Data embassy

Last updated

A data embassy is a solution traditionally implemented by nation states to ensure a country's digital continuity with particular respect to critical databases. It consists of a set of servers that store one country's data and are under that country's jurisdiction while being located in another country.

Contents

Purpose

Data embassies are regarded as a tool to ensure a government's digital continuity, meaning the survival of critical databases to allow the continuation of government even in a situation where governing from within the country's borders is no longer an option. Among threats that might lead to such situation are natural disasters, large-scale cyberattacks, and military invasion. In the worst-case scenario, a data embassy could enable government to provide its digital services without the national territory under its control. [1] This makes data embassies particularly attractive to countries that have already digitalized their most crucial databases and are situated in the vicinity of the aforementioned threat vectors. Additionally, data embassies can offer additional computing power for heightened server traffic, for example during election season or the period of electronic tax return filing. [2]

History

The 2007 cyberattacks on Estonia disrupted websites of Estonian organizations including the Estonian parliament as well as newspapers and banks. Furthermore, Estonia has implemented a stringent paperless policy, meaning that many crucial databases only exist in a digital format. Tasked with ensuring the security and immutability of these databases, the ministries looked towards data embassies as a possible solution for digital continuity. This was crucial not just for Estonia's own citizens but also for e-Residents who rely on these services around the world. These efforts were also written down in the Estonian Cyber Security Strategy 2014-2017 which created an outline for ensuring the digital continuity of the state. [3]

In 2013, then-CIO of the Estonian government Taavi Kotka made active efforts to determine, in which constellation a data embassy would be the most useful and effective. The Estonian government also collaborated with Microsoft on two studies to determine the feasibility of virtual data embassies. [4] [5] The government decided against the option of converting selected Estonian embassies into data embassies because embassies did not possess the necessary technical and crisis response competence, were reliant on whatever telecommunications services they would be offered by virtue of their environment, and were not physically constructed according to safety criteria that datacenters could fulfil.

On 14 November 2016, the Estonian Ministry of Economic Affairs and Communications and Luxembourgish Ministry of Media and Communications signed a Memorandum of Understanding about the hosting of data and information systems. On 20 June 2017, Prime Minister of Estonia Jüri Ratas and Prime Minister of Luxembourg Xavier Bettel signed the agreement to establish an Estonian data embassy in Luxembourg. [6] [7] This agreement was ratified by the parliaments of Luxembourg and Estonia in 2018. In its first iteration, the Estonian data embassy in Luxembourg currently acts as a backup and source of additional computing power for the following datasets that are considered critical for the functioning of the state: e-file court system, treasury information system, e-land register, taxable persons’ register, business register, population register, state gazette, identity documents register, land cadastral register, and national pension insurance register. [8]

In 2018, Bahrain implemented the so-called Cloud Law which allows data stored in Bahraini datacenters to be subject to the domestic law in a third country. [9]

Initially, academic research also considered the application of the 1963 Vienna Convention on Consular Relations or the 1961 Vienna Convention on Diplomatic Relations to ensure the protection and inviolability of data but found that these conventions would require significant changes. [1] As a result of the lack of international legal precedent, data embassies have thus far only been created on the basis of bilateral agreements that are inspired by the wording used in the Vienna Conventions. These bilateral agreements also usually require ratification from the parliaments of the partnering countries.

Sources

  1. 1 2 Kask, Laura; Robinson, Nick (January 2018). "The Estonian Data Embassy and the Applicability of the Vienna Convention: An Exploratory Analysis". Icegov'19 via www.academia.edu.
  2. Kotka, Taavi; Liiv, Innar (September 15, 2015). "Concept of Estonian Government Cloud and Data Embassies". In Kő, Andrea; Francesconi, Enrico (eds.). Electronic Government and the Information Systems Perspective. Lecture Notes in Computer Science. Vol. 9265. Springer International Publishing. pp. 149–162. doi:10.1007/978-3-319-22389-6_11. ISBN   978-3-319-22388-9.
  3. https://www.mkm.ee/sites/default/files/cyber_security_strategy_2014-2017_public_version.pdf Archived 2021-02-12 at the Wayback Machine [ bare URL PDF ]
  4. https://www.mkm.ee/sites/default/files/implementation_of_the_virtual_data_embassy_solution_summary_report.pdf Archived 2021-03-08 at the Wayback Machine [ bare URL PDF ]
  5. https://www.mkm.ee/sites/default/files/transforming_digital_continuity_-_joint_research_report_finaly_may_20.pdf Archived 2021-03-08 at the Wayback Machine [ bare URL PDF ]
  6. https://www.riigiteataja.ee/aktilisa/2280/3201/8002/Lux_Info_Agreement.pdf [ bare URL PDF ]
  7. "Loi du 1er décembre 2017 portant approbation du " Agreement between the Grand Duchy of Luxembourg and the Republic of Estonia on the hosting of data and information systems ", signé à Luxembourg, le 20 juin 2017. - Legilux". legilux.public.lu.
  8. "Data Embassy – the digital continuity of a state". e-Estonia. December 9, 2019.
  9. "Diplomatic immunity for data: Bahrain's Data Embassy Law | Lexology". www.lexology.com. March 2020.

