88% of enterprise leaders say a data sovereignty failure could cost executives their jobs. 64% have no strategy to prevent one

"Senior leaders understand their jobs are on the line over data sovereignty, yet many are still focused on the wrong risks," said Alex McMullan, Chief Technology Officer, International, at Everpure. The company's Global Data Sovereignty Report 2026, conducted by Vanson Bourne among 2,100 C-suite and IT leaders in June, found that 88% believe a sovereignty failure could cost senior decision-makers their jobs, and 91% expect it would cause significant financial or reputational harm. Against that, 64% of organisations have no formal data sovereignty strategy, 62% lack full visibility into who can access, control and manage their data, and 56% have no plan for data being extracted under foreign law or services being withdrawn for political reasons.

The study covers large enterprises in the UK, France, Germany, Australia, Japan, South Korea, Singapore and India, a spread of jurisdictions with very different regulatory regimes and geopolitical alignments. None of the respondents is based in the US. Everpure, the storage and data management company that traded as Pure Storage until its rebrand earlier this year, sells software aimed at the visibility gap the report identifies, a commercial interest worth keeping in view alongside the numbers.

Sovereign hosting goes mainstream

Twelve months ago, 1% of respondents had moved the majority or all of their enterprise data onto local or sovereign infrastructure. Today 28% have, 41% plan to within one to three years, and 92% expect local or sovereign cloud to become the default deployment model for sensitive workloads in that period. Investment has followed: 86% raised sovereignty spending in the past six to 12 months, and 29% made significant budget increases.

"Vendor evaluations are now more stringent, with a greater emphasis on regional hosting capabilities and sovereignty promises," said a C-level executive at a UK bank with between 3,000 and 4,999 employees. The procurement figures bear that out. Only 2% said sovereignty was a significant factor in vendor selection before the past year, against 32% now, and 80% report it has grown in importance in RFP processes. India leads, with 44% treating sovereignty as a significant procurement consideration, compared with 16% in Australia.

Some 40% of organisations are actively limiting their use of SaaS platforms hosted outside their home country, rising to 49% in Germany, and 85% said they would give up advanced features and functionality to work with a sovereign provider. For global SaaS and cloud providers, that last figure signals buyers ready to put jurisdiction ahead of capability.

"Digital sovereignty has moved from a compliance conversation to a critical board-level concern," said Rahiel Nasir, Research Director and Lead Analyst, Worldwide Digital Sovereignty, at IDC. "The challenge for executives is not just about knowing where their data are hosted. It is about being in total control of all data access and transfers (including all metadata), guaranteed protection against extraterritorial data requests, and managing IT and vendor risks in the light of geopolitical uncertainties."

Cybersecurity risks such as breaches and leakage drive sovereignty measures at 47% of organisations, and new regulatory requirements at 39%. Only 9% rank protection against foreign government data requests as a top priority, falling to 5% in the UK, and another 9% prioritise reducing their dependence on overseas technology providers. Encryption and access controls are the most common measures, deployed by 60%, while 49% segment data and applications by jurisdiction to guard against losing access to services.

Those lower-ranked risks already have public precedents. In June 2025, Anton Carniaux, director of public and legal affairs at Microsoft France, told a French Senate inquiry that he could not guarantee data would never be handed to US authorities if they requested it. Weeks earlier, the Associated Press reported that Karim Khan, chief prosecutor of the International Criminal Court, had lost access to his Microsoft email after US sanctions were imposed on him. Microsoft said it had not suspended services to the court itself. The report names these two scenarios, legally compelled data extraction and the loss of essential digital services through foreign legal or political action, as the core sovereignty risks, and more than half of respondents have no plan for either.

