INDUSTRY
The Four Dimensions of Data Sovereignty: A Practical Framework
In the first piece of this series, I made the case that the one variable every organization can act on is where your data physically lives. That’s the right place to start. It’s also where a lot of organizations think they’re done.
Every week, I see the same pattern. A team picks an EU storage region, confirms the data sits in-country, and marks sovereignty as handled. The location box is ticked, so the project moves on.
The trouble with that approach is that location is only one dimension of sovereignty. It’s the necessary foundation, but on its own it doesn’t make you sovereign. In an IDC Spotlight, sponsored by Wasabi1, IDC frames the full picture as four dimensions, and some organizations focus only on the first.
That’s not a criticism. The market is full of sovereignty claims that don’t survive a closer look, and it’s genuinely hard to tell real sovereignty from a label.
Establishing a framework helps, because it turns a vague worry into four specific things you can verify.
The four dimensions of data sovereignty
IDC defines the four dimensions of data sovereignty as: Data, Legal, Operational, and Technical[1].
The Data dimension governs where your data physically resides and who can access it. This is the one aspect teams already think about: residency, encryption, access control.
The Legal dimension is about which jurisdiction governs your data, and who holds override powers if someone comes asking.
The Operational dimension is about ensuring continuity and recovery even if a primary provider is disrupted. That’s where immutable storage, WORM compliance, and a backup genuinely independent of your main environment come in.
The Technical dimension is about preserving the ability to move, recover, and exit without vendor dependency. S3-compatible APIs, no egress fees, and portability by design are what keep that door open.
Minding all four dimensions gives you a practical way to assess where you truly stand on data sovereignty, because addressing one dimension well is not the same as addressing all four.
Some companies stop at the first dimension
The research bears this out, and it shows the gap isn’t uniform. The IDC CloudOps and Governance Survey found that when it comes to the most critical workloads, 38% of organizations have expedited infrastructure purchasing activities to mitigate risk and 32% have increased budgets.[1] That’s a serious response to protect the data that genuinely matters.
One tier down, at business-essential workloads, a higher number of organizations are adopting multitenant environments and moving on. The rigor applied to the crown jewels of their data drops off for the far larger volume of data the organization holds.
Risk response is uneven, and the unevenness is where exposure hides. An attacker or an outage doesn’t check how a workload was classified before it hits. Attackers exploit whatever is least protected.
None of this means every workload should be treated exactly the same. It means knowing which dimension you’ve actually covered for each one, rather than assuming the location box will cover them all.
Two paths, and one’s winning
When you look at how organizations close that gap, two instincts show up. Some go location-only. They pick an EU-registered vendor, keep everything in-country, and call it sovereign. Others take a more pragmatic route, favoring flexibility and resilience over a geographic boundary.
IDC’s FERS Survey shows which instinct the most digitally mature organizations trust. Among digital natives, 44% named supplier diversification as their sourcing strategy, against just 20% choosing local sovereign data centers.[1]
On resilience, 35% are prioritizing multi-region and multi-availability-zone investment over the next 6 to 12 months, compared with only 18% investing in sovereign or locally owned data centers.
The contrast with less mature organizations is telling. Digital followers tend to lean the other way, toward location-only, EU-vendor-only policies, often without a matching reduction in real risk. It feels safer because it’s simpler, but a simple boundary and genuine resilience aren’t the same thing.
IDC’s read is that the next phase of sovereignty in EMEA will be won through optionality, not through either-or restrictions. The interesting part is why native organizations diversify. It isn’t only concentration risk or cost. It’s the fear of lockout as much as lock-in.
The organizations I talk to don’t want their digital future sitting entirely in one vendor’s hands. If that vendor decides to cut access to a service, being locked out is every bit as damaging as being locked in. Diversifying across open, compatible technologies is how they keep that from ever being someone else’s decision to make.
Three questions that test your real posture
The IDC Spotlight boils the whole framework down to three questions every executive should be able to answer.[1] I’d frame them as questions of control, because that’s what they really measure.
1. Can you control your sensitive data? (Do you have flexibility and choice of locations, data visibility, and portability?)
That’s the data dimension. Do you have genuine choice over where it lives, visibility into it, and the ability to move it?
2. Can you manage and govern it independently? (Do you have control of security, policies, data residency, and encryption?)
This is the dimension almost nobody looks at closely enough. Who controls the security, and can you create your own encryption keys?
If you bring your own keys, then even in the scenario everyone worries about, a foreign government making a legal demand for your data, having the keys yourself renders that a non-issue. The data is unreadable without them. That single control does more for your sovereignty posture than a change of address ever could.
3. Can you move the data if conditions change? (Is the environment interoperable, portable, and transparent?)
This is where cost decides everything. A lot of “sovereign” arrangements let you move your data in theory while penalizing you for it in practice, through egress charges and access fees that make leaving expensive enough to think twice. That isn’t control.
At Wasabi, we believe control means predictability. Our pricing is standardized and transparent, so I can forecast a customer’s storage cost three and four years out. And data access fees are zero. You are never financially penalized for reaching your own data, or for moving it.
Answer yes to all three, and you have a real foundation for sovereignty. Answer yes to only the first, and you have a location and a false sense of security.
Where this leaves you
The four dimensions give you the map. The three questions tell you where you stand on it.
What they don’t do, on their own, is build the thing. Answering yes to all three takes a deliberate architecture, not a single vendor’s promise.
That’s where this series goes next: the practical infrastructure decision that turns this framework into something real.
Read the research
For the complete framework, including the four dimensions and the executive questions in full, read the IDC Spotlight paper, sponsored by Wasabi, Cloud Without Compromise: Building Data Sovereignty into Your Infrastructure with a Resilience-First and Risk-Mitigating Approach.
Sources
[1] IDC Spotlight, sponsored by Wasabi, Cloud Without Compromise: Building Data Sovereignty into Your Infrastructure with a Resilience-First and Risk-Mitigating Approach (Doc #US54512826, May 2026)
Related article
Most Recent
AI adoption is outpacing data governance. See how AvePoint and Wasabi close the trust gap with governed, protected, and egress-free storage at scale.
Four myths justify single-vendor backup storage. None hold up in a real incident. See what independent storage like Wasabi actually delivers.
Webb County, Texas avoided weeks-long budget approvals and egress fees by moving to Wasabi, which separated its DA's evidence billing and locked in five years of predictable storage pricing.
SUBSCRIBE
Storage Insights from the Storage Experts
Storage insights sent direct to your inbox.
&w=1920&q=75)