Related Research Articles

The Republic of Estonia gained its independence from the Russian Empire on 24 February 1918 and established diplomatic relations with many countries via membership of the League of Nations. The forcible incorporation of Estonia into the Soviet Union in 1940 was not generally recognised by the international community and the Estonian diplomatic service continued to operate in some countries. Following the restoration of independence from the Soviet Union, Russia was one of the first nations to re-recognize Estonia's independence. Estonia's immediate priority after regaining its independence was the withdrawal of Russian forces from Estonian territory. In August 1994, this was completed. However, relations with Moscow have remained strained primarily because Russia decided not to ratify the border treaty it had signed with Estonia in 1999.

<span class="mw-page-title-main">Schengen Information System</span> EEA database to support law enforcement

The Schengen Information System (SIS) is a governmental database maintained by the European Commission. The SIS is used by 31 European countries to find information about individuals and entities for the purposes of national security, border control and law enforcement since 2001. A second technical version of this system, SIS II, went live on 9 April 2013. An upgraded Schengen Information System entered into operation on 7 March 2023.

<span class="mw-page-title-main">International vehicle registration code</span> Codes used to identify where a vehicle is registered

The country in which a motor vehicle's vehicle registration plate was issued may be indicated by an international licence plate country code, formerly known as an International Registration Letter or International Circulation Mark. It is referred to as the Distinguishing sign of the State of registration in the Geneva Convention on Road Traffic of 1949 and the Vienna Convention on Road Traffic of 1968.

Elections in Luxembourg are held to determine the political composition of the representative institutions of the Grand Duchy of Luxembourg. Luxembourg is a liberal representative democracy, with universal suffrage guaranteed under its constitution. Elections are held regularly, and are considered to be fair and free.

Traffic codes are laws that generally include provisions relating to the establishment of authority and enforcement procedures, statement of the rules of the road, and other safety provisions. Administrative regulations for driver licensing, vehicle ownership and registration, insurance, vehicle safety inspections and parking violations may also be included, though not always directly related to driving safety. Violations of traffic code are often dealt with by forfeiting a fine in response to receiving a valid citation. Other violations, such as drunk driving or vehicular homicide are handled through the criminal courts, although there may also be civil and administrative cases that arise from the same violation. In some jurisdictions, there is a separate code-enforcement branch of government that handles illegal parking and other non-moving violations. Elsewhere, there may be multiple overlapping police agencies patrolling for violations of state or federal driving regulations.

<span class="mw-page-title-main">Estonian identity card</span> National identity card of Estonia

The Estonian identity card is a mandatory identity document for citizens of Estonia. In addition to regular identification of a person, an ID-card can also be used for establishing one's identity in electronic environment and for giving one's digital signature. Within Europe as well as French overseas territories, Georgia and Tunisia the Estonian ID Card can be used by the citizens of Estonia as a travel document.

<span class="mw-page-title-main">Estonia–Finland relations</span> Bilateral relations of Estonia and Finland