AI keeps data at home

"Currently, we prioritise storing highly sensitive business data locally in order to improve compliance, strengthen security, and build customer trust," said a senior manager at a private healthcare organisation in Japan with between 1,000 and 2,999 employees. Some 92% of respondents regard sovereignty as a critical part of their AI strategy, 93% believe sovereign AI capabilities offer a competitive advantage, and 87% will prioritise local or sovereign environments for most or all high-risk or sensitive AI workloads within three years. For patients, account holders and policyholders, it means the models reading their records are increasingly likely to run in the country where they live.

"My biggest challenges are migrating legacy systems to sovereign clouds without downtime, closing the skill gap in compliance plus cloud tech, and balancing advanced features with data residency needs. Sovereign providers are improving but still lag hyperscalers on some AI tools," said a senior manager at an emergency services organisation in India with more than 5,000 employees. The trade-off shows in the wider data: 39% acknowledge that sovereign AI adds operational complexity, and 45% say sovereignty already shapes where AI models and data are hosted.

Executives carry the blame

"Throughout the leadership discussions, the most difficult problem is persuading board members that sovereignty is worth investing in," said a C-level executive at a South Korean energy company with more than 5,000 employees. Only 19% of respondents say their data strategy is driven by the board, and 36% report difficulty securing executive buy-in. That sits uneasily beside the 88% who expect senior jobs to be at risk when something goes wrong.

"We talk about it [data sovereignty] a lot internally now, but nothing has really changed, to be honest," said a senior manager at a German bank with between 3,000 and 4,999 employees. Execution is held back by competing priorities (57%), a shortage of internal skills and capacity (56%), regulation moving faster than organisations can follow (55%) and budget constraints (50%). "There are no ready-made implementation templates. Every step requires trial and error, with high costs associated with mistakes," said a C-level executive at another German bank, with between 1,000 and 2,999 employees.

Among enterprises with more than 5,000 employees, 45% have formally embedded a sovereignty strategy, compared with 30% of those with fewer than 3,000 staff, and 12% of the smaller firms remain unaware of sovereignty challenges altogether. Japan has the highest rate of formal strategy adoption at 47%, while 81% of Singaporean organisations lack formal plans. Firms that have committed are spending more decisively, with 42% of those with an embedded strategy making significant budget increases in the past year, against 29% overall.

"We face a shortage of skilled professionals with expertise in both data sovereignty regulations and technical implementation," said a senior manager at an Australian insurer with more than 5,000 employees. Most organisations in the survey say they cannot find people fluent in both regulation and infrastructure. As sovereignty requirements reach more sectors, the demand for that profile is likely to spread well beyond the banks and insurers that felt it first.

Risk should set the controls

"Sovereignty is not simply about where data is stored, but having full visibility and control over it through modern data management. Who can access data, which jurisdictions apply and whether business-critical data or services could be disrupted are key questions every organisation should be asking," said McMullan. The company calls its recommended approach sovereignty by design. Controls are applied according to the risk of each dataset, application and workload, and the focus moves from national sovereignty to what Everpure calls corporate sovereignty, set by each organisation's own risk appetite and reading of regulation.

Everpure positions its Everpure Data Intelligence product as the discovery layer for that model, classifying data across its own platform, public clouds, SaaS applications and third-party storage. It says the approach lets enterprises protect critical assets without giving up the flexibility and scale of global cloud providers. Its own findings put that promise under some strain, since 85% of respondents would already trade features for a sovereign provider and 28% have moved most of their data. Some 93% rate data management as critical to sovereignty, which suggests buyers accept the premise, and the 62% visibility gap shows how far most of them still are from acting on it.

The report concludes that closing the execution gap "will determine whether enterprise organisations can successfully balance international regulatory demands, cloud scalability, and secure AI deployment over the coming decade." For the customers whose records sit in those systems, the question is narrower and closer to home: which country's law decides who else gets to read them.

Sindhu V Kashyap

Global Technology Journalist & Multimedia Storyteller | Covering Founders, Investors & Leaders Reshaping Tech | Writer · Interviewer · Moderator · Editor

Next
Next

ElevenLabs and DXC begin joint voice AI projects as enterprise buyers demand proof of return