The foundation: engage.re
Data Protection 30 July 2026 9 min read

Data Sovereignty for a UK Organisation, in Plain Terms

Data sovereignty is sold as a location, and location is the weakest of the four questions that matter. A supplier can host your data in London and still hold the keys, answer to a foreign court, and control who reads what. This article separates location, jurisdiction, custody and control, explains what UK hosting does and does not answer, and states the one limit no supplier can remove.

Connect with us about data control · · Replies within 24 hours

4
questions, and location is the weakest of them
1
gate per domain boundary decides every crossing
v2.0.0
the published conformance package that makes self-hosting real

What is data sovereignty?

Data sovereignty is the control you hold over your data, and it breaks into four separate questions.

Question What it asks How much it decides
LocationWhich country holds the storage?Least.
JurisdictionWhich court can compel the supplier?More.
CustodyWho holds the encryption keys?More still.
ControlWho decides which access is allowed?Most.

Most procurement exercises ask the first question and stop. The other three then remain open, and each one can override a favourable answer to the first.

Does UK hosting mean UK sovereignty?

No. Hosting states where the disks are, and it says nothing about the other three questions.

Consider a supplier incorporated outside the UK, hosting your data in a London data centre. The location answer is UK. A court in the supplier's home country can still compel that supplier to act, and your data sits inside a system the supplier operates.

The National Cyber Security Centre's cloud security guidance treats these as separate matters. So does the ICO in its guidance on international transfers, and HM Government sets out the wider position in its approach to international data transfers.

A transfer is not only a movement of data. Remote access from another country reaches your data without moving it. A support engineer abroad who can read a record has accessed UK-hosted data from outside the UK.

Why does key custody decide more than location?

Encryption converts a question about geography into a question about keys. Where your data is encrypted and you hold the keys, the storage location matters less, because the data is unreadable without you.

The ICO's guidance on encryption treats it as a core security measure.

Three custody arrangements exist, and they differ sharply.

  • The supplier holds the keys. The supplier can read your data, and a lawful order to the supplier reaches it.
  • The supplier holds the keys in a managed service. Your contract restricts use, and the technical ability remains.
  • You hold the keys. The supplier cannot read your data, and a lawful order to the supplier produces ciphertext.

Only the third arrangement changes what is possible rather than what is permitted.

What does control mean?

Control asks who decides which access is allowed, and where that decision lives.

Most estates hold their access decisions in many places. Each system has its own permission model, each supplier has its own idea of a user, and hundreds of checks sit inside application code. Nobody can state the policy, because no single place holds it.

Control therefore has a testable form. One place decides every crossing of a boundary, one identity model covers every actor, and every access leaves a record nobody can alter.

We treat the permission half of that question in what may an AI agent touch in your systems, and the evidence half in who answers when an AI agent gets it wrong.

The limit no supplier can remove

Somebody must be able to read your data for your service to work. A care worker reads a care plan, a housing officer reads a tenancy, and a clinician reads a note. That access is the purpose of the system.

Sovereignty therefore cannot mean that nobody can read your data. It means that every read is authorised by you, recorded, and attributable to a named actor.

The honest goal is accountable access, not impossible access. A supplier promising that nobody can ever see your data is describing a system that cannot deliver a service.

What ESRE Media offers

We build your system on engage.re, and each of the four questions has a specific answer.

Question What your system gives you
LocationUK hosting, or your own infrastructure. Three deployment tiers.
JurisdictionSense Future is a UK company, and you may host the platform yourself under a published conformance package.
CustodyEach record is encrypted separately, and you hold your own keys. Destroying a key destroys access to that record.
ControlOne gate per domain boundary, one identity model for your people, applications and agents, and every access recorded as an event in a signed chain.

The conformance package is published at engage.re/conformance, at version 2.0.0. Sense Future built the platform, and it has run in production since December 2025.

How to test a supplier

  1. Where is the data stored? Ask for the region and for any replica locations.
  2. Where is the supplier incorporated? That answer names the courts that can compel it.
  3. Who can access the data from outside the UK? Support, engineering and subprocessors all count.
  4. Who holds the encryption keys? Ask whether you can hold them instead.
  5. Where does the access decision live? Count the places.
  6. Can you list every access to one record? Ask for that list for a record of your choosing.
  7. Could anybody alter that list? The answer decides what the other six are worth.

Question six is the one most suppliers cannot answer quickly, and it is the one an investigation asks first.

The same questions at two sizes

A council procures a case management system and specifies UK hosting. The supplier meets that requirement, holds the keys, and provides support from three countries. The council satisfied its stated condition and answered one question of four.

A care home group buys a records system with the same UK hosting statement. The group holds special category health data, so custody and control matter more to it than to the council, and it usually asks about them less.

The care home software and charity software pages set out the sector detail. Our guides to the Data Security and Protection Toolkit and cyber breaches in business software cover the obligations that follow.

What we do not claim

  • UK hosting is not worthless. It is one of four questions, and it is the easiest to verify.
  • Holding your own keys adds duties. A lost key destroys access, and that is the cost of the control.
  • No architecture prevents a lawful order to you. It changes who receives the order, and it makes the response attributable.

What to do next

  1. Ask your largest supplier the seven questions above, in writing.
  2. Find out who holds your encryption keys. Many buyers do not know.
  3. List everybody who can read your data from outside the UK, including subprocessors.
  4. Request a full access list for one record, and time the response.
  5. Then decide whether your sovereignty rests on a location or on custody and control.

Common questions

What is data sovereignty?

The control you hold over your data. It breaks into four questions: which country holds the storage, which court can compel the supplier, who holds the encryption keys, and who decides which access is allowed. Location decides least of the four, and control decides most.

Does UK hosting give us UK data sovereignty?

No. Hosting states where the disks are. A supplier incorporated outside the UK can host your data in London and remain subject to a foreign court, and a support engineer abroad can read a record without any data moving. Remote access reaches your data without a transfer in the ordinary sense.

Why do encryption keys matter more than location?

Because encryption converts a question about geography into a question about keys. Where the supplier holds the keys, a lawful order to the supplier reaches your data. Where you hold the keys, the same order produces ciphertext. Holding the keys changes what is possible rather than what is permitted.

What does control over data actually mean?

One place decides every crossing of a boundary, one identity model covers every actor, and every access leaves a record nobody can alter. Most estates hold their access decisions in many places, so no single place holds the policy and nobody can state it.

Can a supplier guarantee that nobody sees our data?

No, and a supplier claiming it is describing a system that cannot deliver a service. A care worker must read a care plan for the service to work. The honest goal is accountable access: every read authorised by you, recorded, and attributable to a named actor.

What does ESRE Media build?

We build your system on engage.re. You choose UK hosting or your own infrastructure across three deployment tiers, each record is encrypted separately under keys you hold, one gate decides every domain crossing, and every access is an event in a signed chain. A published conformance package at version 2.0.0 makes self-hosting real.

Connect with us about data control · · Replies within 24 hours

Sources and further reading