The Off Switch in Another Country: Data Sovereignty
When the International Criminal Court's chief prosecutor lost access to his Microsoft email to a sanctions decision taken abroad, a quiet question turned urgent. How much of a Bangladeshi bank now runs on software that can be switched off from outside our borders, and why this can no longer be left to the IT department alone.
In the early months of 2025, Karim Khan, the chief prosecutor of the International Criminal Court, found that he could not open his own email. The cause had nothing to do with a technical fault. The United States had imposed sanctions on him, and his Microsoft account simply stopped working. An institution built to stand above the politics of any single nation discovered that one of its most basic tools answered to the law of another country. Within months the ICC was reported to be moving towards openDesk, a sovereign open-source suite assembled in Germany.
Most people read that story as a piece of international politics. I read it differently, because I have spent more than ten years building the very kind of systems that were switched off.
I have worked in human resources across Bangladesh and Australia, and I now sit inside private commercial banking in Dhaka, having earlier served at another bank in the same city. I have led the digital side of HR, integrating our HRIS, automating more than 12 core workflows and cutting manual processing time by roughly 65% while pushing data accuracy to 99.2%. I have built people-data dashboards in Power BI that leadership used to make decisions on turnover and workforce planning. I am also the custodian of some of the most sensitive records a bank holds, having handled more than 110 employee relations and disciplinary cases under Bangladesh Labour Law with a clean audit record. So when I watched the ICC lose its email, my first thought was not about The Hague. It was about how much of my own bank now sits on tools that a decision in another capital could quietly disable.
Why this matters now
Let me define the two ideas plainly, because they are often blurred. Data sovereignty is the principle that data is subject to the laws of the country in which it is collected and held. Software sovereignty is the related idea that an organisation should keep genuine control over the software it depends on, including the ability to run it, inspect it, adapt it and keep it operating regardless of any single supplier's decisions.
The trap most banks fall into is assuming that physical location settles the matter. It does not. The gap between where data physically sits and who holds legal jurisdiction over the vendor is the whole problem. Under the United States CLOUD Act of 2018, a company incorporated in the United States can be compelled to hand over or act on data regardless of where that data is hosted. A data centre in Singapore, or even one inside Bangladesh, does not remove the exposure if the company that owns the platform is American. The jurisdiction travels with the vendor, not with the server.
This is where my own work stops being abstract. Every workflow I automated and every dashboard I built made the institution more efficient, and at the same time more dependent on whoever owns the platform beneath it. Consider how much of a single working day at my bank already passes through one American company. Our email runs on Outlook and Exchange. Our meetings, our calls and the everyday conversations where work actually gets done sit inside Microsoft Teams, including the channels where decisions are taken and quietly recorded. Our documents are written in Word and Excel and stored in SharePoint and OneDrive. The leadership dashboards I built run on Power BI. And beneath all of it, the identities that decide who is even allowed to log in are managed by Microsoft's own directory service. If that single company were ever compelled to suspend our access, whether by a sanction, an export-control ruling or a policy decision taken far from Dhaka, the damage would not be one product going offline. Email would stop arriving. The Teams conversations and shared files that hold the institution's working memory would go dark in an instant. Staff might not be able to sign in to their own computers, because the key to the front door would be held abroad. This is not a claim that Microsoft is a hostile actor. It is the plain observation that the control sits outside our borders, and control is the only thing that matters at the moment a service is switched off. I also now understand its second meaning.
A frozen Tuesday at a Bangladeshi bank
Picture an ordinary Tuesday at a Bangladeshi bank where the foreign vendor relationship has gone wrong, whether through sanctions, a contractual dispute, an export-control decision or a policy change made far away. Payroll cannot run because the HR platform and its email are frozen. Productivity licences stop validating, so documents and spreadsheets across the bank turn read-only or refuse to open at all. Cloud-hosted services are suspended. Vendor support is withdrawn at exactly the moment it is needed most. And in my own corner of the bank, employee and disciplinary records sit stranded in the middle of live legal processes, including show-cause and inquiry matters that carry statutory deadlines under Bangladesh Labour Law.
Before 2025, a chief risk officer could dismiss all of this as paranoia. After the ICC, that is no longer honest. If it can happen to an international court, it can happen to a bank. The deeper danger is systemic. If most banks in the country depend on the same one or two vendors, a single decision taken offshore does not damage one institution, it stresses the financial system at the same moment. We have spent years worrying about cyber attackers breaking in. We have spent far less time worrying about a supplier we trust simply turning the service off.
Why banking carries a heavier duty than most
A clothing retailer that loses its email has a bad week. A bank that loses its core systems can trigger a loss of public confidence that no marketing budget repairs. Banks are different because they are custodians, not merely users. We hold citizens' financial and personal data, we keep the payment system moving, and we carry an explicit regulatory duty to do both without interruption.
The Bangladesh regulator has already seen this coming. The Bangladesh Bank Guidelines on Cloud Computing of 2023 lean clearly towards private cloud and local hosting for sensitive workloads. The ICT Security Guideline, now in version 4.0, sets expectations for control, resilience and data protection that a black-box foreign dependency makes hard to satisfy. And Section 12 of the Bank Companies Act 1991 restricts the movement of a bank's records outside Bangladesh without prior permission, which is precisely the kind of provision that a cross-border cloud arrangement can quietly breach.
