Subscribe to our newsletter!

Submit

Thank you for signing up for our newsletter!

We’re excited to have you with us and will keep you updated with the latest news, insights, and updates straight to your inbox.
Oops! Something went wrong while submitting the form.
Back to Blog
August 11, 2020
|
Read time {time} min

What Is Data Sovereignty? Everything You Need to Know

Written by
Permission
Stay in the loop

Get the latest insights, product updates, and news from Permission — shaping the future of user-owned data and AI innovation.

Subscribe

Control over our data has become increasingly important.

With multiple recent high-profile data breaches and scandals, governments are taking extra measures to prevent their citizens’ personal information from falling into the wrong hands.

Data sovereignty, which has become a hot topic nowadays, is one of the concepts governments are using to protect citizens’ data.

But what is data sovereignty, why is it important, and how does it affect businesses and consumers?

Bear with us as we explore this important topic.

What Is Data Sovereignty?

Data sovereignty refers to the concept that the data an organization collects, stores, and processes is subject to the nation’s laws and general best practices where it is physically located.

In layman’s terms, this means that a business has to store the personal information of its customers in a way that complies with all the data privacy regulations, best practices, and guidelines of the host country.

If the business fails or refuses to comply with the host’s data privacy laws, the country’s government can impose a fine or force the company in another way to fulfill its requirements.

As part of data sovereignty measures, multiple countries have regulated how businesses can handle citizens’ data, including the locations and jurisdictions where organizations are allowed to store citizen data.

When a business transfers data of a citizen outside of the country, the third nation’s government can use measures (e.g., subpoenas) to access the user’s data, even though the citizen is a foreign national.

Since governments seek to prevent other nations from acquiring the data of their citizens, they have introduced data sovereignty measures that restrict how businesses can transfer personal information outside of the country.

Furthermore, the recent data protection law of the European Union, the GDPR, has implemented strict rules on how organizations handle the personal information of their citizens, even when the company processes data outside the region.

As a side note, data sovereignty is sometimes used in the context of indigenous societies.

Indigenous data sovereignty refers to the decolonization of the personal information of indigenous people that could play a key role in achieving autonomy for these societies.

Data Sovereignty vs. Data Residency

While data sovereignty and data residency are two terms that have similar meanings, it’s very easy to confuse them.

Data Residency

Data residency is when a business or government specifies the geographical location where its data should be stored.

Data residency requirements are often the result of policy- or regulation-related reasons.

Let’s see an example to understand this.

A nation has favorable data privacy laws that help enterprises in handling data-related processes in a convenient, predictable way.

Due to the favorable regulatory environment, businesses would choose this country to store their data.

A company may also include the location where its users’ personal information is kept in its data sovereignty policy.

An excellent example of a regulation-related data residency requirement is when a business chooses to store the data in a specific country due to its favorable tax environment.

To receive the tax benefits, the business needs to ensure that it does most of its operations within the nation’s borders. Therefore, it decides to store its data in a geographical location somewhere in the country.

Data Sovereignty

On the other hand, data sovereignty refers to designating the geographical location where the data is physically stored AND being the subject of that nation’s laws.

While data residency ensures that the data stays in the specified geographical location, data sovereignty makes sure that the information is subject to the legal punishments and protections of the country where it is physically stored.

The History of Data Sovereignty

To understand our topic, it’s essential to take a look at the most important events leading to data sovereignty’s rising popularity.

Where It All Started

Many credit the popularity of data sovereignty and the rise of related discussions to Edward Snowden’s leaks that exposed the US National Security Agency’s (NSA) PRISM spying program.

As part of the program, the US agency was collecting sensitive personal information – including photos, emails, social media login credentials, video calls, and other data – from tech companies in the United States (e.g., Facebook, Apple, Google, and Twitter).

The problem with the spying program was that the NSA did not only collect the sensitive personal information of US citizens but also from foreign nationals.

In addition to the NSA’s spying program, as per the US Patriot Act, the American government has the authority to access data that is physically stored within the country, regardless of its origins.This means that, for example, German citizens’ data are exposed to the US government if the information is physically stored within the North American country.

Amid concerns that their citizens’ data could fall into the hands of a foreign government, nations all over the world have introduced data sovereignty measures.

