Where Your Data Live Is Only Half The Risk

Blog
Corporate Risk Leaders
Third-Party Risk Management
02 Oct, 2026

Geopolitical risk is increasingly becoming a third-party risk, and data sovereignty is emerging as a critical blind spot. The 2026 Verdantix global corporate survey found that 75% of risk executives consider the geopolitical environment the most or a very urgent internal challenge, up from 52% in 2025. At the same time, both geopolitical risk and data privacy are seen as highly significant external risks by 56% of decision-makers. As organizations become progressively more dependent on globally distributed cloud and SaaS providers, data control can no longer be assessed by location alone; jurisdictions, ownership structures, fourth parties and legal obligations are now major factors to consider.

Our recent analysis of China’s expanding compliance architecture highlighted how geopolitical developments can create third-party exposure in suppliers’ jurisdictions. These dependencies can extend beyond the immediate supplier relationship – especially when it comes to data.

International data management creates complex dependencies

Data residency tells an organization where its data are stored or processed. Data sovereignty goes further, considering which laws and jurisdictions can govern or provide access to the data. A provider can, for example, host data in the UK or EU while remaining exposed to another jurisdiction through its ownership, infrastructure or legal obligations. Guidance from the UK government and National Cyber Security Centre (NCSC) warns that international cloud and SaaS providers may be subject to home jurisdiction laws and that legal jurisdictions can be more complex than physical storage locations. For TPRM teams, this creates a visibility challenge, because knowing where a supplier hosts data does not necessarily reveal which jurisdictions, owners or fourth parties have an influence on access rights.

Cloud and SaaS systems rarely operate in isolation. A critical supplier may depend on cloud infrastructure, subprocessors or other fourth parties, each introducing additional jurisdictions, legal obligations and potential points of access. Approximately 75% of risk executives report that geopolitical unrest significantly impacts supplier risk, yet conventional assessments may not fully map these dependencies. TPRM teams must therefore understand who owns the provider, where data flow, which fourth parties process them and which jurisdictions could compel access.

Sovereignty risk is dynamic

Sanctions, trade restrictions, national security legislation, cross-border data transfer rules and diplomatic tensions alter the risk profile of a supplier without any change to its product or security controls. This unpredictability reflects the need for greater intelligence in risk management: 78% of risk executives say real-time data collection and reporting is a high or the highest priority. Yet, in our question on risk intelligence practices, 34% said they manually scrape public sources such as Google and X, while 15% reported using no risk intelligence. These findings highlight the gap between the need for timely risk intelligence and organizations’ ability to continuously monitor changing exposures. Static due diligence is now insufficient. A supplier’s jurisdictional risk possibly changes with legislation, ownership or geopolitical relations shift – leaving firms exposed if they don’t adapt.

Risk teams should treat data sovereignty as part of ongoing third-party monitoring rather than a one-off privacy assessment. This means maintaining visibility of critical data flows, supplier and fourth-party jurisdictions, ownership structures, and material changes to relevant laws and geopolitical relationships. The next generation of TPRM will need to connect supplier intelligence with jurisdictional, technological and geopolitical intelligence to ensure an organization can maintain appropriate levels of data control when the external environment changes.

To learn more about TPRM best practices, explore our third-party risk management module, and to find out about the technology that can help organizations bolster their TPRM programmes, watch out for the upcoming Green Quadrant on TPRM early next year.

Discover more Corporate Risk Leaders content
See More