The UK Department of Science, Innovation, and Technology (DSIT) has released new guidance to public sector organisations looking to host their cloud data in multiple regions.
This comes at a time when many nations seek capabilities to increase their data sovereignty – the maintenance of their data in their home nation, with their native data regulations.
The new guidance recommends public sector bodies to adopt a “multi-region approach” for their data storage, with full acknowledgement that this may well mean public body and government data is housed in data centres outside of the UK.
“We recommend that organisations adopt a multi-region approach in which they make controlled, considered use of regions in a way which is compatible with UK law,” the guidance document, which was seen by Computer Weekly, said.
The new guidance also says that this is not a change of policy – even ‘official’ government data can be stored and processed in foreign data centres and cloud storage facilities, as long as “satisfactory” data protection and security measures are taken.
The document noted that, in many instances, this is already the case as more and more organisations take advantage of software as a service (SaaS) products which are not solely hosted or operated in the UK.
Public bodies could risk losing out on cost-effective, more advanced SaaS options if they were limited to those that operated exclusively in the UK.
“It can be prohibitive for smaller vendors to provide an entire capability within every geography worldwide because of the level of expense and complexity,” DSIT‘s guidance said.
Further, to improve resilience outcomes, DSIT acknowledges that some organisations disaster response requirements may be too broad for UK public cloud regions to handle, making overseas cloud storage options even more vital.
DSIT says its goals with the new guidance is to provide legal clarification to public bodies looking to move some of their data services to overseas bodies, which it encourages as an option to keep public services up to date as technologies emerge and data capabilities and reliance transforms.
Recommended reading
- Half of UK Orgs Say Data Sovereignty Is Crucial
- Data Security Gap Threatens European Collaboration
- Scots Businesses Trailing UK on Data & Security
However, the guidance does come at a crucial time for data sovereignty in Europe as a whole as nations grapple with changing data demands sparked by the rapid expansion of AI and its data requirements.
About half of UK organisations say that data sovereignty is crucial – this means having full access to one’s data, as well as a full understanding and control over how and where that data is transferred.
As laws continue to change, the guidance should provide vital information to public organisations with expanding data needs as they legally manage their data overseas, which often means contending with varied data laws and regulations.





