Data sovereignty is the principle that data is subject to the laws of the country where it is stored or processed, not the laws of wherever the company that owns it happens to be based. As workloads move to cloud providers, the same dataset can be replicated across several jurisdictions at once, each with its own rules about access, disclosure, and government requests.
The EU’s GDPR is the most cited example. Personal data belonging to people in the EU must be handled to GDPR standards regardless of where the processing company is headquartered, and some countries go further by requiring that certain data physically stay within national borders, a stricter idea called data residency. This is why cloud architecture decisions are never purely technical. Choosing a region for a database is also a legal decision that can trigger fines or a costly migration later. Contracts with providers must pin down exactly where data lives and who can compel access to it.
How is data sovereignty tested on the CISSP?
Data sovereignty is addressed in Domain 2: Asset Security and in Security and Risk Management. Candidates should understand how jurisdictional rules shape data classification, storage location, and cloud design.
Related terms: Data Classification, Compliance