19 Feb Data sovereignty: Why it matters for physical security
Firas Jadalla, Regional Director META, Genetec explores the risks of cross-border data transfers, outlines what organisations should look for in a technology partner and highlights how sectors such as public safety, healthcare, government and higher education are adapting.
When most physical security leaders think about risk, they focus on preventing theft, protecting facilities or ensuring people are safe. Increasingly, though, the risks also involve the data generated and stored by physical security systems. Surveillance video, access control logs and IoT sensor readings are among an organisation’s most sensitive assets. As more systems move into the cloud, hosted in data centres around the world, the question of data sovereignty (where that data resides, who governs it, and how it can legally be used) has become a central concern for the physical security industry. This is not only a matter of meeting privacy regulations; it’s also essential for ensuring operational resilience, protecting national security interests and maintaining stakeholder trust in an era of globalised digital threats.
The risks of crossing borders
Why does it matter where data is stored? Because once information crosses national borders, it becomes subject to different, sometimes conflicting, laws. This can introduce certain risks, such as:
Compliance penalties: Regulations such as GDPR in Europe, the CCPA in California, India’s Digital Personal Data Protection Act and the Australian Privacy Principles (APP) impose strict guidelines on how personal data can be transferred internationally, and non-compliance can result in large fines.
Loss of control: Data stored outside a jurisdiction may be accessible to foreign authorities, creating uncertainty about who can demand access and under what conditions.
Geopolitical exposure: This loss of control particularly matters in times of political tension, when the flow of data across borders can create points of vulnerability, especially for critical infrastructure and other data of national interest.
Operational disruption: If a regulator restricts access to data stored abroad, organisations may lose visibility into incidents just when they need it most.
What to look for in a technology partner
Meeting data sovereignty obligations is not just about an organisation’s internal policies. It also depends on the technology partners they select. When evaluating vendors, there are several areas physical security leaders should pay close attention to:
Built-in privacy safeguards: Security systems should incorporate features such as role-based access controls, anonymisation tools and detailed audit trails. These capabilities ensure that sensitive data is handled responsibly from the start, rather than being bolted on after deployment.
Deployment flexibility: Organisations need options. In some cases, storing all data on-premises makes the most sense. In others, cloud hosting is appropriate. Often, certain workloads are kept locally while others are processed in the cloud, which provides the right balance. The important point is that systems should allow for choice rather than forcing a one-size-fits-all model.
Alignment with global regulations: Laws can change and, when technology is involved, things could move quickly. Systems that can adapt to evolving requirements give organisations confidence that they will remain compliant over time. This includes the ability to demonstrate where data is stored, both primary and redundant copies and how it is managed, even if regulations shift.
Practical steps for strengthening data sovereignty
For physical security leaders, there are clear actions that can help strengthen data sovereignty:
Map the legal environment: Identify which regulations apply to your organisation across all the regions where you operate. Physical security data should be included in this assessment alongside IT data.
Ask providers the right questions: Where will the data be hosted, including backups? How will it be processed? What are the options for local residency? Can you demonstrate compliance with applicable laws? What are their policies about accessing data when requested by government entities?
Plan for change: Assume that regulations will evolve. Choose technologies and architectures that can adapt without requiring complete replacement.
Invest in governance: Establish internal policies that cover how data is accessed, shared and retained. This will help ensure consistency across sites and departments.
How organisations are adapting
Across industries, many organisations are reshaping their security strategies with data sovereignty in mind. Public safety agencies, for example, host investigative data within national borders to comply with local privacy laws.
That same thinking is influencing decisions in higher education. At the University of British Columbia (UBC), for example, data sovereignty was central to their evaluation of Genetec Cloudrunner™, a cloud-native vehicle-centric investigation system that helps public safety agencies and security teams detect, analyse and respond to vehicle-related crime.
“One of our primary considerations during the evaluation of Cloudrunner was ensuring that all collected data would be securely stored and remain within Canadian borders,” said Jeff Joyce, Manager – Parking Services at UBC. “Data sovereignty was a non-negotiable priority for us, as it not only addresses regulatory requirements but also reinforces our commitment to protecting sensitive information and upholding the trust of our campus community.”
Enterprises in transportation and energy are also rethinking vendor selection criteria. They increasingly expect systems to provide clear options for local hosting and to demonstrate compliance with multiple regulatory frameworks. In practice, this means evaluating platforms not only for technical capability but also for how well they support governance and accountability.
A shared responsibility
With more than 130 countries now enforcing some form of data protection law, data sovereignty has become a collective responsibility. IT, physical security, executive leadership and regulators all play a role in ensuring that sensitive information is protected and compliant with local requirements.
Physical security teams are at the centre of this evolution. Alongside their core mission of protecting people and assets, they now need to ensure the sensitive data generated in the process is governed appropriately. That means making careful technology choices that can stand up to changing regulations.
As cloud adoption accelerates and privacy laws continue to evolve, data sovereignty will only become more important. The organisations that succeed will be those that make it a strategic pillar of their cyber and physical security posture.
This feature appeared in issue 146 of Security Middle East magazine.
Sorry, the comment form is closed at this time.