Written by a human

Is data security a board-level priority for Nordics firms?

Data sovereignty is no longer just an IT concern for Nordic firms, it's a board-level priority, as GDPR, DORA, and rising supply chain attacks expose the reality that data is only as secure as the weakest link in the chain.

4 mins read 10 August 2026

In brief:

  • Data sovereignty is now a board-level priority for Nordic firms, under GDPR and DORA, organizations must know exactly where their data resides and who can access it, especially as cloud storage complicates jurisdictional accountability
  • Third-party and supply chain risks are the weakest links, from misconfigured vendor databases to hyperscaler reliance, firms are increasingly vulnerable to breaches outside their direct control, while the Nordics face some of Europe’s highest rates of cyberattacks and data leaks
  • Vendors must demonstrate ownership, residency, and resilience, where the ideal platform offers sole infrastructure ownership, verifiable data residency, closed-loop AI processing, full deletion tracing, and EU-aligned certifications, not just feature sets

Data sovereignty is a growing concern

Financial entities and systems are interconnected globally, with data shared at huge volume across borders every day. However, where that data “lives” is a growing concern, as data residency and sovereignty considerations can mean data is subject to laws and regulations across jurisdictions.

Answering data residency questions can become even more complex when data is stored in “the cloud.” Firms in the Nordics are subject to stringent data protection legislation such as the General Data Protection Regulation (GDPR) and now the Digital Operational Resilience Act’s (DORA) requirements.

Understanding where data is stored and how it can be accessed, and what this may mean for regulatory and compliance concerns, is no longer solely an IT problem, but now sits firmly at board level.

Third-party risk

Third-party risk is increasingly coming under the regulatory spotlight, and for good reason. Research found that, in 2025, it was found that an unsecured database of firm information was sat open on a “misconfigured cluster” operated by a downstream client, rather than the firms itself. While the data had presumably been shared legitimately under commercial license, it had been left exposed once it had moved beyond the firm’s own environment.

Businesses must remember that data exists as part of a chain, and a chain is only ever as strong as its weakest link. When you forge new business relationships, you are responsible for ensuring that your partners are as resilient as you need them to be.

Not just national, but regional

Threat intelligence from 2025 puts Sweden as the most targeted Nordic country at roughly a third of recorded attacks, although Denmark at 23.5% and Norway at 22.6% are not far behind. Data or database leaks now account for close to 60% of all threat activity tracked across the region – and Nordic regulators have taken note. Norwegian banks are pushing for early adoption of the EU’s NIS2 directive to ensure better and stricter cybersecurity risk management and alignment with the European Economic Area. Danish and Swedish institutions are already pushing ahead on AI-specific risk assessments. The direction of travel is clear – more scrutiny on where data sits, who can access it, and how resilient the systems around it are.

The ideal vendor qualities

  • Sole infrastructure ownership where there is no subcontracted cloud layer or hyperscaler in the chain, and one party is accountable for your data, not three or four
  • Verifiable data residency, where the archive is stored in a data center the vendor owns and operates
  • Closed-loop AI processing means that any LLM used for risk analysis, processes data in memory and discards it after each request, with nothing retained or used for training without consent
  • Constant integrity checks and full deletion tracing allows due diligence teams to verify a record’s entire lifecycle rather than take a vendor’s word for it
  • Certifications that match Nordic/EU regulatory expectations including ISO 27001, SOC 2, and alignment with frameworks regulators are already pointing to (NIS2, DORA)
  • 24/7 monitoring with infrastructure built to withstand the kind of DDoS activity that’s already hit Nordic banks, not just encryption on paper

For Nordic compliance teams weighing up AI-enabled surveillance, the questions worth asking a vendor are not solely about features. They’re about ownership, so, who controls the infrastructure, who can access the data, and what happens to it once an AI model has touched it. At Global Relay, we build our own infrastructure, so the answers are always clear

4 mins read 10 August 2026