Microsoft’s Data Privacy Case vs. the DoJ

Microsoft’s case against the US Department of Justice (DoJ) was also a high-profile event that further highlighted the importance of data sovereignty.

After the DoJ ordered the tech company to grant access to emails stored in Ireland-based servers related to a narcotics investigation in 2013, Microsoft had refused to comply with the Department of Justice’s request.

Despite that Microsoft stated that complying with the request would break the data privacy laws of the European Union, the initial ruling ordered the company to fulfill the DoJ’s request.

However, later on, after Microsoft won the appeal and the DoJ changed its data-related policies.

Why Is Data Sovereignty Important?

Protecting Your Money or Your Data: Is There Really a Difference?

Let us show an example to understand why data sovereignty is crucial.

You open a bank account in the United States, where you regularly deposit your funds.

While you were of the belief that the financial institution would store your funds in the US, you get a call from the bank’s manager that your money has been moved to a third country as the regulatory environment is more beneficial there.

Later on, that nation’s government decides to close your bank’s local branch. For a reason, it confiscates all the funds that the bank’s customers held there, including yours.

Fortunately, due to the different financial regulations in place, the above-mentioned example could not happen with your money.

However, without laws that ensure adequate data sovereignty compliance, your personal information – which is as valuable as your money – could be as easily abused as your funds in the example.

Facebook’s Cambridge Analytica Scandal

Before data sovereignty and privacy were important, businesses could (more or less) use the personal information of their users as they liked.

This means that tech companies could sell your personal data without your consent to a third party for advertisement purposes.

A great example of the above-mentioned is Facebook’s scandal with Cambridge Analytica.

With an app called This Is Your Digital Life, Cambridge Analytica collected personal data from Facebook users who agreed to participate in surveys.

However, Facebook allowed the firm to collect the data of the survey takers’ friends on the social media platform, harvesting the data of millions of Facebook users without their consent, using the information predominantly for political advertising.

After the scandal was revealed in 2018 by a former Cambridge Analytica employee, the event sparked outrage among consumers and governments alike.

Furthermore, the infamous data leak emphasized the importance of data sovereignty, and governments all over the world have been turning an increased focus on this matter to protect their citizens against information leaks.

Which Countries Have Data Sovereignty Laws?

Now let’s take a look at some nations that already have data sovereignty laws in place.

Canada

Canada has 28 data privacy laws, which include federal, provincial, and territorial statutes.

Regarding Canada’s data sovereignty, we should mainly focus on the Personal Information Protection and Electronic Documents Act (PIPEDA) regulation.

Based on Canada’s data sovereignty laws, an organization remains responsible for the protection of the data it transfers to a third-party (even though the service provider is the one processing or handling the information).

Furthermore, Canadian businesses have to reference in their privacy policies and procedures whether they transfer data to third parties outside of the nation’s borders.

The Quebec Privacy Act is more strict with local organizations as they have to ensure that personal information transferred to third parties outside the state would be used only for the intended purposes of the company.

At the same time, the state’s data sovereignty regulation prevents service providers from transferring data to third parties without consent.

If an organization cannot ensure that the third-party service provider outside of Quebec has proper data protection measures, it must refuse the transfer.

California, United States (CCPA)

It’s also important to mention the California Consumer Privacy Act (CCPA), one of the most prominent data privacy laws in the United States.

After becoming effective on January 1, 2020, the CCPA introduced a set of privacy laws for organizations doing business in California that fit one of the following criteria:

  1. Have an annual gross revenue of over $25 million
  2. Buy, receive, or sell the personal data of at least 50,000 households or consumers
  3. Gain over 50% of their annual revenue from selling the personal data of consumers

As per the CCPA, organizations have to disclose the personal data they collect, the purpose of the collection, as well as the third parties they share the information with.

Consumers can demand the deletion of their data from businesses, and they are also able to opt out of their personal information being sold.

In the latter case, the CCPA prohibits organizations from raising the price or changing the level of the service for consumers who don’t want companies to sell their data. However, the data privacy law does allow businesses to offer financial incentives to their customers in exchange for data collection or the ability to sell their personal information.

Furthermore, if the CCPA’s privacy guidelines are violated by an organization, consumers can sue the company.

