New research shows 88% of executives believe a data sovereignty failure could cost them their job, yet 64% of organisations still have no formal strategy in place. For UK infrastructure buyers, that gap between fear and readiness is now a boardroom liability, not a niche IT concern.
View the data behind this chart
| Cyber security | Political disruption | Extraterritorial access | |
|---|---|---|---|
| Executives citing driver | %47 | %26 | %9 |
What the Everpure survey actually found
Storage and data management supplier Everpure released its Global data sovereignty report 2026 at its Accelerate event in London this week, based on a Vanson Bourne survey of 2,100 C-suite and IT leaders across the UK, France, Germany, Australia, Japan, South Korea, Singapore and India, carried out in June 2026.
The headline numbers are stark: 88% of leaders fear a sovereignty failure could cost them their job, and 91% worry about financial and reputational damage from a sovereignty failure. Yet 64% of organisations operate without a formal data sovereignty strategy, and 90% recognise sovereignty as a business concern while 62% admit they lack visibility into who can access, control and manage their data. Everpure frames this as a 'sovereignty gap' — executive anxiety running well ahead of operational control.
Why UK buyers should read this as a resilience issue, not a tick-box exercise
Everpure's chief technology officer for international, Alex McMullan, put it plainly: "Senior leaders understand their jobs are on the line over data sovereignty, yet many are still focused on the wrong risks. Sovereignty is not simply about where data is stored, but having full visibility and control over it through modern data management."
That distinction matters for UK procurement teams because location alone has never been the whole story. IBM describes sovereignty as including control over data at rest, in use and in motion, including access, keys, logs and audit evidence. For teams working through UK GDPR compliance for IT teams, that means residency certificates alone won't satisfy a regulator or a board asking who can actually reach the data and under which jurisdiction's laws.
Executives are worrying about the wrong risks
Perhaps the most useful finding for buyers building a business case is the mismatch in risk priorities. Everpure's survey found 47% of leaders cite cyber security as their leading sovereignty driver, while only 26% flag service disruption from political uncertainty and just 9% prioritise protection from extraterritorial data access. Some foreign laws may enable authorities to seek provider-held data, subject to their scope and applicable legal process — a risk that receives comparatively little attention in survey responses despite its potential significance.
Everpure also found that a third of organisations tie sovereignty to their AI initiatives, treating data control as a precondition for AI adoption rather than something bolted on afterwards. That's a shift worth planning for: any procurement decision around AI tooling should now include a sovereignty and access-control review from day one, not a retrofit once the AI project is already live.

'Sovereignty by design': what it means in practice
Everpure's proposed fix is what it calls 'sovereignty by design' — moving from a national, location-based view of sovereignty to a corporate one, applying controls based on the risk profile of each dataset, application and workload rather than a blanket policy. Patrick Smith, Everpure's chief technology officer, framed this as a strategic rather than tactical exercise, and the company says its Data Intelligence software is built to discover, classify and contextualise data across its own platform, public clouds, SaaS applications and third-party storage so organisations can decide governance rules dataset by dataset.
IDC's Rahiel Nasir, research director and lead analyst for worldwide digital sovereignty, described the issue as having moved from a compliance conversation to a board-level one — where the real test isn't just knowing where data sits, but proving total control over access, transfers and metadata. As a matter of general procurement practice rather than a specific survey finding, contracts with cloud and storage suppliers should include enforceable SLAs, audit rights, breach-notification duties and remediation commitments, not just technical promises about where servers are located.
A practical audit checklist for UK infrastructure buyers
Whatever platform or supplier sits underneath, the responsibility for security and compliance cannot be outsourced. The Computer Weekly analysis of UK public cloud data sovereignty recommends audits, data-residency certification and security benchmarking mapped against frameworks such as GDPR, ISO 27001 and PCI DSS, backed by risk assessments and a multi-supplier strategy rather than reliance on a single provider's assurances — recommended governance measures rather than uniform legal requirements.
With European regulators having issued approximately €1.2bn in GDPR fines during 2025, according to the annual survey reported by The Register, and the Irish DPC saying it has issued €4.04bn in fines since May 2018, the cost of getting sovereignty wrong is measurable and growing. UK buyers weighing where responsibility sits internally versus with suppliers should treat auditing data residency as a recurring exercise tied to the wider UK regulatory landscape, not a one-off project.
- •Map where regulated data is stored, processed and transferred, and which laws apply at each point
- •Verify supplier contracts include audit rights, breach notification and remediation clauses
- •Classify datasets by sovereignty risk rather than applying one policy to everything
- •Build sovereignty checks into AI procurement from the outset, not after deployment
View the data behind this chart
| Awareness | Gap | Action | |
|---|---|---|---|
| Job & reputational risk | 88-91% cite risk | 64% no formal strategy | Build sovereignty strategy |
| Data visibility | 90% flag as concern | 62% lack access visibility | Map data access & flows |
| Risk prioritisation | 47% cite cyber risk | 9% flag extraterritorial access | Reassess risk drivers |
| AI & sovereignty | AI adoption rising | 1/3 tie sovereignty to AI | Embed controls pre-AI rollout |
Closing the gap: where to start
For most UK organisations, closing this gap starts with visibility rather than new tooling. Before building a formal data sovereignty strategy, buyers need an honest inventory of who can access what, across on-premises systems, public cloud and SaaS. That's the groundwork for addressing compliance gaps credibly, and it pairs naturally with broader cyber security services work such as zero trust access controls, which enforce exactly the granular, risk-based permissions that sovereignty by design requires.
The Everpure findings suggest boards already sense the exposure. The task for IT and procurement leaders now is turning that anxiety into an auditable, evidenced programme — one that satisfies regulators, survives scrutiny, and doesn't leave the organisation's sovereignty posture resting on trust in a single supplier's word.
- 01Computer Weekly — Everpure survey: 88% of executives fear data sovereignty failures · 30 September 2026
- 02Everpure Blog — Sovereignty's Data Imperative · 30 September 2026
- 03Computer Weekly — Public cloud: Data sovereignty and data security in the UK · 30 September 2026
- 04IBM — Digital sovereignty · 30 September 2026
- 05IBM — GDPR · 30 September 2026
- 06The Register — Europe's GDPR cops dished out €1.2bn in fines last year · 22 January 2026
- 07techradar.com
- 08computerweekly.com
