Skip to main content

Sovereignty scan

The Sovereignty scan is an assessment in which we systematically map out where an organisation's data and systems are located, which suppliers and underlying parties are involved, and under which legal framework that data falls.

Two colleagues talking in a meeting room
Two colleagues working together at a laptop

Why the Sovereignty scan?

The Sovereignty scan is an assessment in which we systematically map out where an organisation's data and systems are located, which suppliers and underlying parties are involved, and under which legal framework that data falls. Think of exposure to legislation such as the US CLOUD Act, alongside the frameworks that apply within the EU and GDPR.

The scan is particularly relevant for organisations in sectors with heightened sensitivity: government, healthcare, financial services and vital infrastructure, where regulation or internal risk assessment explicitly calls for a grip on digital sovereignty.

Our approach

  1. 1

    Mapping suppliers and data processors

    We take stock of which cloud platforms, suppliers and subcontractors are involved in processing and storing your data, including the chain of underlying processors (sub-processors).

  2. 2

    Assessing legal exposure

    We assess which jurisdictions the parties involved fall under, with specific attention to exposure to non-European legislation such as the US CLOUD Act.

  3. 3

    Analyzing data locations and flows

    We map out where data is actually stored and processed, including any movement of data between regions that isn't always visible in standard documentation.

  4. 4

    Identifying risks and alternatives

    We connect the findings to concrete risks for your organisation and, where relevant, map out alternatives such as European platforms like Scaleway or StackIT.

  5. 5

    Reporting and advice

    The scan results in a clear report with findings, risk classification and concrete advice, suitable for sharing with regulators, the board or compliance officers.

What does the Sovereignty scan deliver?

Full overview

Complete visibility into where your data and systems are located and which suppliers and sub-processors are involved.

Legal clarity

Clarity on which jurisdiction your data falls under, including exposure to legislation such as the US CLOUD Act.

Substantiated risk assessment

A concrete risk classification per domain, so you can make informed choices about platforms and suppliers.

Usable reporting

A report suitable for sharing with regulators, the board or compliance officers.

  • Stadlander logo
  • Mourik logo
  • Evides Waterbedrijf logo
  • Gemeente Alphen aan den Rijn logo

Data

Curious how we can help your organisation in the area of data?

Colleague working at a laptop and monitor

Ready to gain insight into your digital sovereignty?

Digital Survival Company carries out Sovereignty scans for organisations in government, healthcare, financial services and vital infrastructure, with experience in both the major cloud platforms and European alternatives such as Scaleway and StackIT. Get in touch and let's discuss what the Sovereignty scan delivers for your organisation.

FAQ

  • Which organisations is the Sovereignty scan particularly relevant for?

    The scan is especially valuable for organisations in government, healthcare, financial services and vital infrastructure, where regulation or risk policy explicitly calls for a grip on where data sits and which law it falls under. Organisations that are deliberately thinking through their dependence on non-European suppliers also benefit from the scan.

  • Does a low sovereignty score mean we need to switch platforms right away?

    Not necessarily. The scan provides insight, not an obligation. For many organisations the outcome is a deliberate trade-off between functionality, cost and sovereignty. We advise on alternatives where relevant, but the choice to actually switch platforms lies with your organisation.

  • How does the Sovereignty scan relate to the BIO/NIS2 compliancy scan?

    The scans overlap but have a different focus. The Sovereignty scan focuses on where data sits and which law it falls under. The BIO/NIS2 compliancy scan assesses whether information security meets specific legal frameworks. For organisations dealing with both questions, we combine the scans where that's efficient.