Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Technology · 2 min read · Updated 16 August 2026

Data trustee

In shortA trustee only holds up if it is economically and legally independent of the provider.

At a glance

Basic idea
Separating operations from access control: whoever runs the technology does not hold the keys
Typical arrangement
Key custody, approval workflow for administrative access, logging by the third party
Decisive condition
Economic and legal independence of the trustee from the provider
Common weakness
A trustee that is a group subsidiary, a sales partner, or economically dependent
Effective against
Administrative access by the operator, disclosure orders served on the operator
Ineffective against
Failure of the trustee itself — an emergency procedure is mandatory

A data trustee is an independent third party standing between customer and operator. It holds keys, approves administrative access or logs it — so that the operator cannot make the data readable on its own.

The model is the technical and organisational answer to a legal problem: the US CLOUD Act attaches to possession, custody and control. Giving up control over readability changes the starting position.

Role 1 Customer decides who gets access and retains the authority to decide Role 2 Trustee holds keys or controls access, independently of the provider Role 3 Provider operates the technology but cannot make the data readable alone
The model only holds where the trustee is economically and legally independent of the provider.

How it is arranged

Most often as key custody: the trustee runs key management and the provider receives at most short-lived authorisations. There are also models in which the trustee approves and logs administrative access by operator staff.

In practice the two are combined, because administrative access to a running system reveals a great deal even without keys.

The condition everything hangs on

Independence. A trustee that is a subsidiary of the provider, is paid mainly by it, or answers to the same legal order, changes nothing — it merely adds a station to the route.

Three questions settle it: what is the trustee in company-law terms, how is it paid, and which law does it answer to? Anyone with those three answers can assess the model; anyone who cannot obtain them has an answer too.

The emergency procedure

The most common failure in these arrangements is not lack of independence but the missing rule for trustee failure.

What happens if it is unreachable, insolvent or overloaded? Without a documented procedure, a deputy arrangement and deadlines, you have traded an access risk for an availability risk — and the second is far more likely to occur.

When the effort is justified

Not across the board. Classification is the sensible route: the highest tier for categories where a single access would cause serious harm. For everything else the tiers described under Key control suffice — and in many cases simply choosing a provider where the question does not arise.

Common questions

Is a trustee model the same as key control?
It is one form of it. Key control means the provider cannot make the data readable alone. You achieve that either in-house or through an independent third party — the latter when you do not want to run key management yourself.
How do I recognise a workable model?
By three points: what is the trustee in company-law terms, how is it paid, and which law does it answer to? If the trustee belongs to the same group or lives mainly off the provider, independence is formal rather than economic.
What happens in an emergency?
Exactly that must be settled in advance: a procedure for trustee failure, a deputy arrangement, deadlines, and a documented route by which you can reach the keys yourself. Without it you have traded an access risk for an availability risk.
Who is this worth it for?
For processing where a single unauthorised access would cause serious harm — health data, client files, design data. For the rest the effort is usually disproportionate.

Sources

See also

Related terms