Most organisations would quite happily have more data. More supplier data can improve forecasting. Partner data can help companies understand customers beyond their own part of the journey. Industry data can reveal patterns no single organisation could see alone. 

And as AI systems become more capable, access to broader and better information is becoming even more valuable. The awkward part comes when everyone has to contribute. According to the UK Government’s UK Business Data Survey 2026, only 14 per cent of businesses handling digitised data said they shared data outside their organisation. 

The figure rises to 40 per cent among large businesses, but the broader picture is still one of fairly limited exchange. Organisations may recognise the value of other companies’ data while remaining understandably protective of their own. That tension has helped shape the data sovereignty conversation

em360tech image

Usually, sovereignty is treated as something defensive. Keep sensitive information under the right jurisdiction. Know where it’s stored. Reduce dependence on providers you can’t control. But new research suggests there may be another side to it. If an organisation knows it can keep meaningful control over data after sharing it, sovereignty may not restrict movement at all. 

It could be one of the things that makes sharing feel possible.

Data Sovereignty Isn't The Same As Keeping Data At Home

Data residency and data sovereignty are often discussed as though they mean roughly the same thing. They don’t. Data residency describes where information is physically stored. Data sovereignty is about who retains meaningful authority over that information and what can happen to it. 

Location still plays a part, particularly when different national laws apply, but it’s only one piece of the problem. A useful way to separate the concepts is to ask five different questions:

Concept Core Question
Residency Where is the data?
Jurisdiction Which laws apply?
Control What can others do with it?
Portability Can it be moved?
Revocation Can access be withdrawn?

The distinction becomes much more important when data leaves systems an organisation directly controls. Keeping a customer database in your own environment is relatively straightforward. Sharing part of it through a partner ecosystem, data marketplace or industry data space introduces another question entirely: what rights do you still have once somebody else can use it?

Current enterprise thinking is already moving in this direction. In the 2026 Thales Data Threat Report, 45 per cent of respondents said some form of portability across software, data or operations was the main driver behind their sovereignty initiatives. Another 34 per cent specifically wanted full control over software and data to preserve future portability.

So the harder sovereignty problem isn’t necessarily deciding where data can go. It’s deciding whether your control over it survives once it gets there.

Control Could Change The Data-Sharing Equation

Researchers Antragama Ewa Abbas, Anneke Zuiderwijk and Mark de Reuver examined exactly this question in an August 2026 study published in Technology in Society. Their starting point was surprisingly basic. 

Data sovereignty is routinely presented as important to successful data marketplaces and ecosystems, yet there hasn’t been much empirical evidence showing whether it actually changes organisations’ willingness to provide data. Their findings suggest it does.

Across the research, greater perceived sovereignty increased participants’ willingness to share business data. It also reduced perceived risk, which was itself associated with greater willingness to share. In practical terms, people became more comfortable with the idea of providing data when they believed the organisation supplying it retained meaningful ownership and control.

There are limits to how far we can take that finding. The research examines willingness and behavioural intention rather than proving that every enterprise given stronger sovereignty controls will suddenly start exchanging its most valuable information. Commercial sensitivity, regulation, intellectual property and competitive risk don't disappear because the technology improves.

But it does challenge a familiar assumption. Data sovereignty doesn't necessarily sit opposite openness. Under the right conditions, greater control can lower one of the barriers that stops useful data from moving in the first place.

Control may reduce how much trust organisations need

The most interesting part of the study may actually be what happened with trust. The researchers found that higher perceived sovereignty increased trust. Yet trust itself didn't significantly increase participants’ willingness to share data in the two main studies. They suggest that strong control mechanisms can partly substitute for relational trust.

Think about the difference. One approach asks an organisation to trust that a partner will follow the rules once it receives the data. The other gives that organisation ways to monitor usage, restrict what the partner can do and intervene if the agreement changes or something goes wrong.

Trust hasn't disappeared. Companies will still care who they're dealing with, particularly where commercially sensitive information is involved. But the consequences of misplaced trust become easier to contain. This becomes even more useful as enterprise data ecosystems grow beyond familiar bilateral partnerships

Trusting one long-standing supplier is one thing. Sharing information across marketplaces, interconnected data spaces and chains of organisations you don't directly manage is something else. In those environments, designing control into the relationship may be more reliable than expecting trust to carry the whole thing.

Data Sharing Changes When Control Travels With The Data

Of course, saying an organisation owns its data is relatively easy. Making that ownership useful after the data has been shared is harder. The August study separates ownership rights from practical control for precisely this reason. An organisation can technically retain rights over information while having very little ability to see how it’s being used or stop that use later.