When California authorities discover a violation of the CCPA’s guidelines, businesses have 30 days to comply with the privacy laws after the regulator’s official notice.

If an organization fails to resolve its issues within that time frame, California regulators can impose a fine of up to $7,500 per record. As there is no upper limit for the fine, a business that processes the data of millions of consumers could pay billions for violating the CCPA.

Unlike the EU’s GDPR, the CCPA does not restrict international data transfers.

European Union (GDPR)

When it comes to data privacy laws, the European Union’s General Data Protection Regulation (GDPR) is what comes to most people’s minds.

After its approval in 2016 by the EU Parliament, the GDPR requires all organizations – within and outside of the European Union – to comply with strict data privacy rules if and when they collect, process, or store the personal information of EU citizens.

We will discuss data sovereignty and GDPR more thoroughly later in this article.

Germany

Germany has been amongst the leaders of data privacy and protection.

Apart from the EU’s GDPR, the European country has implemented the new German Privacy Act (BDSG-new) that restricts data transfers to third countries.

According to Germany’s data sovereignty laws, companies that process the nation’s citizens’ personal information have to fulfill the German government’s data protection requirements, even if they are located outside the country’s borders.

As per the BDSG-new, those who infringe the data protection laws of Germany – for example, illegally transferring data to third parties – could face criminal charges with up to three years in prison.

France

Like Germany, in addition to the GDPR’s rules, France has implemented its own data sovereignty laws to protect its citizens.

Based on France’s Data Protection Act 2, when an organization interacts with the personal information of its citizens – even if it processes the data outside the nation’s borders – it must comply with French regulations in addition to fulfilling the GDPR’s requirements.

Australia

In Australia, data sovereignty laws come in the form of the Federal Privacy Act of 1988 and its Australian Privacy Principles (APPs).

Similar to Canada’s data sovereignty measures, the organization that transfers the data to a third party is responsible for how that service provider handles the information and whether it complies with the APPs.

Also, Australian organizations have to ensure that the third party does not breach the APPs while it processes the data.

Data Sovereignty and the GDPR

The GDPR is one of the most prominent data privacy laws that governments have implemented to protect their citizens’ personal information.

For breaching the GDPR, organizations can be fined by as high as 20 million EUR or by the equivalent of 4% of their global turnover.

After becoming active in 2018, EU authorities have imposed fines of nearly 500 million EUR on organizations that have breached the GDPR’s data protection requirements.

In addition to rules like the right to be forgotten, the GDPR also includes data sovereignty measures.

According to the GDPR, organizations that collect or process the personal information of EU citizens have to store the data within the region or in a jurisdiction that offers similar data protection levels.

Furthermore, no matter where the company stores, collects, or processes the data, it has to comply with the GDPR’s rules in case it handles the personal information of European Union citizens.

What Does Data Sovereignty Mean for Consumers?

From the consumer’s point of view, data sovereignty requirements regulate how businesses interact with their customers’ personal information while preventing third-party service providers from abusing the data.

While data sovereignty requirements are not introduced in every nation and can’t fully protect user data, proper regulations discourage organizations from abusing their users’ personal information.

What Does Data Sovereignty Mean for Businesses?

While consumers are often those who benefit from data sovereignty requirements, businesses must find ways to comply with the relevant data privacy and security laws of each nation.

Therefore, in addition to knowing local, regional, and international data privacy laws, organizations have to develop a new or use existing infrastructure for data collection, processing, and storage that aligns with all the relevant data sovereignty requirements.

Data sovereignty measures could also make things complicated for companies that store their data in the cloud.

For example, an Australian organization has two options to comply with its nations’ data sovereignty laws.

  1. The business can choose a cloud service provider to store and process its data, but it has to ensure that the third party is complying with all the relevant laws and requirements; OR
  2. The business can choose a cloud service that operates as well as stores and processes data exclusively within the national borders of Australia to prevent sensitive personal information from leaving the country.

It’s clear that whichever option the business chooses, it requires some extra legwork from the company’s side.

However, doing so helps ensure that the data of the nation’s citizens remain safe(r) with data sovereignty.

Data Sovereignty: A Crucial Concept That Requires Immediate Attention

It’s good to see that multiple governments are implementing data sovereignty measures to ensure that organizations treat their citizens’ personal information appropriately.

