Research
How the law of sovereignty applies when territory, data, and jurisdiction no longer coincide.
Sovereignty is a foundational principle of international law: the supreme and exclusive authority of a state over its territory. It carries a matching obligation on every other state to respect that authority.
For the canonical statement, see the Island of Palmas Case (Netherlands v. United States), Permanent Court of Arbitration, 1928, in which Max Huber described sovereignty as the right to exercise the functions of a state to the exclusion of all others.
The open question is how this principle holds when territory, data, and jurisdiction no longer coincide. The Centre’s work engages three positions, each more precise than the last.
Existing international law, including the UN Charter, applies to state conduct in cyberspace. The 2015 UN Group of Governmental Experts confirmed that states have jurisdiction over the ICT infrastructure within their territory. Authority still follows physical location.
An extension addressing state authority over data as it moves within and across borders, and over the platforms that carry it. First articulated in France in 2014, it gained force through the EU General Data Protection Regulation in 2018. The model is still territorial: the concern is data and platforms operating inside state borders.
A proposed extension addressing state authority over data regardless of where it physically resides. It holds that a state retains, or ought to retain, the exclusive right to control access to its data even when that data has been replicated to infrastructure in another jurisdiction.
This position was necessitated by the extraterritorial reach of legislation such as the United States CLOUD Act, which can oblige a US-registered provider to produce data on lawful demand wherever that data is stored.
The following scenario is illustrative and uses the neutral form common to international law case examples. States B and C are not identified.
Neither technological nor digital sovereignty offers a remedy, because neither reaches data that has moved beyond the originating state. Data sovereignty, as lex ferenda, proposes that the law must follow the data rather than the infrastructure. It awaits adoption by a state to begin its passage toward customary international law.
The Centre draws on the following peer-reviewed research to establish and recognise data sovereignty as an emerging norm of international law, lex ferenda, the law as it ought to become.