Privacy · research july 2026 · published 2026-08-03 · v1 · 3 min read
Sovereignty relocates trust
Holding your own database moves the trust boundary from technical to legal, and the person who did not choose the tier pays the difference
What actually changes when an institution takes custody of its own data, argued from the section of our own architecture that concedes the point we would be assumed to resist. The canonical treatment of trust relocation.
Data sovereignty sells itself. Hold your own database, answer to nobody, and the vendor with the security team and the compliance department stops being a party to your clients’ most private material. We build for this and we think it is often the right choice. It is also the argument we most want to state against ourselves, because the version of it that circulates is missing the party it most needs to name.
European law has been precise about who is responsible since 2018 and the precision matters here. Article 4 defines the controller as the party that determines the purposes and means of processing. Article 24 puts on that controller the duty to implement appropriate technical and organizational measures and to be able to demonstrate that the processing complies. Self-hosting changes none of it. An institution that moves the database under its own roof was already the controller and remains the controller, having simply become its own processor as well, and the erasure right a person exercises under Article 17 was always exercised against the controller rather than against whoever happened to be running the servers.
Which is where the honest accounting starts, and our own architecture notes make it in a section written to be uncomfortable. The threat model for a sovereign deployment treats the institution as the trusted role and has no adversary type for the data controller themselves. The mechanism, stated plainly, is that relocating the database adds no adversary to that model and removes none, but it converts the constraint on the party most able to read everything from a technical control into a legal obligation, and legal obligations bind after the query rather than during it. The comparison people reach for, a therapist opening a paper file, understates it by a wide margin. A filing cabinet imposes friction per file. A single statement over a client table returns every disclosure anyone ever made, in seconds, with nothing in the way, and the same notes concede that direct access of that kind sits outside what any application-layer audit log can see.
The cost of this does not land on whoever made the decision. The institution chose the tier; the people whose material is held under it were not asked and in most cases are not told. On a hosted tier a person who wants their data deleted asks the platform and the platform can enforce it, because the platform controls the database. On a sovereign tier that same person has to ask the institution directly, which is fine right up until the relationship is the thing they are trying to leave, and then their only remaining leverage is legal rather than technical. Sovereignty transfers a real power to the institution and transfers a real exposure to everyone downstream of it, and only one of those two parties was in the room.
None of that makes the sovereign choice wrong. It makes the sovereign claim narrower than it sounds, and our own conclusion is the narrow one: this option is not inherently more trustworthy, it is more controlled, and control is a good that some institutions genuinely need and some people genuinely want their practitioner to have. What the argument forbids is letting the word do work the architecture has not done. Say which tier holds someone’s material during onboarding rather than in the terms. Say which of their rights survive it and which now depend on a letter to a regulator. Sovereignty is worth having, and it becomes worth trusting the moment the people who did not choose it are handed the same map as the person who did.
Evidence and lineage
Research trail
Follow the sources, inspect how the claims are graded, or propose a correction at the exact record it concerns.
Sources 2
-
European Union (2018). General Data Protection Regulation, Articles 4(7), 17, and 24
The legal frame that makes the relocation legible. Article 4(7) fixes controllership on whoever determines purposes and means, Article 24 puts the demonstrable-compliance duty on that party, and Article 17 directs the erasure right at the controller. Together they explain why self-hosting changes the topology without changing who is accountable.
Comment on this source -
MNSTRY platform documentation (2026). Sovereign database architecture, unresolved design tensions
The internal source, and an unusual one. It is a section of our own architecture written to argue against the position we would be assumed to hold, conceding that the threat model has no adversary type for the data controller, that SQL removes the friction paper files impose, and that the sovereign tier is more controlled rather than more trustworthy.
Comment on this source
Claims and confidence 8
- verified
GDPR Article 4(7) defines the controller as the party that, alone or jointly, determines the purposes and means of processing personal data.
The regulation's own text, verified externally at authoring time.
Respond to this claim - verified
GDPR Article 24 requires the controller to implement appropriate technical and organisational measures and to be able to demonstrate that processing complies with the regulation.
The regulation's own text, verified externally at authoring time.
Respond to this claim - verified
A person exercises the Article 17 erasure right against the controller, so where the controller holds its own infrastructure, enforcement runs through that controller rather than through a platform.
The regulation's allocation of the duty, combined with the ordinary consequence that a party without access to the database cannot perform a deletion in it.
Respond to this claim - verified
The unresolved-tensions section of our sovereign database architecture states that its threat model treats the institution as the data controller, a trusted role, and has no adversary type for the data controller themselves.
The section's own opening claim, written as a self-criticism of the preceding architecture.
Respond to this claim - verified
The same section states that a single SQL statement returns every client's disclosures in seconds where paper files impose friction, and that direct database access sits outside what application-layer audit logs record.
The section's own text, including its rejection of the paper-file analogy as understating the risk.
Respond to this claim - verified
The same section states that on the sovereign tier a person wishing to leave must ask the institution directly, because the platform cannot enforce deletion on a database it does not control, and that the person did not choose the tier.
The section's client-exit and client-awareness subsections.
Respond to this claim - verified
The same section concludes that the sovereign option is not inherently more trustworthy but more controlled.
The section's own counter-narrative on tier positioning.
Respond to this claim - verified
Relocating a database under the controller's own administration converts the constraint on the party most able to read everything from a technical control into a legal obligation.
Follows from the controller definition plus the source's admission: on a hosted tier the institution's reading is bounded by a platform's access controls and audit surface, and on a sovereign tier those bounds are replaced by the institution's own legal duties. Not a claim that either arrangement is safer.
Respond to this claim
Read next
-
Privacy · read
Finish with the discipline all five rooms were arguments for, drawing the edge of your own claim before a reader has to go looking for it.
What your claim excludes
-
Endings · read
Or ask what control is worth to anybody who cannot exercise it, and find the test that separates an arrangement somebody has actually walked out of from one that has only ever described the door.
Exit rights