Data Sovereignty / Source date:

Sovereignty Requirements in RFPs Become Standard

Procurement templates started specifying hosting jurisdiction, support locations, and key custody explicitly.

Illustration of inspectors reviewing evidence at a secured equipment entrance, representing sovereignty procurement checks.

A year ago, questions about where data would live belonged in the legal annex. They were raised after a supplier had been selected, negotiated by lawyers, and settled in a data processing addendum nobody in the business ever read. In tenders issued this quarter they appear in the requirements section, with weightings attached. That shift is not fashion. Europe's new transfer clauses became mandatory for new contracts in September, China's personal information law took effect on 1 November, a federal data protection law was issued for the Emirates last month, and the Saudi law takes effect in the spring. Procurement teams are asking these questions because their own compliance colleagues are now being asked them. The problem is that most of the questions being asked are badly written. They are answerable with a yes by suppliers whose architecture would fail the buyer's actual requirement, and unanswerable by suppliers who are being precise.

The genre

Four questions appear in almost every template now in circulation. Where will our data be stored? Is your solution compliant with the General Data Protection Regulation? Do you transfer personal data outside the country? Please confirm that our data will remain within the Emirates. Each of them can be answered truthfully by a supplier who stores data in the requested country, administers the platform from three others, replicates backups to a paired region abroad, exports telemetry continuously, and holds every encryption key itself. None of those facts is a lie about storage location. All of them matter more than storage location. The second question is worse than useless, because no product is compliant with a data protection law — organisations are, through how they use products. A supplier that answers yes has told you nothing, and a supplier that explains the distinction looks evasive next to it.

Why bad questions are worse than no questions

Three failure modes, in rising order of cost. A scored yes becomes assurance. Once the answer sits in an evaluation record, your own file says the requirement was satisfied, and the next person to look at it — an auditor, a regulator, a customer conducting due diligence — reads a conclusion the architecture does not support. Precision is penalised. The supplier who writes we store data in the local region, administer it from two named countries, and can offer external key management in this region from the second quarter loses marks to the supplier who writes yes, fully compliant. Templates that reward confidence over accuracy select for the wrong suppliers systematically. And the real negotiation gets deferred. Sovereignty terms not settled before award are settled after a preferred bidder has been named, internal expectations have been set and the project has a start date — which is the moment your leverage is lowest and the supplier's is highest.

Ten questions that actually discriminate

None of these can be answered with a yes, which is the point. Name the legal entity that will contract with us, and the governing law of that contract. List every country in which our data will be stored, processed, or capable of being accessed — including backups, disaster recovery and test environments. From which countries can support, engineering and administrative staff reach production data or systems, and under what approval process? Provide the current sub-processor list with function and location, and describe how changes are notified and whether we can object. Who holds encryption key material, can we hold our own, and is external key management generally available in the specific region we are buying today? What is your documented process on receiving a lawful access request from an authority in your jurisdiction — who is informed, what is challenged, and what are you prohibited from telling us? What data leaves our tenant for telemetry, product analytics or abuse prevention, and can that be disabled? What are the exit terms: export format, timeframe, cost, and what evidence of deletion is provided? Which certifications and attestations cover the specific service and region we are purchasing, rather than the company as a whole — and may we see the scope pages? And finally: which of the answers above can you change without our consent? That last question is the most revealing in the set, and almost nobody asks it.

Ask for evidence a yes cannot supplyQualitative examples condensed from the article's tender questions. This is not a legal compliance determination.
Weak promptEvidence to request
Where is data stored?Storage, processing, backup and access countries
Is the product compliant?Service-specific architecture, commitments and attestation scope
Does data leave the country?Support access, telemetry and subprocessor functions
Will data remain here?Change rights, exit terms and contract representations

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

Score constraints and criteria separately

Two different things get muddled into one requirement line. Mandatory constraints derive from a written rule — a central bank circular, a classification scheme, a government contract term — and should be stated as a pass or fail condition with the source cited. Everything else is an evaluation criterion, weighted, scored on the quality and verifiability of the answer. The bar for scoring should be documented and verifiable, not maximal. A supplier who provides an architecture diagram, a sub-processor list, a regional service availability statement and the scope page of an attestation should outscore one who asserts more and evidences nothing. And the answers should be incorporated into the contract by reference, as representations. An unbinding answer in a spreadsheet is a marketing statement; the same answer attached to the agreement is a remedy.

If you are the one answering

Three answers create liability, and all three are common. An unqualified no to whether data leaves the country, when support staff elsewhere can access it. A claim of compliance with a named law, which is not a property a product can have. And a commitment that data never leaves a region, made by someone who has not checked what the disaster recovery configuration does. The better technique is to answer with the architecture, the caveats and the commitment separately: here is where data sits, here is who can reach it and from where, here is what we will commit to contractually, and here is what we cannot commit to. Suppliers fear that precision loses deals. In competitive technical evaluations it usually wins them, and it certainly prevents the more damaging outcome — a customer discovering in year two, during an audit, that the pre-award answer was wrong.