However, despite the strict laws, we are still very far from reaching true data sovereignty.

Businesses can still take advantage of our personal information and use it to increase their profits by selling our info to data vendors while we receive nothing in return.

Permission is determined to end this by creating a next-generation, blockchain-based advertising platform where users have full control over their data.

If a user gives permission to an advertiser to use his data or leverages his time to engage with the advertiser’s campaigns, he gets rewarded in Permission.io’s ASK cryptocurrency.  The user can hold, exchange, or spend the currency in the Permission.io Store.

On the other hand, by only targeting consumers with ads they’ve granted permission for, businesses earn the trust and loyalty of their users while building long-term relationships and achieving a holistic view of their customer’s needs in real-time.

Take a look at Permission’s official website to learn more about the win-win advertising model (including the innovative Permission Browser Extension) that is changing who controls and profits from our data.

Recent articles

Your ASK Wallet, Now Powered by Coinbase

Sep 22nd, 2026
|
{time} read time

We've partnered with Coinbase to bring best-in-class wallet technology to our community.

Today we're updating the technology that powers your ASK wallet. Here's what's changing, what it means for you, and what stays exactly the same.

What's changing

We've moved your Permission wallet to Coinbase's platform. What that means in plain language is this: starting today, you are in full control of your ASK. When you click to send, redeem, or manage your balance, the transaction happens from your account, signed by your login. We no longer hold your wallet keys. Coinbase does, on your behalf, under your authority.

We chose Coinbase's embedded wallet specifically because it brings institutional-grade security to our users without requiring you to manage anything yourself. The infrastructure is Coinbase's. The wallet is yours.

Beyond the custody change, our users now have a wallet that can go wherever they go: exportable, cross-chain ready, and backed by a platform that serves millions of people around the world. We're proud to bring that to our community.

What it means to control your own keys

As Permission has grown, we felt strongly that your funds should be held by a platform built specifically for that purpose, with the security standards and regulatory rigor that come with it. Moving to Coinbase's embedded wallet reflects that commitment.

With today's change, Coinbase secures your private key inside their systems, and only your Permission login can authorize transactions. When you click to send or redeem ASK, the transaction is authorized by you, through your login. We are no longer part of that process.

What this means practically: your wallet operates on its own, independent of Permission. Treat your Permission login like you would a bank password. It is now the key to your wallet. If you ever want to take your wallet entirely outside of Permission, Coinbase supports key export and that option is yours.

What Coinbase sees

Because Coinbase is now part of the infrastructure, your email address, account identifier, and wallet information are shared with them for the purpose of operating the wallet. For details on how Coinbase handles this data, you can review their embedded wallet documentation and their privacy information.

For how Permission handles your data, our Terms of Use and our Privacy Policy govern that relationship, as they always have.

What stays the same

Everything you experience in the app. Earning ASK, redeeming it, transferring it, viewing your balance, managing your family. None of that changes.

And, what does change, we're excited about: key export, cross-chain support, and institutional-grade security. These are capabilities that would have taken years to build in-house and that Coinbase has spent that time perfecting. We chose to partner with the best-in-class, and our product and users will be better for it.

If you have questions, support is always here.

The Permission Team 🤝

What Is Family Friendly AI™?

Sep 9th, 2026
|
{time} read time

Only 15% of people globally say they trust AI systems, and 72% of parents are concerned about AI’s impact on their children.

AI is quickly becoming part of everyday family life, but Big Tech wasn’t built with families in mind. Family Friendly AI is technology intentionally designed for families, giving parents visibility into their children’s digital lives, guidance when they need it, and tools to encourage positive behavior.

5 Things That Make AI Family Friendly

1. Your family owns its data.

‍Your family’s data is never sold. It belongs to your family, and you stay in control of it.

2. Parents know what’s happening online.

‍Family Friendly AI gives parents visibility into their children’s digital lives, helping them fully understand how their children use and interact with technology.

3. It motivates children with rewards and incentives.

‍Parents can set rewards and incentives to encourage positive behaviors and help their children build better habits around technology and beyond.

4. It gives parents coaching and inspiration.

‍Parenting in a digital world comes with challenges that screen-time limits alone can’t help with. Family Friendly AI gives parents personalized AI-insights and guidance to help them navigate what their children are doing online and decide what to do next.

