Perspective
Control over data drains away one procurement at a time.
Few organisations decide to give up control. It disappears in small instalments, as every service and licence is chosen separately. It is usually noticed only when the price rises, the regulation changes or the supplier discontinues the service.
What this is about
Digital sovereignty is the ability to decide on your own data and architecture also when the circumstances change. In practice you know three things: what you depend on, what the dependency costs and how to get out of it if you have to.
Cloud services do not have to be given up. The public cloud is often the right answer: the data production of Western Uusimaa Wellbeing Services County runs on Azure and Databricks. We do not start from the assumption that everything is moved into your own environment. What matters is that you can move in a controlled way in the direction you choose yourselves, and that an exit plan exists.
What goes wrong
- The platform has been chosen on the basis of one use case, and everything else has been built on top of it.
- Raw data moves into environments whose legal position has not been assessed.
- Costs grow with use, and there is no realistic alternative left.
- Procurements are made with product names, when they should describe what the system has to be able to do.
The cloud decision is five questions
Which workloads, on which terms, into which cloud, when and with which exit plan. Once these have been answered one workload at a time, the question "cloud or not" has already been settled.
How we think
The architecture is chosen according to the purpose of use
The choice is decided by the purpose of use, the risk and continuity. Personal data, critical dependencies and jurisdiction weigh differently in different workloads.
Alternatives are kept open where losing them costs the most
Standards, open components and portable data keep the alternatives open even when the platform is one supplier's product. The most important points are the location of the data, the integrations and identity and access management.
Data protection is built into the structure
A platform can be built so that raw data stays in an environment the organisation controls and only pseudonymised data moves into the public cloud. Pseudonymised data is still personal data for whoever holds the key, so the structure alone does not settle data protection. It makes the data protection work verifiable.
We say what we mean by sovereignty
The word can mean freedom to choose the architecture, the location of the data or a European governance model. We always say which of them we are talking about. "Full sovereignty" on its own says nothing.
What we do
| Service | What it means here |
|---|---|
| Definition | Assessment of dependencies, architecture policies and the requirements for procurement |
| Data platform | The platform can be designed for the public cloud, for your own environment or for both. The part in your own environment can be isolated from the network if needed. |
| Data as Software | Version-controlled and tested data production that is not tied to one platform |
Who this is for
For wellbeing services counties, hospitals and national health and social care bodies whose health data requires controlled processing (GDPR, the Finnish Act on the Secondary Use of Health and Social Data, EHDS). We apply the same principles in the security and defence sector, where control over data is part of security of supply. They also suit critical industry.
Expert: Antti Brunni, Chief Executive Officer
In 30 minutes we go through what your architecture depends on and which of the dependencies are deliberate choices.