Ask a stakeholder engagement vendor where your data sits and you'll usually get an answer about servers: which country, which data centre, sometimes a full page of specifications. That's not actually the question that matters. The question that matters is who can be compelled to hand the data over, and under which country's law, and that's a different thing entirely.
'UK data residency' and 'UK data sovereignty' get used almost interchangeably in vendor copy, and they're not the same claim. If you're choosing or reviewing a stakeholder relationship management (SRM) system for local government, the NHS, energy, water or transport work, knowing the difference changes what you should actually be asking.
What does data sovereignty mean
Data sovereignty is about jurisdiction, not geography: it's the question of which country's laws, courts and disclosure powers can reach your data, wherever it physically sits. A system can store data in the UK and still be reachable by a foreign law, if the company running it is incorporated somewhere else and subject to that country's own disclosure rules.
Data residency and data sovereignty aren't the same thing
Data residency tells you where the servers physically are. Data sovereignty tells you whose laws govern what happens to the data on them. A vendor can truthfully say 'your data is hosted in the UK' while the entity that operates the platform, and therefore the legal reach over that data, sits somewhere else entirely.
For most software, that distinction is academic. For stakeholder engagement records, it usually isn't, because of what those records actually contain.
Why this matters more for stakeholder data than for typical business data
Stakeholder records aren't a customer list. They routinely include personal data: names, addresses and contact details, stated positions on a scheme, sometimes political affiliations or formal objections to a development. On infrastructure and energy projects, the record extends to landowners affected by compulsory purchase, elected representatives, and community groups organising against a proposal.
That's a different risk profile to a typical CRM export. A council, NHS trust or energy company handling this kind of data usually has statutory duties attached to it, under UK GDPR, the Planning Act 2008 development consent regime, section 172 of the Companies Act 2006, or the Gunning Principles that govern how public consultations have to be run. Regulators including Ofgem, Ofwat and the Planning Inspectorate can ask an organisation to produce the record and explain how it's protected. 'It's stored securely somewhere' isn't an answer that survives that conversation. 'It's stored in the UK, by a UK-regulated provider, and here's the audit trail' is.
This is also where residency and sovereignty stop being an IT question and become a procurement one. The ICO's guidance on international transfers under UK GDPR sets out when moving personal data outside the UK requires extra safeguards, and it's worth reading before you take a vendor's hosting claim at face value.
What to ask a vendor about data sovereignty, not just residency
A location on a datasheet doesn't answer the sovereignty question on its own. Five questions get you closer to a real answer:
-
Where is the data physically stored, and is that the default or an opt-in? Some vendors default to a US or EU region and offer UK hosting as an add-on.
-
Where is the company that operates the platform incorporated, and where is its parent company, if it has one? This is what actually determines which country's laws can compel disclosure.
-
Who can access the data for support or maintenance, and from where? A UK-hosted database supported by an overseas team can still create a sovereignty gap.
-
What happens to the data if the contract ends? Export format, retention period, and deletion confirmation should all be specified, not implied.
-
What accreditations back the hosting claim up? ISO 27001:2022, Cyber Essentials Plus and, for NHS work, the Data Security and Protection Toolkit are the ones a UK public sector security review will actually check for.
The NCSC's Cloud Security Principles are the standard framework UK public sector buyers use to run this assessment, and they cover more than physical location: separation between customers, supply chain security and personnel security all sit alongside where the servers are.
How Tractivity approaches this
Tractivity, the UK stakeholder relationship management platform, defaults to Microsoft Azure hosting in the UK region, with full UK data residency and no configuration needed to get it. Alternative regions, including the EEA and the United States, are available for organisations with their own jurisdictional requirements, with identical security controls wherever the data sits. The platform holds ISO 27001:2022, Cyber Essentials Plus and NHS DSPT (audited annually), and is listed on G-Cloud 14 through the Crown Commercial Service, which UK public sector buyers can use to shortcut a separate tender.
EDF Energy relies on this for the Hinkley Point C and Sizewell C consultation programmes, evidencing a100% response rate across roughly 30,000 logged stakeholder issues. Anglian Water uses the same audit trail to produce engagement evidence for its regulator. Both are the kind of organisation that asks the sovereignty question before signing anything, and both had to be satisfied with the answer.
For the full breakdown of Tractivity's hosting regions, accreditations and what 'SRM' means when a security review asks about it, see the security and compliance page. For the wider set of requirements a government contract typically brings, what secure databases for government contractors actually require covers Cyber Essentials, OFFICIAL classification and the incoming Cyber Security and Resilience Bill in more depth. For how UK vendors compare on GDPR readiness specifically, see GDPR-ready stakeholder databases.
If you'd like to see how Tractivity handles UK data residency and sovereignty for your sector, book a demo or get in touch.
Frequently asked questions
