A regulator, an auditor, or a major customer asks a question that sounds simple: where does your data live? Which systems hold it, in which countries, processed by whom, under what agreements? For a great many businesses, the honest answer is “we are not entirely sure” — and being unable to answer is, increasingly, a compliance problem in its own right. Data sovereignty has moved from a niche concern to a question regulated and serious businesses are expected to answer on demand.
Why the question is being asked now
Where data physically lives, and who can access it, has become a regulatory concern across sector after sector. Data-protection law cares about where personal data goes, especially across borders. Financial-sector rules increasingly require firms to know and control where their data and critical services sit, including the operational-resilience expectations of DORA. Customers, particularly larger ones, ask because their own obligations require them to know where their data ends up when they hand it to a supplier. The common thread is that “we keep it safe somewhere” is no longer an acceptable answer.
Why businesses cannot answer it
The reason most businesses struggle is that their data spread organically, without anyone mapping it. It lives in the main systems, yes, but also in cloud services chosen by different teams, in backups in places nobody checks, in third-party tools, in spreadsheets, and in whatever AI tool a staff member used this morning. Each addition made sense locally; nobody held the whole picture. This is the data-governance gap behind shadow IT, and it is the same fragmentation that produces reports that show different numbers — data scattered across places nobody has fully catalogued. You cannot say where your data lives because no one ever drew the map.
Free · 4 minutes
When two of your systems disagree, do you know which one to believe?
Fourteen questions on ownership, lineage, and quality — the difference between a number on a dashboard and a number you could defend. Banded finding on screen, full sheet by email.
What being unable to answer actually risks
The inability to map your data is not just embarrassing in front of a regulator. It means you cannot demonstrate compliance, because you cannot show how data is protected if you do not know where it is. It means you cannot be sure you are meeting cross-border transfer rules, because you do not know which borders your data crosses. It means you cannot fully protect data you do not know you hold. And it means that when an incident happens, you cannot scope it, because you do not know everywhere the affected data resides. The unanswered question is the visible tip of several real exposures.
What to do
The fix is a data mapping exercise — establishing what data the business holds, where each kind of it lives, who processes it, where it flows, and under what agreements. It is detective work as much as technical work, because so much of it grew unrecorded, but it is finite and it is the foundation of every data-related compliance obligation you have. Done once and kept current, it turns the regulator’s question from a panic into a one-page answer. It also tends to surface data sitting in places it should not be, which is worth finding before someone else finds it.
Data sovereignty is becoming a requirement across every regulated sector, and if you cannot map your data flows, that is urgent rather than theoretical. We will work out where your data actually lives before someone makes you answer for it.
Start a ConversationFree interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming