What data sovereignty actually means for humanitarian communications

Mzuri Mwakidedi
09/10/2026 18:26 Comment(s)

The face of the moon was in shadow

Data sovereignty is one of those phrases that appears in a requirements document without anybody being sure what it obliges them to do. In humanitarian and peacekeeping operations it has a precise and consequential meaning, and getting it wrong has consequences that are not administrative.

The plain definition

Data sovereignty is the principle that data is subject to the laws of the country in which it is physically stored. Not the country of the organization that collected it, and not the country of the person it concerns. Where the server sits determines which government can compel access to what is on it.

That is the whole idea. Everything else follows from it.

Why it matters more in humanitarian work than almost anywhere else

Most organizations reason about data protection in terms of fines. Humanitarian operations have to reason about it in terms of people.

A beneficiary list is a list of who received assistance. In a stable context that is an administrative record. In a contested one it can identify who cooperated with an international organization, which community received support and which did not, and where vulnerable people are living. A staff roster shows who is where. Movement coordination shows where a convoy will be and when.

The humanitarian principles of neutrality and independence are not only ethical commitments. They are operational protection. An organization that is understood to hold data a party to a conflict can obtain (lawfully or otherwise) is an organization whose neutrality is in doubt, and its staff and beneficiaries carry the risk of that doubt.

The four questions that establish your actual position

1. Where is the data physically stored?

Not the vendor's headquarters. Not the region named in the console. The physical location of the servers, including replicas and backups, which are frequently in a different jurisdiction from the primary.

2. Which legal regimes reach it?

The jurisdiction of the hosting location, the jurisdiction of the parent company, and any framework that permits cross-border compelled access. A provider can be entirely honest and still be subject to an order it cannot disclose.

3. Who holds the keys?

End-to-end encryption changes this question materially. If the provider cannot decrypt content, compelled access yields metadata rather than messages. Metadata is not nothing (who spoke to whom, when, and how often is often sufficient to cause harm), but it is a different exposure.

4. What happens at the end?

Deletion, retention and the treatment of data when a programme closes or an organization withdraws. Retention defaults set for a commercial market are rarely appropriate for a protection context.

The Kenyan dimension

Kenya hosts a substantial community of international organizations and regional humanitarian operations, and it has a developed data protection regime. The Data Protection Act imposes obligations on data controllers and processors, including in relation to transfers of personal data outside Kenya. Organizations operating here are frequently subject both to Kenyan law and to their own institutional data policies, and the two do not always point the same way.

That combination is why deployment choice tends to decide these procurements. A platform that can only be consumed as a public cloud service in another jurisdiction cannot satisfy a requirement to keep data in-country, however good it is otherwise.

Deliberately general on Kenyan legal detail. The Data Protection Act's transfer provisions are specific and this is a blog article, not legal advice. The Privacy & Data Protection Notice carries BCE's own position.

What sovereign deployment looks like in practice

  • On-premises, where the platform runs on infrastructure the organization controls, in a location it chooses
  • Private cloud in a specified jurisdiction, where control of the physical infrastructure is not required but control of the location is
  • Hybrid, where sensitive functions are held in-country and less sensitive ones are not
  • Federation, where separate organizations run their own deployments and connect them, so that no single party holds everybody's data

Federation is the option most often overlooked and it maps unusually well onto humanitarian coordination, where several independent organizations need to work together without any one of them becoming the custodian of the others' communications.

The uncomfortable trade-off

Sovereign deployment costs more. It requires infrastructure, administration and someone accountable for keeping it running. Public cloud is cheaper, better maintained and usually more reliable than what a mission can operate itself.

So the question is not which is better in the abstract. It is whether the data you hold could be used to harm the people it describes. If it could, the cost of sovereignty is part of the cost of the programme. If it could not, paying for it is a way of feeling careful rather than being careful.

Metadata is the part people underestimate

Organizations that have understood the sovereignty question often still assume that end-to-end encryption resolves it. It resolves the content question. It does not resolve the pattern question.

Who contacted whom, at what time, how often, from where, and in what groups; that is metadata, and in a protection context it can be more revealing than the messages themselves. A sudden increase in traffic between a field office and headquarters, a group that adds three new members the day before a movement, a device that stops appearing in one location and starts appearing in another. None of that requires reading a single message.

So the question to ask a provider is not only whether they can read your content. It is what they retain about the fact of your communication, for how long, and where that record sits. Platforms differ substantially here, and the difference is rarely on the front page of the datasheet.

Where to start

Before selecting anything, write down what you actually hold: beneficiary identities, staff locations, movement plans, incident reports, communications with authorities. Then ask, for each category, what happens if a party to the local context obtains it. Most organizations find the answer varies sharply by category, and that a single platform decision applied to everything is either too expensive or too exposed.

Discuss a Requirement

Mzuri Mwakidedi