5. It earns families' trust.

‍Technology for families should have a higher bar. The companies building it should stand behind it with an unconditional, no-questions-asked money-back guarantee.

It’s time for AI, crypto, and the technology shaping our children’s lives to meet the family-friendly standard.

Big Tobacco Had Its Reckoning. Now It’s Big Tech’s Turn.

Aug 12th, 2026
|
{time} read time

The floodgates are open.

Thousands of lawsuits are moving forward. States are writing new rules for kids online. And lawmakers are beginning to tell AI companies what they can and cannot do when children use their products.

And you don't have to look far to see it happening...

The courts: 3,000+ lawsuits get the green light

On August 10, the Ninth Circuit allowed more than 3,000 lawsuits against Meta, Google/YouTube, TikTok and Snap to move forward.

The cases allege that the companies deliberately designed features of their platforms to be addictive, particularly for young users.

The tech companies had argued that Section 230 of the Communications Decency Act protected them from the claims. The court rejected their attempt to use Section 230 to stop the litigation at this stage, finding that it provides a defense rather than immunity from being sued.

At their core, these cases are allegations about the platforms themselves: how they were designed, how they kept people engaged, and what responsibility the companies bear for the consequences.

The companies will still have the opportunity to defend themselves against those allegations.

But with more than 3,000 cases now getting the chance to be heard, this is getting harder to argue away.

New Jersey: families get a way to enforce the rules

One day later, New Jersey Governor Mikie Sherrill signed the New Jersey Kids Code Act into law.

The law establishes new design and privacy requirements for covered online services likely to be accessed by minors. Among other provisions, it requires high privacy settings by default, restricts certain push notifications, prohibits dark patterns for minors, limits how children's personal data can be used and retained, and places restrictions on targeted advertising.

But one provision in particular changes the accountability equation: a private right of action.

An individual under 18 who is injured by a violation can bring a claim under the law, with statutory damages of $5,000 per violation. Parents may also bring an action on a minor's behalf.

Which is legal language for something pretty simple: families don't have to wait around for a regulator to act. They can take companies to court themselves.

Colorado: AI safety starts becoming a legal requirement

Then there's Colorado.

Earlier this year, Governor Jared Polis signed Colorado HB 26-1263, establishing specific requirements for operators of conversational AI services.

And this one is worth paying attention to because the law doesn't simply tell AI companies to "keep kids safe." It starts defining what that actually means.

Operators must estimate users' ages. When dealing with minors, the law requires recurring disclosures that they are interacting with AI rather than a person and establishes protections around sexually explicit interactions.

It also addresses one of the most unsettling questions surrounding companion-style AI: emotional dependence.

The law requires safeguards designed to prevent conversational AI from producing statements that simulate emotional dependence. It also requires protocols for responding to suicidal ideation and self-harm, privacy and account-management tools for minors and parents or guardians, and reporting requirements intended to help regulators evaluate whether those safeguards are actually working.

The law takes effect January 1, 2027.

For companies building conversational AI, that's a meaningful shift. Child safety is moving beyond a set of voluntary guardrails companies write for themselves. In Colorado, some of those guardrails are becoming law.

It's no coincidence that this is all happening at once.

Big Tobacco didn't wake up one morning and discover the world had changed its mind. The reckoning came piece by piece, until lawsuits became regulation and an industry that had spent decades setting its own standards was finally forced to take responsibility for the harm its products caused.

We're watching that shift happen again.

For years, the responsibility for keeping kids safe online has fallen on parents.

Set the parental controls. Check the privacy settings. Watch the screen time. Know which apps they're using. Figure out who they're talking to. Keep up with every new platform, algorithm and now AI chatbot entering their lives.

All while the technology on the other side of the screen gets more sophisticated by the month.

Now courts and lawmakers are starting to ask the companies building that technology a much more uncomfortable question:

If children are using your products, what are you doing to keep them safe?

For families, that's the shift that matters most.

This isn't another round of false promises to "do better."

This is legislation. These are lawsuits. This is accountability beginning to have teeth.

Parents will always have the role of protecting their children online. We happen to believe they should have far more visibility and control over the technology entering their families' lives, not less.

But parents cannot be the entire safety system.

