Data Sovereignty and Data Control 

16/07/2026
Sebastian Tietz

Sebastian Tietz, Chief Commercial Officer

Clarity in the Data Jungle of Cloud and AI 

Data control – and therefore data sovereignty – is not something organisations achieve once and then forget. It’s an ongoing responsibility. Powerful Software-as-a-Service (SaaS) platforms and AI applications make that responsibility more complex than ever. Even so, public sector organisations can maintain control, build trust and meet their compliance obligations.

Software-as-a-Service (SaaS) offers scalability, flexibility and lower upfront investment. Artificial intelligence (AI) can analyse, organise and generate information, helping organisations gain valuable insights while reducing manual effort. At the heart of both technologies lies data – whether that is sensitive citizen information, government data, or patient records in healthcare.

The key question is: who remains in control once that data leaves an organisation’s own infrastructure? Who is responsible when SaaS providers or AI models process information in public cloud environments? And, perhaps most importantly, who is accountable for protecting that data – the customer or the service provider?

In practice, the answer is neither simple nor absolute. It depends on how responsibilities are defined, how services are delivered and how security controls are implemented. Against the backdrop of an increasingly complex geopolitical landscape and the growing debate around European data sovereignty, public sector organisations need a clear understanding of where responsibility begins and ends – and how they can retain control over their data.

What is data control? 

Data control refers to the authority, responsibility and decision-making rights associated with data throughout its entire lifecycle. It is concerned not only with the legal question of ownership, but more importantly, with who controls how data is accessed, used and protected. In practice, this requires clear governance frameworks, well-defined contractual arrangements and appropriate technical controls.

Data control is therefore an operational concept, whereas data sovereignty is a broader strategic principle. Data sovereignty means that organisations retain effective control over their data regardless of where it is physically stored or processed. In Germany, technological and digital sovereignty are currently being advanced through initiatives such as the High-Tech Agenda Germany (HTAD) and the Federal Government’s modernisation agenda for government and public administration.

The cloud clouds the picture 

Whether in public administration, contact centres, or any other environment that handles sensitive information, SaaS applications offer flexible access and can scale rapidly to meet changing demand. They deliver continuous innovation through regular updates and typically require significantly lower upfront investment than traditional on-premises solutions.

At the same time, moving data to the cloud can make it less obvious who ultimately retains control over that information. The same applies to AI applications, which often process data in public cloud environments. While AI can generate valuable insights from large volumes of information, it also places greater demands on transparency, governance and clearly defined rules for data processing and retention.

Public sector organisations therefore need to establish clear policies governing how AI is used, which data it is permitted to process and how long that data is retained.

German public authorities and local authorities face a dilemma 

Public sector organisations face particular challenges when it comes to data control and data sovereignty. Many of today’s leading technology providers are headquartered outside Europe. As a result, the use of public cloud services from hyperscalers such as AWS, Microsoft Azure and Google Cloud often raises complex questions around European data sovereignty, regulatory compliance and jurisdiction.

At the same time, European sovereign cloud providers do not always offer the same breadth of services, global scale or commercial competitiveness as the largest hyperscalers. Public sector organisations therefore need to strike a careful balance between technological capability, regulatory requirements and the level of control they wish to retain over their data.

Transparency is the starting point 

Within this complex landscape, the first step towards achieving effective data control is understanding how, where and by whom data is stored and processed.

In principle, public sector organisations retain control over their data. In practice, however data is often processed across multiple SaaS platforms, AI services and cloud environments, creating a far more complex picture. The resulting ecosystem of software providers, cloud platforms and, in some cases, additional third-party service providers can be difficult to oversee. As complexity increases, so too does the challenge of maintaining clear responsibilities – particularly when it comes to data security and regulatory compliance.

Shared Responsibility: Who is accountable? 

One widely adopted approach is the Shared Responsibility Model. Under this model, the provider is responsible for securing the underlying infrastructure, including the cloud platform and the application itself. Public sector organisations, however remain responsible for areas such as identity and access management, data configuration and the security of integrations and interfaces.