I feel this acutely as a data custodian. The disciplinary files I manage contain allegations, medical references, financial details and the private circumstances of named employees. Across more than a hundred such cases I kept a clean audit record, and I did so partly by knowing exactly where that information lived and who could touch it. The moment I cannot answer that question with confidence, both my compliance and my duty of care weaken. An outage caused offshore is not only an IT incident. It is a legal exposure, a regulatory breach and a breach of trust with our own people, all at once.
The alternatives, assessed honestly
The encouraging news is that credible alternatives exist, and I want to describe them as a practitioner rather than as a believer. For office and productivity work there is LibreOffice on the desktop and Collabora Online for browser-based collaborative editing. For email and collaboration there is Thunderbird as a mail client, along with Open-Xchange and Nextcloud for shared mail, calendars, files and groupware, and Proton where encrypted communication matters most. For an organisation that wants a single integrated and sovereign suite rather than a set of assembled parts, there is openDesk, built by Germany's Centre for Digital Sovereignty, ZenDiS, which is the very direction the ICC has taken. At the operating-system and directory layer there is the Linux desktop and Univention Corporate Server as an alternative to Active Directory. And for hosting, the answer is local and private cloud, including the government data centre at Kaliakoir.
I will not pretend the switch is painless, because I have led migrations and I know where they hurt. Interoperability with legacy specialist banking applications is the hardest constraint, since core banking and many regulatory tools were written with foreign productivity software in mind. File-format and macro friction is real, and a finance team that has built years of work into complex spreadsheets will feel it first. Migration takes genuine effort and disciplined sequencing. And the support model changes from a single global vendor to a blend of community, local integrators and in-house capability. None of these is a reason not to act. Each is a reason to plan properly.
The number that should reach the board
The economics are not a side argument, they are central. The German state of Schleswig-Holstein, with around 30,000 staff, has been migrating more than 40,000 accounts and over 100 million emails and calendar entries off Microsoft Exchange and Outlook. It projects savings of more than EUR 1,50,00,000 a year in licence costs against a one-time investment of around EUR 90,00,000. In other words, the recurring annual licence bill was larger than the entire cost of moving away from it.
Translate that into terms a Bangladeshi bank board will recognise at once. Foreign software licences are a recurring outflow paid in hard currency, year after year, with no end date. A migration to sovereign tooling is largely a one-time spend, much of it paid locally in taka for migration, integration and training, with the recurring cost falling sharply thereafter. In a country under real pressure on its foreign-exchange reserves, every renewal cycle quietly exports scarce dollars for software we could increasingly run ourselves. That is not only a resilience question. It is a balance-of-payments question, and our boards are paid to notice both.
This is already happening elsewhere
This is not theory, and Bangladesh would not be a pioneer taking a wild bet. The ICC's move towards openDesk after the email episode is the clearest signal yet that even the most internationally exposed institutions are reconsidering. Schleswig-Holstein is replacing Microsoft with LibreOffice, Thunderbird, Open-Xchange and Nextcloud, and is piloting Linux on the desktop. Denmark's Ministry of Digital Affairs has begun moving its own staff to LibreOffice. Across the European Union, digital sovereignty has shifted from a slogan into a procurement principle and a political priority. The pattern is consistent. Governments and serious institutions are deciding that control matters as much as convenience.
The hardest part was never the technology
Here I want to speak plainly as the HR practitioner I am, because this is where most sovereignty conversations go quiet and where they ought to grow louder. Every migration I have run taught me the same lesson. The technology is the manageable part. The people are the hard part.
Adoption resistance is real, and it is rational, because staff who have used the same productivity tools for their entire careers will not embrace change merely because a memo told them to. It is overcome with a structured training and reskilling plan, with patient internal communication that explains the why and not only the what, and with visible support from leadership rather than instruction from a distance. There is also a workforce-building dimension we tend to ignore. Moving to open-source tooling means deliberately growing local IT and open-source talent, both inside the bank and in the wider market, so that we do not simply trade dependence on a foreign vendor for dependence on a handful of irreplaceable individuals. That is the succession and key-person risk every HR head should already be tracking.
Employee data privacy sits at the centre of all of this, and it is the thread that ties the HR lens and the IT lens together. The records I protect are only as sovereign as the platform they live on. If that platform answers to a foreign legal order, the assurances I give our employees are conditional in a way I never agreed to.
Which brings me to the governance question that matters most. Who owns sovereignty risk? Today, by default, it is filed under IT. That is a mistake. Sovereignty is not a technical specification, it is a question of who controls the institution's ability to function, to pay its people, to keep its promises and to obey its own regulator. It cannot sit with IT alone. It must be a shared mandate across HR, IT, Risk and Compliance, owned at board level and reviewed like any other principal risk.
So my call to action is measured, not alarmist. I am not asking any Bangladeshi bank to tear out its systems tomorrow, and I am certainly not arguing against any single country or supplier. I am asking boards to name an owner for sovereignty risk, to map honestly how much of the institution would stop if a foreign decision went the wrong way, and to begin a sober pilot of sovereign alternatives where the risk is highest. I am asking Bangladesh Bank to keep moving the sector in the direction its own guidelines already point. And I am asking my fellow HR leaders to stop treating this as somebody else's problem.
I helped build the dependence. I know exactly where the data sits and what it runs on. That is precisely why I believe we still have time to take the off switch out of someone else's hand and put it back in our own.
