Data Sovereignty
What is Data Sovereignty?
The concept that data is subject to the laws and governance structures of the country in which it is collected, stored, or processed.
Terms that appear alongside data sovereignty
Each of these is named in at least one of the same controls as data sovereignty. The number is how many controls name both.
- data protection 6 shared controls
- sub processor 5 shared controls
- certification 5 shared controls
- encryption 4 shared controls
- consent 4 shared controls
- gdpr 4 shared controls
- transparency 4 shared controls
- audit 4 shared controls
Frameworks that govern data sovereignty
What the standards actually require on data sovereignty
Requirements naming data sovereignty across 6 standards, quoted from the control text.
Article 12 of the Kazakhstan PDPL establishes the data localization requirement for biometric personal data of Kazakhstan citizens and residents - a key sovereignty provision strengthened by the 2022 amendment.
KZ-PDPL-Biometric-Data-Localization-Article12-Server-Kazakhstan-On-Soil-Data-Storage-Citizens-Residents · Kazakhstan PDPL Biometric Data Localization + Article 12 + Mandatory Server Storage in Kazakhstan + 2022 Amendment + Citizens + Residents + Foreign Cloud Provider Restrictions + Data Sovereignty + State Service for Information Security Oversight →Data sovereignty and cross-border movement of sensitive data are recorded, auditable and controlled in accordance with defined policy.
CDMC-KC4 · Data Sovereignty and Cross-Border Movement →Sets the principle of data transfer (Art.18), the required level of protection in third parties (Art.19), conditions for cross-border transfer (Art.20), safeguards prior to cross-border transfer (Art.21) and data sovereignty considerations (Art.22).
ETH-PDPP-Art.18-22 · Cross-border transfer and data sovereignty →Third-Party + Outsourcing + Cloud Service Provider cybersecurity is critical per FSA Cybersecurity Guidelines + FISC Cloud Guidelines (FISC Anzen Taisaku Kijun - Cloud Computing Edition). (1) Outsourcing Governance: (a) Outsourcing Policy + Board Approval;
JP-FSA-CYB-Third-Party-Outsourcing-Cyber-Risk-Cloud-Service-Provider-Due-Diligence-Audit-Right-Sub-Processor-Visibility-Concentration-Risk · Japan FSA Cybersecurity Third Party + Outsourcing Cyber Risk + Cloud Service Provider Due Diligence + Audit Right + Sub-Processor Visibility + Concentration Risk + Data Sovereignty + ISMAP Certification + FISC Cloud Guidelines →Agencies must ensure government data stored in cloud environments meets data residency and sovereignty requirements.
IM8-CLD.4 · Cloud Data Sovereignty →Per CSAP: domestic data storage + sovereignty per Korean law + restrictions on cross-border.
KRCSAP-3 · Data Sovereignty, Domestic Storage →Questions people ask about data sovereignty
What is Data Sovereignty?
Why is Data Sovereignty important for compliance?
Which compliance frameworks address Data Sovereignty?
Where can I learn more about Data Sovereignty?
See how Data Sovereignty applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.