GDPR
What is data sovereignty?
Data sovereignty refers to the legal and jurisdictional control that applies to data based on where it is stored, processed or accessed. It determines which laws and regulations govern the data and what requirements apply to how it is handled.
Data residency describes where data is geographically stored, while data sovereignty also considers the legal jurisdiction, access controls and service providers involved in handling that data.
This is particularly relevant for organisations using international cloud services, where data may be stored in one country and accessed or processed from another. Organisations need to consider where their data is stored, who can access it and whether personal data is transferred across borders.
Under the GDPR, personal data can be transferred outside the EEA when the applicable requirements are met. Depending on the circumstances, this may involve an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules or another permitted transfer mechanism.
Data sovereignty therefore involves more than choosing where data is hosted. It also requires understanding the jurisdictions, access arrangements and transfer rules that apply to the data.
Türkçe
English