Practical Guidance for Procurement Template Review

  • Replace yes-or-no sovereignty questions with ones that require a named country, entity or process.
  • Separate mandatory constraints from scored criteria, and cite the rule behind every mandatory line.
  • Require evidence with the answer — diagram, sub-processor list, certificate scope page, regional availability statement.
  • Ask what the supplier can change without your consent, and make material changes a notification-and-objection right.
  • Incorporate pre-award answers into the contract as representations rather than leaving them in the evaluation file.
  • Settle sovereignty terms before naming a preferred bidder, while you still have leverage.
  • Ask about the specific region and service, never the company, when requesting certifications.
  • Keep the questionnaire short and sharp; ten answerable questions beat eighty that invite copy-paste.

The Regional Angle

Three adjustments make this work for a group operating from the Gulf, and the first saves the most wasted effort. Suppliers here divide into two populations, and sending the same questionnaire to both is why procurement teams conclude the exercise is pointless. Global platforms will not negotiate: you will receive a link to a trust centre, a standard addendum and a polite refusal to amend. Regional integrators, hosting providers, outsourcing firms, managed service providers and bespoke development shops will negotiate almost everything, and frequently have never been asked these questions by anyone. Spend the procurement effort on the second group, where the answers change outcomes and the contract can be shaped. For the first group, the work is not contractual at all — it is configuration: which region the tenant is created in, which optional data flows are disabled, whether external key management is available where you bought, what the default storage location is set to, and which administrative roles exist. Those decisions are made once, at signup, often by whoever ran the trial, and they are irreversible in practice. A procurement process that negotiates hard with the small local supplier and clicks through the global one has spent its energy exactly backwards. The second is about how purchasing actually happens in regional groups. A great deal of it is relationship-led: the chairman knows the vendor's principal, a decision is taken over a meeting, and the tender document is produced afterwards to formalise something already agreed. A sovereignty questionnaire embedded in the tender template therefore arrives too late to influence anything. The fix is unglamorous and effective — move the questions into vendor onboarding, which every group already operates because finance needs a trade licence, bank details, tax registration and insurance certificates before a supplier can be paid. Add four of the ten questions to that pack. It is the one gate that even a relationship-led purchase must pass through, and it catches the supplier at the moment it wants to be set up for payment. The third is timing, and it is specific to this month. The Saudi law takes effect in the spring; executive regulations for the new Emirati law are expected during next year; and implementing rules for China's regime are still being issued. Any three-year agreement signed now will outlive the rules it was drafted against. Put a change-in-law mechanism in every material contract — not the boilerplate version that merely allows the parties to discuss, but a right to require relocation, reconfiguration or additional safeguards within a defined period at no penalty, and a termination right if the supplier cannot deliver. Suppliers will accept this far more readily in December than they will after the regulations are published and the demand arrives from every customer at once.

The objection worth taking seriously

The strongest objection is that questionnaires are theatre. Nobody reads the answers properly. Suppliers maintain a library of responses and paste them in. Adding ten questions to a template lengthens a process that internal stakeholders already route around by buying with a card and asking for reimbursement. Real protection comes from architecture and contract terms, not from a scored spreadsheet, and procurement teams are not equipped to evaluate technical answers about key custody or management planes anyway. Most of that is accurate, and long questionnaires are a well-documented way to generate paperwork without changing anything. The value, though, is not in the answers. It is in three side effects. The first is disqualification: a supplier who cannot name its own sub-processors or say where its support staff sit has revealed something about its maturity that no reference call will surface. The second is the record — once answers are incorporated as representations, a later discovery that they were wrong is a contractual matter with a remedy rather than a disappointment. The third is the mirror. A template cannot ask a question the organisation has not decided it needs answered, so writing the template forces the buyer to state its own requirements, which is usually the first time anyone has. Organisations that revise these documents almost always find their real problem was internal ambiguity rather than supplier evasion. So make the questionnaire shorter, sharper and binding, and accept that its main audience is you.

Common Questions

How many sovereignty questions should a tender contain?

About ten, each requiring a specific factual answer, with evidence requested. Beyond that, response quality falls faster than information gained.

Should hosting location be a pass or fail requirement?

Only where a written rule requires it. Otherwise it eliminates suppliers on a proxy rather than on the control you actually need.

What if a supplier refuses to answer?

Record the refusal and score it. For a small negotiable supplier it is usually disqualifying; for a global platform it tells you the work is configuration rather than negotiation.

What should we expect over the next twelve months?

Expect the Saudi law taking effect in the spring and the Emirati executive regulations to make these questions mandatory rather than optional in regional tenders, including in the private sector. Expect the major platforms to publish structured answer packs and regional data flow documentation precisely because the same questions are arriving from everyone. Expect the locally operated sovereign cloud model to appear in regional tender language as a specified option, ahead of it actually being available. And expect a wave of contract renegotiations next autumn, driven by agreements signed this year against rules that had not yet been written — which is the argument for putting the change-in-law clause in now.


Procurement Template Review — we rewrite the sovereignty section of your tender and onboarding documents into questions that discriminate, bind the answers into the contract, and put the effort where it changes the outcome.

Continue reading

Talk to OPS

Start with the operating problem.