Estonia–Finland relations are foreign relations between Finland and Estonia. The independent Republic of Finland, established in 1917, and the independent Republic of Estonia, established in 1918, established diplomatic relations and formally recognised each other in 1920. Diplomatic relations between the two countries were interrupted during World War II and officially restored on 29 August 1991. Finland has an embassy in Tallinn and an honorary consulate in Tartu. Estonia has an embassy in Helsinki and five honorary consulates, located in Oulu, Turku, Ekenäs, Tampere and Kotka. Both countries are full members of the Council of the Baltic Sea States, Council of Europe, European Union, NATO and the Eurozone. Finland has given full support to Estonia's membership of the European Union. Estonia also has strongly supported Finland's NATO membership. The majority languages in both countries are Finnic languages, as Finland's main language, Finnish, is related to Estonian, and there is and has been a certain feeling of kinship. 76% of Finns have visited Estonia, and in 2004, 1.8 million Finns reported visiting Estonia. The excise tax on alcohol is lower in Estonia than in Finland, thus it is common to buy large volumes of alcohol when returning from Estonia: a study in 2014 indicated that 34% of alcohol sold in Estonia is bought by Finns. Finnish and Swedish investors are the largest foreign investors in Estonia. Both Finland and Estonia are members of the European Union, Schengen agreement and the Eurozone, freeing international travel and trade between the countries. Finland is Estonia's top import partner, accounting for over 15% total import value in 2012, as well as the second-greatest market for Estonia's exports after Sweden. Finland's government recognised Estonia's independence in 1920. In response to the Soviet invasion, diplomatic missions were de facto removed. However, when Estonia restored its independence, this "temporary obstruction" was resolved. During the restoration of Estonia's independence, Finland secretly contributed with significant economic aid and know-how under the cover of "cultural co-operation" in order to not upset the Soviet Union. Finland continues to contribute militarily, such as officers' training, and the provision of equipment.

<span class="mw-page-title-main">Visa requirements for Pakistani citizens</span> Entry restrictions by the authorities of other states placed on citizens of Pakistan

Visa requirements for Pakistani citizens are administrative entry restrictions imposed on citizens of Pakistan by the authorities of other states. As of December 2023, Pakistani citizens had Visa free, visa-on-arrival and eVisa access to 77 countries and territories. All of the updated links and visa-related requirements can be found listed in the chart below. Pakistani passport holders that hold multi-entry visas or permanent residency permits in certain European countries, Canada, USA, GCC states or Australia may grant the ability to apply for eVisas to certain nations, as well as Visa on Arrival access that they would not have without visas to these nations. The Pakistani passport is currently ranked 102nd in terms of travel freedom according to the Henley Passport Index in the third Quarter of 2023.

Administration system for the state information system (RIHA) of Estonia is the Estonian catalogue of public sector information systems. It serves as the national registry of systems, components, services, data models, semantic assets.

e-Residency of Estonia Estonian virtual residency program

e-Residency of Estonia is a program launched by Estonia on 1 December 2014. The program allows non-Estonians access to Estonian services such as company formation, banking, payment processing, and taxation. The program gives the e-resident a smart card which they can use to sign documents. The program is aimed towards location-independent entrepreneurs such as software developers and writers. The first e-resident of Estonia was British journalist Edward Lucas; the first person to apply for and be granted e-residency through the standard process was Hamid Tahsildoost from the United States.

The Estonian Foreign Intelligence Service is the foreign intelligence service of the Republic of Estonia. The Foreign Intelligence Service coordinates with all Estonian intelligence functions, collects intelligence concerning foreign interests and activities, and transmits information to the President, Prime Minister, the General Staff of the Estonian Defence Forces, the Interior Minister, the Foreign Minister, and the Minister of Defence.

<span class="mw-page-title-main">Taavi Kotka</span> Estonian businessman

Taavi Kotka is an IT visionary and previously the chief information officer of the Estonian Government known for leading e-residency program. Between years 2005-2012, Kotka was the CEO of Nortal, one of the largest software development companies in the Baltic states. Taavi Kotka proposed "10 million e-residents by 2025" on idea contest by Estonian Development Fund in 2014.

<span class="mw-page-title-main">Luxembourg School of Business</span> Graduate business school

The Luxembourg School of Business (LSB) is the only accredited graduate business school in Luxembourg. LSB offers a part-time Master in Business Administration, a full-time Master in Management, as well as specialized programs for individuals companies.

The once-only principle is an e-government concept that aims to ensure that citizens, institutions, and companies only have to provide certain standard information to the authorities and administrations once. By incorporating data protection regulations and the explicit consent of the users, the public administration is allowed to re-use and exchange the data with each other. The once-only principle is part of the European Union's (EU) plans to further develop the Digital Single Market by reducing the administrative burden on citizens and businesses.

Veriff is a global identity verification service company founded and headquartered in Tallinn, Estonia. The company offers services for online businesses to mitigate fraud attempts and assisting regulatory compliance. Offering protection from identity fraud and identity theft, Veriff verifies a customer's identity automatically, using an AI that analyzes a multitude of technological and behavioural indicators, including facial recognition. The service is provided to companies as an API, which has been compared to Stripe.