Sovereign data sharing needs control that can travel with the data.

A useful progression is:

Rights → Visibility → Usage Control → Enforcement → Revocation

Rights establish what an organisation is entitled to decide. Visibility makes it possible to see where data has gone and how it’s being used. Usage controls define what recipients are permitted to do with it, while enforcement turns those restrictions into something more substantial than a clause buried in a contract.

Then comes the difficult part: what happens when permission ends? Access might need to expire after a project. A supplier relationship may end. A participant could leave an ecosystem. Data might have been copied, transformed, combined with other information or used to create something new.

This is where data provenance, auditability and revocation become important. It isn’t enough to press a button labelled “revoke” if nobody can verify what happened afterwards. Portability creates a similar problem. An organisation that can share its information but can't move it somewhere else without rebuilding processes or accepting significant disruption may still have less control than it appears to.

The further data travels through an ecosystem, the more these questions compound. Which is why sovereignty starts looking less like a location setting and more like an ongoing capability.

From Data Protection To Data Participation

This opens up a more useful way of thinking about sovereignty. Instead of treating it only as infrastructure for protecting data, organisations can begin asking whether it could also provide infrastructure for participation. Europe's evolving data strategy offers a good example of the idea. 

The European Commission’s Data Union Strategy is trying to increase access to high-quality data, particularly for AI, while also strengthening European data sovereignty. Its position isn't that sovereignty requires shutting down international exchange. It explicitly combines sovereignty with openness to trusted partners, provided data can move under fair and secure conditions.

Common European Data Spaces follow the same logic. They’re designed to make information available for reuse while allowing businesses, public bodies and individuals to retain control over the data they generate. The Commission describes secure exchange and continued control as complementary parts of the same model.

Are you enjoying the content so far?

There’s a practical reason for building systems this way. Data spaces, supply-chain networks, research partnerships and other collaborative ecosystems only become useful if organisations contribute information as well as consume it. AI adds another layer

Companies increasingly want diverse, high-quality information for analytics, models and automated systems, while those same technologies make it harder to understand where information could eventually travel or how it might be reused. 

The 2026 UK survey found businesses already using AI reported more developed data practices, including higher rates of data sharing, than businesses that weren't using it. None of this means sovereignty creates a reason to share data where one doesn't already exist. There still needs to be commercial or operational value on the other side.

But where organisations already want to collaborate and loss of control is holding them back, stronger sovereignty mechanisms could change the calculation.

The Better Question Is What Happens After You Share

Enterprise data-sharing decisions often focus heavily on the recipient. 

  • Who are we giving this to? 
  • Where will they store it? 
  • Which contract applies?

Those are sensible questions. They're just not enough once data starts moving through larger ecosystems. A more useful data-sharing strategy also asks what remains controllable afterwards:

  • Can permitted uses of the data be defined precisely?
  • Are those restrictions technically enforceable, or do they exist only in a contract?
  • Can we see where the data travels and how it’s being used?
  • Can access expire automatically or be withdrawn?
  • Can we verify that revocation has actually taken effect?
  • What happens to copies, derivatives or AI models created using the original data?
  • Which jurisdictions govern the data, recipient and underlying infrastructure?
  • Can we move our data or leave the platform without becoming trapped by technical dependencies?
  • What happens if the original recipient shares the data with someone else?

Not every organisation will need the same answers. A research collaboration using low-risk operational data isn't the same as a financial services ecosystem exchanging sensitive customer information. But the principle holds across both. The real test of sovereignty begins when the data is no longer sitting somewhere you directly control.

Final Thoughts: Control Could Make Data More Shareable

Enterprises have spent years being told that extracting more value from data requires breaking down barriers and making information easier to access. That sounds reasonable until the information being opened up happens to be yours.

The emerging research adds some useful nuance to that problem. Organisations may not have to choose between protecting data and participating in the wider data economy. Stronger sovereignty can reduce perceived risk by preserving meaningful control after information has been shared.

It won't make every dataset suitable for collaboration. It won't remove legal obligations, competitive concerns or the possibility that another organisation behaves badly. What it may do is reduce how much of the relationship depends on simply hoping they don't.

And that brings us back to the original tension. Most organisations want access to richer data than they can generate alone. Building the ecosystems needed to provide it may depend on giving every participant enough control to contribute without feeling as though they're surrendering something they can't get back.

As data architecture, governance and AI continue pushing information across more organisational boundaries, EM360Tech will keep following the decisions shaping who controls that data, how it can be used and what enterprises become willing to do with it next.