The law is making clear that the companies designing the products, writing the algorithms and building the AI our kids interact with have a responsibility, too.

And when they fail to meet it, they'll finally be held accountable.

ChatGPTs Births A Parenting Tool That Needs Some Image Repair

Aug 4th, 2026
|
{time} read time

Sam Altman keeps pitching AI as a co-parent. The reason parents aren't buying isn't nostalgia, it's the lawsuits.

Last Friday, Sam Altman had an idea he was excited about. Hook your family calendar up to ChatGPT, tell it what your kids are into, and every morning on the drive to school it'll produce a little podcast: one kid's soccer game that afternoon, another kid's birthday coming up, maybe some news. He called it a "cool use case."

What should’ve felt really innovative, landed like the opening scene of a bleak dystopian movie. Two kids in the back, one parent up front, and a smooth synthetic voice narrating, to everyone present, the lives of everyone present. "Later today, Maya has soccer." Maya, who has soccer, looks out the window. Nobody says anything, because the podcast is saying it for them.

The internet population caught what we caught. The reply that stuck came from Alex Hirsch, creator of Disney’s Animated series, Gravity Falls. It was seven poignant words: "What if you just talked to your children?" That was the entire rebuttal, and it traveled a great deal further than the thing it was rebutting. Altman's post drew somewhere around 9,600 likes. Hirsch's reply cleared 120,000. On the CEO's own platform, the crowd took a vote, and the crowd chose the small talk.

Now, we want to be fair here, because the easy thing is to dunk and move on. But we’re parents here at Permission and anyone who has done the 7:40 a.m. drive on four hours of sleep, refereeing a backseat dispute about who touched whom first, knows the exact fantasy of a button that handles the morning. That instinct isn't a character flaw. It's a Tuesday.

But this wasn't a one-off. Altman has been quietly auditioning AI for the co-parent role for a while now. On The Tonight Show in December 2025 he said he couldn't imagine having to "raise a newborn without ChatGPT" then added that people had managed the trick for a few hundred thousand years without it. Also, last year, in a podcast hosted by Andrew Mayne, Altman admitted that people might form “problematic parasocial relationships” to a chatbot. (You know, the one-sided kind that we usually reserve for celebrities we've never met.) He sees the hazards clearly. He's pitching the product anyway.

When visibility turns into vulnerability.

The reason parents flinched at the idea of carpooling with a chatbot for school drop off isn't that they're allergic to convenience. It's that the company making the offer is, right now, being sued by multiple families who say its chatbot played a role in their loved ones' spiraling delusions and, in the worst cases, their deaths. OpenAI says it is continually improving how its models handle sensitive conversations, and that work genuinely matters. But you can see the problem. "Let me into your calendar, your commute, and your kids personal details" is a big ask from anyone. It is a much bigger ask from a company currently explaining itself in court.

Trust isn't a feature you ship in the next update. It's something people hand you slowly, and take back all at once.

Here's where we should admit an interest. We build Permission on a belief that sounds boring until you sit with it: your data belongs to you. With Permission your kids’ browsing history doesn’t get shipped out to the open internet. Not to a model, not to a growth chart, not to whoever posts the next cool use case. And the closer AI creeps toward our kids (and it is creeping, because kids are already asking it everything) the more one question starts to outrank all the others:

Where is the line between parenting and outsourcing parenting?

Because "parenting tool" is doing a lot of quiet work in that phrase. A tool is a hammer. It lives in a drawer, it does one honest thing, and it does not ask to read your child's messages or move into the family calendar. When a company calls its chatbot a "parenting tool," it's worth asking, gently, which word they mean. The tool part, or the parenting part.

We happen to think AI can be genuinely, unglamorously useful to families. Not by doing the talking for you, but by handing you the context you'd otherwise miss instead of a thousand panicked notifications, and then getting out of the way so you can make the call. That's a real distinction, and it deserves its own piece.

So take this as Part One: the news, the flinch, and the reason the flinch is earned. In Part Two, we'll make the harder and more hopeful argument that you can let AI help you parent without completely handing over your family secrets. There is a version of this where the grown-ups stay in charge. We think it's the only version worth building.

For now, the seven best words anyone has offered on the whole affair still belong to Hirsch. So we'll give him the last one, too.

What if you just talked to your children?

‍