This division of responsibilities is often misunderstood. If a configuration error exposes sensitive data, responsibility will generally rest with the public sector organisation rather than the provider. From a regulatory perspective, it is often of secondary importance whether the incident originated with the cloud provider or the service owner. The key question is whether each party fulfilled its respective security obligations. Where a provider has failed to meet its own responsibilities, it too may be subject to regulatory scrutiny.

Is data control a project or an ongoing process? 

Regulatory requirements have firmly placed data protection – and particularly the protection of sensitive information – at the top of the agenda. However, this is not something that can be addressed through a one-off project. SaaS platforms and AI applications are evolving continuously, introducing new capabilities and new risks.

As a result, data control and compliance must be treated as ongoing responsibilities rather than one-time initiatives. Organisations that can clearly demonstrate control over their data strengthen trust among regulators, partners and citizens, while reducing risk as SaaS and AI technologies continue to evolve.

What can public authorities and local authorities do now? 

Public sector organisations should establish effective data control through a combination of contractual safeguards, transparency and technical controls.

In practice, this begins with a clear understanding of contracts and responsibilities. Who is the data controller, and who is the data processor? Which sub-processors and cloud providers are used by the SaaS or AI vendor? How are data processing, retention and deletion managed, particularly when a contract comes to an end?

Alongside this, organisations should maintain a comprehensive map of their data flows. They need to understand where data is created, where it is stored, processed and replicated, which AI functions have access to which categories of information and which third-party systems and applications are integrated into the environment.

Implementing internal policies 

Building on this foundation, public sector organisations should establish clear security and AI governance policies. These should define who is permitted to access which data and how that access is protected, for example through centralised identity management, single sign-on (SSO) and multi-factor authentication (MFA).

Equally important are clearly defined roles and permissions, comprehensive audit logging, encryption of data both at rest and in transit and technical controls capable of automatically identifying and masking sensitive information where appropriate.

Where suitable, open-source software can also offer advantages because its source code is publicly available for independent review and security assessment. However, this should always form part of a broader security and governance strategy rather than being regarded as a security measure in its own right.

In addition, organisations should define clear data retention and deletion policies to ensure that information is kept only for as long as necessary. AI systems also require well-defined guardrails that specify which data may be processed, which use cases are permitted and how AI inputs, outputs and decisions are logged, documented and retained.

Working together towards a common goal 

Data control must be embedded across the entire organisation. As soon as individual departments begin adopting SaaS or AI solutions independently, isolated systems with their own data policies, permissions and retention rules can quickly emerge, creating blind spots in governance and reducing organisational oversight.

IT, security and governance teams should therefore be involved from the outset whenever new requirements are defined, providers are selected, deployment regions are chosen or AI capabilities are introduced.

At the same time, public sector organisations need clearly defined roles and responsibilities. Who approves new AI use cases? Who reviews software updates and new releases? Who is responsible for audits, compliance evidence and ongoing governance? Ultimately, effective data control can only be achieved when every department follows the same governance framework across all systems and applications.

 

What is the difference between data control and data sovereignty?

While data control is a practical, operational concept, data sovereignty represents a broader strategic objective at both political and organisational level. The aim is to ensure that sensitive data remains under the legal and operational control of the organisation responsible for it, regardless of where that data is stored or processed.

Data sovereignty also seeks to reduce dependencies on individual providers and avoid excessive vendor lock-in. This can be supported through measures such as open standards, data portability, interoperable architectures and where appropriate, the use of open-source software.

Why is data sovereignty important for Europe? 

The current debate at European level is being shaped by geopolitical tensions and developments in US legislation. Under frameworks such as the US CLOUD Act and the Foreign Intelligence Surveillance Act (FISA), US authorities may, under specific legal conditions, require US-based providers to disclose certain data – even where that data is stored in European data centres.