Data trustee
In shortA trustee only holds up if it is economically and legally independent of the provider.
At a glance
- Basic idea
- Separating operations from access control: whoever runs the technology does not hold the keys
- Typical arrangement
- Key custody, approval workflow for administrative access, logging by the third party
- Decisive condition
- Economic and legal independence of the trustee from the provider
- Common weakness
- A trustee that is a group subsidiary, a sales partner, or economically dependent
- Effective against
- Administrative access by the operator, disclosure orders served on the operator
- Ineffective against
- Failure of the trustee itself — an emergency procedure is mandatory
A data trustee is an independent third party standing between customer and operator. It holds keys, approves administrative access or logs it — so that the operator cannot make the data readable on its own.
The model is the technical and organisational answer to a legal problem: the US CLOUD Act attaches to possession, custody and control. Giving up control over readability changes the starting position.
How it is arranged
Most often as key custody: the trustee runs key management and the provider receives at most short-lived authorisations. There are also models in which the trustee approves and logs administrative access by operator staff.
In practice the two are combined, because administrative access to a running system reveals a great deal even without keys.
The condition everything hangs on
Independence. A trustee that is a subsidiary of the provider, is paid mainly by it, or answers to the same legal order, changes nothing — it merely adds a station to the route.
Three questions settle it: what is the trustee in company-law terms, how is it paid, and which law does it answer to? Anyone with those three answers can assess the model; anyone who cannot obtain them has an answer too.
The emergency procedure
The most common failure in these arrangements is not lack of independence but the missing rule for trustee failure.
What happens if it is unreachable, insolvent or overloaded? Without a documented procedure, a deputy arrangement and deadlines, you have traded an access risk for an availability risk — and the second is far more likely to occur.
When the effort is justified
Not across the board. Classification is the sensible route: the highest tier for categories where a single access would cause serious harm. For everything else the tiers described under Key control suffice — and in many cases simply choosing a provider where the question does not arise.
Common questions
- Is a trustee model the same as key control?
- It is one form of it. Key control means the provider cannot make the data readable alone. You achieve that either in-house or through an independent third party — the latter when you do not want to run key management yourself.
- How do I recognise a workable model?
- By three points: what is the trustee in company-law terms, how is it paid, and which law does it answer to? If the trustee belongs to the same group or lives mainly off the provider, independence is formal rather than economic.
- What happens in an emergency?
- Exactly that must be settled in advance: a procedure for trustee failure, a deputy arrangement, deadlines, and a documented route by which you can reach the keys yourself. Without it you have traded an access risk for an availability risk.
- Who is this worth it for?
- For processing where a single unauthorised access would cause serious harm — health data, client files, design data. For the rest the effort is usually disproportionate.