# What does data sovereignty mean in practice?

What does real control over data require - and how do we avoid control becoming just a promise on a website?

Canonical: https://ideallya.com/en/perspectives/data-sovereignty-in-practice/

Author: Ideallya

Published: 2026-09-17

Updated: 2026-09-17

## Control must be concrete

Control must be understandable and usable. It is not enough to say that the data is yours if you do not know which information exists, what it is used for or who gets access to it.

## From access to practical choices

We use data sovereignty to mean the ability to have real influence over the use of data. For an individual, it may concern information that describes interests, choices or needs. For an organization, it may concern expertise, capacity, agreements and information shared with collaboration partners. What can be decided by whom must be clarified for the specific information and use.

## The trade-off: freedom and complexity

It first requires access. Then understandable purposes and clear access boundaries are needed. Real freedom of choice also requires that it is possible to correct errors and end or change a use, and that it is practically possible to switch service where the data can be taken along.

This has a cost. More choices can mean more to administer. Boundaries that are too tight can make useful collaboration difficult. Control should therefore be built into good defaults and explained where a decision is made, rather than gathered in an unclear set of settings.

## Our position

Our position is that data sovereignty should make safe and useful use possible. Each service must show what is actually available, and how the user can get help when a control is not yet self-service.

## Worked example: leaving a viewing group

Imagine a service that helps a group choose a film. You contributed three preferences and a short list of films you have already watched. When you leave the group, make three separate requests: inspect what was stored, correct any wrong preference, and end the group's future access. Ask whether the service keeps a copy and why. These are distinct decisions; one button labelled ‘leave’ does not explain all of them.

A useful record of your choice states the recipient, the information covered, the purpose and when access ends. Check the result by reopening the group view or obtaining confirmation. An export should explain the fields well enough for another tool to use them. Removing access does not necessarily remove copies already received.

This is a design example for evaluating a service. For personal information, legal rights and exceptions depend on the situation. The EDPB guide below explains access, correction, deletion and portability in more detail.

[EDPB: a practical guide to individual rights](https://www.edpb.europa.eu/sme/be-compliant/respect-individuals-rights_en)

## Try the question on a service you use

Can you find out which information is used about you, who receives it and how you correct an error? If the answers are hard to find, control is hard to exercise.
