Public authorities, organizations and companies are having to address the sovereignty of data as part of digital sovereignty – not least given the dependence on global cloud providers and stricter regulatory requirements. In terms of digital work environments, managers need to be asking where they should store their sensitive data. Many rely on European data locations. But to achieve data sovereignty, they also need to know whether content is technically readable, who controls the keys and which functions are available for roles, rights and traceability.
A cantonal authority is preparing a new support programme. Several teams work on applications, internal evaluations and contract documents. External experts need to examine individual documents, legal counsel accompanies the process, and a research partner provides additional assessments. A cloud-based application is to be used for collaboration. When choosing the right solution, the data location is an obvious first criterion for the authorities. The data is to be stored in Switzerland or another European country – in accordance with the protection requirements relating to sensitive information and the directives applicable to the public authority.
Many organizations take a similar approach when testing cloud applications. A data location in Switzerland or Europe gives you a sense of having enough security. It helps to meet regulatory requirements and internal guidelines, and, in turn, establishes an important foundation. But location alone isn’t enough for secure data storage.
Location alone doesn’t provide control
The jurisprudence of a provider also plays a significant role. The storage location and provider’s jurisdiction don’t necessarily have to be the same. Even if data is stored in Switzerland or another European country, an international provider may be subject to a different legal system, resulting in official access or disclosure rights.
The CLOUD Act is often referred to in relation to data sovereignty. It allows US law enforcement agencies to require, on the basis of court orders, the disclosure of data from cloud and communications service providers that are subject to US jurisdiction – even if the data itself is stored outside the US.
Organizational and contractual measures can limit this risk, but don’t exclude a disclosure obligation.
A cloud application and the underlying cloud infrastructure need to be considered separately, which means US cloud infrastructure may also be relevant when using a European provider. The data that each provider could actually read and potentially release depends on the form in which it has this data and who controls the keys needed for decryption.
The key question: who can read the data?
The confidentiality of sensitive content depends on who can access readable content or the cryptographic keys along the processing chain. This aspect isn’t just relevant for government disclosure requests. Technical architecture is also key in cyberattacks on cloud applications and the underlying cloud infrastructure – a common risk today. It determines whether stolen content can actually be read by attackers.
The public authority needs to ask a second question during the selection process. Who could access readable content? It’s here where we clearly see the difference between data residency and technical data control.
Control comes from architecture
Appropriate encryption and key management designed according to the zero-knowledge principle are interlinked when it comes to restricting access to readable content from a technical perspective:
- Appropriate encryption protects the content by ensuring that only authorized recipients can decrypt and read the data.
- With the zero-knowledge principle, key management is designed in such a way that the provider doesn’t have access to the cryptographic keys required for decryption. This prevents them from viewing the content saved in the cloud in unencrypted form.
The public authority has now opted for a digital working environment that combines cooperation and data sovereignty. The project manager establishes a protected working area for the support programme and involves internal teams, external experts and legal counsel with appropriate rights. Applications, evaluations and draft contracts are not only stored there, but also reviewed, shared and processed without circulating uncontrolled via e-mails, local copies or open links.
The solution encrypts content on authorized users’ devices before it’s transferred. If an external body requests data from the provider, the provider cannot issue readable content as the keys required for this are not available to them
Data governance and ease of use make control suitable for everyday use
The fact that the provider can’t read content doesn’t answer all the questions in the everyday life of a project. As soon as authorized persons work together, clear rules for control, responsibility and traceability are required. Organizations need be able to decide who’s allowed to see, edit or share which information, how approvals are granted and how accesses can be checked. They also have to be able to make granular changes to these rules in line with roles, project phases and protection requirements. And the solution has to be easy to use so that secure processes are actually applied in everyday working life and users don’t switch to unsecure workarounds.
Based on the technical principles of end-to-end encryption and zero knowledge, role models, approval processes, traceability and ease of use ensure that data sovereignty can be implemented in everyday working life. They allow you to have specific control over internal and external accesses, place time restrictions on the validity of rights, revoke permissions if necessary and document activities in a traceable manner. These functions make accesses auditable and support data governance.
In the support project, the external expert is given access to selected applications only. Legal counsel works exclusively with contract documents, and the research partner can only view and process certain project data. As soon as the audits have been completed, the authority revokes external rights and can then use logs to determine which accesses and activities have taken place.
To sum up
A data location in Switzerland or another European country creates trust and helps to meet regulatory requirements and internal directives. But the sovereignty of data doesn’t stop once it leaves a data center. It depends on who can read content, who controls keys and how accesses are controlled in everyday life. Organizations that handle sensitive data in digital processes shouldn’t just be interested in the storage location. How encryption, key control and access control is implemented in technical terms is equally important. It’s only then that a data location promise leads to genuine data control.
How do you keep control of sensitive data when teams, external partners and service providers work together?
Find out how Tresorit, a Swiss Post company, supports secure collaboration and data sovereignty by design – with data residency in Switzerland or another European country, zero knowledge, end-to-end encryption and features that make compliance and auditable data governance easier.
