Data sovereignty is sold as a location, and location is the weakest of the four questions that matter. A supplier can host your data in London and still hold the keys, answer to a foreign court, and control who reads what. This article separates location, jurisdiction, custody and control, explains what UK hosting does and does not answer, and states the one limit no supplier can remove.
Connect with us about data control · · Replies within 24 hours
Data sovereignty is the control you hold over your data, and it breaks into four separate questions.
| Question | What it asks | How much it decides |
|---|---|---|
| Location | Which country holds the storage? | Least. |
| Jurisdiction | Which court can compel the supplier? | More. |
| Custody | Who holds the encryption keys? | More still. |
| Control | Who decides which access is allowed? | Most. |
Most procurement exercises ask the first question and stop. The other three then remain open, and each one can override a favourable answer to the first.
No. Hosting states where the disks are, and it says nothing about the other three questions.
Consider a supplier incorporated outside the UK, hosting your data in a London data centre. The location answer is UK. A court in the supplier's home country can still compel that supplier to act, and your data sits inside a system the supplier operates.
The National Cyber Security Centre's cloud security guidance treats these as separate matters. So does the ICO in its guidance on international transfers, and HM Government sets out the wider position in its approach to international data transfers.
Encryption converts a question about geography into a question about keys. Where your data is encrypted and you hold the keys, the storage location matters less, because the data is unreadable without you.
The ICO's guidance on encryption treats it as a core security measure.
Three custody arrangements exist, and they differ sharply.
Only the third arrangement changes what is possible rather than what is permitted.
Control asks who decides which access is allowed, and where that decision lives.
Most estates hold their access decisions in many places. Each system has its own permission model, each supplier has its own idea of a user, and hundreds of checks sit inside application code. Nobody can state the policy, because no single place holds it.
Control therefore has a testable form. One place decides every crossing of a boundary, one identity model covers every actor, and every access leaves a record nobody can alter.
We treat the permission half of that question in what may an AI agent touch in your systems, and the evidence half in who answers when an AI agent gets it wrong.
Somebody must be able to read your data for your service to work. A care worker reads a care plan, a housing officer reads a tenancy, and a clinician reads a note. That access is the purpose of the system.
Sovereignty therefore cannot mean that nobody can read your data. It means that every read is authorised by you, recorded, and attributable to a named actor.
We build your system on engage.re, and each of the four questions has a specific answer.
| Question | What your system gives you |
|---|---|
| Location | UK hosting, or your own infrastructure. Three deployment tiers. |
| Jurisdiction | Sense Future is a UK company, and you may host the platform yourself under a published conformance package. |
| Custody | Each record is encrypted separately, and you hold your own keys. Destroying a key destroys access to that record. |
| Control | One gate per domain boundary, one identity model for your people, applications and agents, and every access recorded as an event in a signed chain. |
The conformance package is published at engage.re/conformance, at version 2.0.0. Sense Future built the platform, and it has run in production since December 2025.
Question six is the one most suppliers cannot answer quickly, and it is the one an investigation asks first.
A council procures a case management system and specifies UK hosting. The supplier meets that requirement, holds the keys, and provides support from three countries. The council satisfied its stated condition and answered one question of four.
A care home group buys a records system with the same UK hosting statement. The group holds special category health data, so custody and control matter more to it than to the council, and it usually asks about them less.
The care home software and charity software pages set out the sector detail. Our guides to the Data Security and Protection Toolkit and cyber breaches in business software cover the obligations that follow.
The control you hold over your data. It breaks into four questions: which country holds the storage, which court can compel the supplier, who holds the encryption keys, and who decides which access is allowed. Location decides least of the four, and control decides most.
No. Hosting states where the disks are. A supplier incorporated outside the UK can host your data in London and remain subject to a foreign court, and a support engineer abroad can read a record without any data moving. Remote access reaches your data without a transfer in the ordinary sense.
Because encryption converts a question about geography into a question about keys. Where the supplier holds the keys, a lawful order to the supplier reaches your data. Where you hold the keys, the same order produces ciphertext. Holding the keys changes what is possible rather than what is permitted.
One place decides every crossing of a boundary, one identity model covers every actor, and every access leaves a record nobody can alter. Most estates hold their access decisions in many places, so no single place holds the policy and nobody can state it.
No, and a supplier claiming it is describing a system that cannot deliver a service. A care worker must read a care plan for the service to work. The honest goal is accountable access: every read authorised by you, recorded, and attributable to a named actor.
We build your system on engage.re. You choose UK hosting or your own infrastructure across three deployment tiers, each record is encrypted separately under keys you hold, one gate decides every domain crossing, and every access is an event in a signed chain. A published conformance package at version 2.0.0 makes self-hosting real.
Connect with us about data control · · Replies within 24 hours