Changing geopolitical pressures and the resultant regulatory demands have steadily driven interest in sovereign clouds, as enterprises pay increasing attention to where their data resides. Localised cloud environments are becoming ever more essential as regulations place complex restrictions on which jurisdictions organizations can use to store their data in order to meet compliance requirements and provide risk mitigation. Yet without data portability, sovereign clouds are just blue-sky thinking.
In reality, moving data across hybrid environments is no easy task. It shouldn’t be driven purely by regulation – it needs to be embedded into day-to-day operations. Primary data can’t simply be moved to meet specific requirements; it must also be sufficiently protected while addressing where all related data, such as backups and Large Language Model (LLM) training data, will sit. After all, nothing works in isolation. So while data sovereignty is becoming increasingly important for organizations to meet today’s pressures, the overall focus should always be on data resilience first, no matter where in the world it’s stored.
Sound familiar? The cloud undoubtedly gives businesses more options and flexibility, but to take proper advantage of this, it will require deeper work.
What’s on the horizon?
Across the globe, regulators are driving organizations to look at their data differently, with new requirements appearing at breakneck speed in response to increasing data globalization, as countries try to get a better grasp on their data. The European Union (EU) is especially ahead of the curve with the General Data Protection Regulation (GDPR), which stipulates data sovereignty. The chain of custody of data is also under scrutiny in the EU, with both the NIS2 and DORA regulations demanding robust risk management for data, especially when held or handled by third parties.
With data, including highly sensitive and classified information, increasingly being handled by third parties (namely cloud providers) keeping it bound under privacy laws has become a priority for both organizations and governments as their data moves across the globe.
The increased movement of data between countries, and even continents, has brought global instability concerns to the forefront when securing data, with governments treating it as a top consideration. Some have already adopted sovereign clouds to protect their most sensitive data from potential malevolent access. Many have taken it one step further: with cloud services completely reliant on data centre infrastructure, some governments have begun to divest their interests in foreign cloud and data infrastructure, reinvesting instead in their own. This way, they can avoid storing their most sensitive data with foreign providers.
Of course, there’s no cure-all with cloud sovereignty. For those utilising multinational cloud providers, there might be the option to stipulate where data is ultimately stored and which countries’ laws it will be held under, but there is no guarantee that this won’t change. The issue isn’t solved merely by relocating the primary data. It must be protected, certainly, but what about all of the related data? As mentioned above, backups and Large Language Model training datasets, for example, all need to be carefully considered to meet data sovereignty.
A new weather front moving in?
To do any of this, organizations need to centre data portability in their data resilience planning. There’s a fine line between protecting data and inadvertently restricting it beyond the point of use, so organizations must tread carefully. If data portability isn’t achieved, then moving to a hybrid cloud environment to take advantage of both sovereign clouds and localization of data storage becomes a pointless endeavour.
Specialist Backup as a Service (BaaS) and Disaster Recovery as a Service (DRaaS) providers can simplify the process of maintaining portability and compliance, but it’s not a task that can be completely offloaded to a third party. Organizations still need to take a hands-on approach, planning and managing it thoroughly to ensure that data remains secure throughout. Otherwise, they will be unable to utilise sovereign clouds to adhere to the growing range of data residency and sovereignty regulations without compromising data resilience.
It’s not without nuance, however. For larger, multinational organizations operating across countries and continents, multiple cloud environments will be required to house multiple sovereign clouds. But more environments mean increased complexity for both the monitoring and management of data across jurisdictions. Not only will multiple cloud environments need to be considered, but also multiple sets of data regulations across countries. And for those organizations that do get it right, the benefit of enhanced data resilience comes with the added risk of data fragmentation.
So there’s no easy way out with data portability. But it’s certain to be an essential part of any solution that organizations settle on. It’s clear that, no matter which approach is taken, being able to move data seamlessly across platforms and clouds will be a necessity as organizations wrestle with data sovereignty. As regulations continue to emerge, data portability will give organizations a head start on future compliance, allowing them to flex more easily to meet regulations where less portable counterparts will struggle.
Dressing for the weather
It’s clear that data globalization isn’t going to slow down anytime soon, with information flows becoming their own form of trade, with tangible economic value. And with global instability as an ever-present factor, data sovereignty will only move higher up the priority list.
While organizations may not have fully realised it yet, data sovereignty and operational clarity are closely linked. You can’t secure your data without knowing exactly where it’s stored and how. Once this comprehensive understanding of your data landscape is established, you can pinpoint the operations or processes where data resilience might be lacking and tackle your data portability. By reworking data resilience from the ground up, organizations can solidify security, compliance, and sovereignty into their operations, and manage them through risk assessments, compliance audits, and strategies that take into account multiple suppliers.
After this groundwork, organizations can then start leveraging hybrid cloud environments effectively, perhaps storing the most sensitive data on-premises under precise data sovereignty regulations, while offloading less critical data to the cloud. But this can only be achieved by organizations that have prioritised data portability. Rather than waiting for regulations to enforce it, organizations need to take proactive steps to benefit from it. Otherwise, they risk losing the very longevity, flexibility, and security that make the cloud so valuable in the first place.
The author
Michael Cade is Global Field CTO, Veeam






