty assessment. How long to move, at what cost, with what data loss, is a board-relevant number and nobody has it.
- Ask providers what they do when an authority asks, in writing. Notification commitments, challenge procedures and transparency reporting matter more than a data centre postcode.
- Regularise the paperwork behind the emergency adoptions. Processing terms, security schedules and authorised signatures, before renewal removes your leverage.
- Record a position per data category with a named owner. Not a principle, a decision, with a date on it.
The Regional Angle
Four things here deserve separate treatment. First, the direction of the sovereignty question inverted this year. The standard regional concern is foreign access to local data. What actually happened since March is that employers across the Gulf were required to disclose employee information to domestic authorities: case reporting to health ministries, staff lists for testing programmes, registration of workers on national applications, and identity details submitted for movement permits during curfew periods. Some of that was a legal requirement, some was a condition of operating, and almost none of it was assessed, documented or disclosed in a privacy notice. If your organisation transmitted employee health or identity data to a government platform this spring, that is a processing activity with a legal basis, a recipient and a retention question, and it belongs in your records whether or not anyone asked you to put it there. Second, there is a notification backlog building with the sector regulators. Banks, insurers, healthcare providers and telecommunications operators in the region generally have to notify or obtain approval before outsourcing services or placing data with a third party, and in March a great many of them adopted cloud collaboration, remote access and conferencing services without going near that process, entirely reasonably. The supervisors were accommodating at the time. They are now returning to normal inspection cycles, and "we did it in the emergency" is a defensible explanation exactly once. Compile the list of arrangements that should have been notified, regularise them in a single submission, and do it before the inspection rather than during it. Third, look at how the emergency purchases were actually contracted. A large share of the tooling adopted this spring in regional groups was bought online, on a corporate or personal card, under click-through terms, by someone without signing authority, from a vendor with no local entity and no Arabic-language contract. There is frequently no processing agreement, no security schedule, no agreed jurisdiction, and no record of who accepted the terms. Renewal season is the moment to fix that, and it is worth doing early: negotiating terms with a supplier you are already fully dependent on is a weak position, and it gets weaker every month. Fourth, note the divergence opening inside single groups. A financial free zone entity is now subject to a data protection regime that came into force in July, another sits under a separate free zone framework, the onshore companies fall under sector rules and general law, and the Saudi entity answers to its own requirements — while all of them share one email tenancy, one file server and one human resources system, because that is what the last five months pushed everyone towards. Consolidated platforms and divergent obligations are a genuinely hard combination. The answer is usually not four platforms; it is knowing which data belongs to which entity and being able to segregate access and export on demand.
The objection worth taking seriously
The strongest objection is that 2020 argued against the sovereignty case rather than for it. The global platforms absorbed an unprecedented surge and kept working. Organisations that had moved to them carried on; organisations running their own infrastructure spent March discovering that their gateways were undersized and their backup windows had disappeared. Meanwhile a good deal of what is marketed as sovereignty is straightforward protectionism with a compliance vocabulary, sold by providers whose real advantage is a local sales office. That objection is right about capability and wrong about exposure. The same year that demonstrated the operational superiority of the hyperscale platforms also produced a judgment in July that invalidated the principal legal mechanism for transferring European personal data to the United States, and left every organisation using those platforms to construct its own justification. Competence and legal exposure are separate variables, and this year moved them in opposite directions. The workable discipline is to separate the three reasons anyone cares. Law, which is enforceable and should drive spend. Resilience, which is measurable and should drive architecture. Politics, which is real but should be recognised for what it is rather than smuggled into a risk register. Programmes that keep those three apart tend to produce defensible decisions. Programmes that blend them produce expensive local hosting and an unanswered question about who can actually reach the data.
Common Questions
Do we need to move data back into the country?
Usually not. Establish which obligations actually require in-country residency, which require control and notification, and which require nothing beyond documentation. The three are different and are constantly conflated.
How do we handle staff accessing systems from another country?
Establish the facts first, then decide. Remote access from abroad is a real transfer of data and frequently a tax and employment question as well, so the assessment needs more than the IT team in the room.
Is employee health data really our problem once the pandemic ends?
Yes. Retention outlives the emergency, and an unexplained archive of health records is precisely the finding that turns a routine audit into a difficult conversation.
What should we expect over the next twelve months?
Expect European guidance on supplementary measures for international transfers before the end of the year, and a wave of contract renegotiation once it lands. Expect further regional legislation, with the financial free zone regime moving into active enforcement from the autumn. Expect supervisors to begin asking what was adopted during the emergency and under what authority. Expect employee health data to become an audit theme. And expect at least one major provider to announce additional in-region capacity and to present it as an answer to questions that hosting location does not settle.
Data Sovereignty Strategy — we re-establish the facts after five months of improvisation, then set defensible positions across residency, access, legal reach and continuity.
