Ian Finn Ian Finn

Data Sovereignty, Resilience, and a Danish Pastry: Reflections from a Morning at the Embassy

Earlier this week I had the privilege of joining a Technology Leaders Breakfast at the Danish Embassy in London, hosted by Ambassador Kristina Miskowiak Beckvard and the team at Denmark in the UK, on data sovereignty in a cloud and AI-first age.

The room was genuinely exceptional: CIOs, CISOs, and senior technology leaders from across sectors and government, all wrestling with the same tension I see daily in identity and platform work. How do you build systems resilient enough to withstand real disruption, whilst keeping trust and sovereignty intact for the people who depend on them?

It's a tension that doesn't resolve itself with a single framework or a single vendor. Data sovereignty sits at the intersection of technical architecture, national policy, and commercial pragmatism, and the organisations that navigate it well tend to be the ones who treat all three as inseparable, rather than solving the technical problem in isolation and hoping policy and commercial reality catch up later. That's true whether you're a retailer managing customer identity across markets, or a government department managing citizen data across borders, the underlying discipline is the same: resilience isn't a feature you bolt on, it's a property of how the whole system, technical and institutional, is designed from the outset.

The event also brought back fond memories for me of my time building out globalised technology solutions, across 110 countries, to support international trade for the UK government a few years ago, in the post-Brexit phase. That work taught me a version of the same lesson from a very different vantage point: platforms that need to serve multiple sovereign jurisdictions at once can't treat "compliance" as a downstream concern. It has to be architected in from day one, or it becomes the thing that quietly breaks under real-world pressure, exactly when you can least afford it to.

It was genuinely great to see states and business converging so seamlessly to discuss pivotal shared concerns like this one. Too often these conversations happen in separate rooms, technologists talking to technologists, policymakers talking to policymakers, when the actual problem sits squarely in the overlap between them.

And yes, discussions were well-fuelled by the obligatory and freshly-baked Danish pastries, which were, without question, the best I've ever tasted.

Grateful for the invitation, the warm hospitality, and the calibre of thinking in that room. Conversations like these are exactly why I believe identity, trust, and resilience belong at the same table as commercial strategy, not somewhere further down the agenda, or in a different room entirely.

Read More