Whose Treasure Is Your Data?
You assume the data is yours. The contract may even say so. But ownership is one thing and access is another. IBM’s report recommends treating datasets as high-value assets on par with financial records. And the defining feature of an asset is this: its owner can pick it up and leave whenever they choose.
Data failing that test is not yours in practice, however the contract reads. This piece separates the two. Four questions measure your ownership and show where you actually stand.
Why Is the Question Being Asked Now?
BU BÖLÜMÜN ÖZETİ
- Every tool now takes a piece
- Scattered data costs more
- Switching tools got more frequent
- Customers are asking too
Four developments sharpened the question.
Every tool now takes a piece
Data used to sit in a handful of systems. Today each new tool collects a share. AI tools joined that list and became the fastest collectors; every query leaves a record. As the spread grows, ownership blurs and nobody knows where all of it sits. When a new tool arrives, nobody updates the old list either.
Scattered data costs more
The report’s finding is clear: data spread across several environments carries a higher breach cost than data in one place. The reason is detection time. Where nobody knows what sits where, establishing scope drags on, and the delay lands on the bill. In a small business that means months of uncertainty — nobody even knows what to tell which customer.
Switching tools got more frequent
New tools appear quickly, old ones get expensive or shut down. A system used to stay in place for a decade. Now the switching decision comes up every few years, and a business that cannot move its data gets stranded. Putting up with poor terms starts looking easier than migrating, so the dependency deepens each year.
Customers are asking too
Corporate buyers have expanded the data questions in supplier audits. Where does our data sit? Who is it shared with? How long is it kept? Suppliers who cannot answer get eliminated. So data order has become a sales matter; a supplier who answers cleanly beats a technically equal rival.
What Is Wrong?
BU BÖLÜMÜN ÖZETİ
- “The contract says it’s ours, so we’re fine”
- “We have a backup”
- “It’s in the cloud, so it’s safe”
- “We’re small, nobody wants our data”
Four assumptions misdescribe ownership.
“The contract says it’s ours, so we’re fine”
An ownership statement is a starting point, not a guarantee. The same contract can grant the provider broad processing rights. The data may be yours. But if somebody else can process it, the ownership stays on paper.
“We have a backup”
A backup protects against loss. Not against dependency. A backup that only opens in the same system does not give you the freedom to leave the tool. The real question is whether that backup opens in another programme. If the answer is no, what you hold is a copy, not a backup. The two are very different things.
“It’s in the cloud, so it’s safe”
The cloud is a location, not a guarantee. Who can reach it, how long it is kept and how it comes out are separate questions. And in a business using several cloud services, the data sits more scattered than anyone assumes; each tool holds its own piece. Customer details in one place, correspondence in another, invoices in a third.
“We’re small, nobody wants our data”
The issue is not whether your data is wanted but how it gets used. Data you enter into a tool gets processed under that tool’s terms. Supply-chain attacks are also among the most common routes, and a small business usually sits as the weak link in that chain — capable of harming others through its own data.
The Real Mechanism
Ownership gets measured with four questions.
Who Is Affected, and How?
BU BÖLÜMÜN ÖZETİ
- The service business
- The e-commerce business
- The manufacturer
- Anyone using AI tools
Four profiles.
The service business
The most valuable data lives in the customer relationship. Correspondence, quote history, project notes. These usually accumulate in one tool and are the hardest to move. An annual export habit secures that accumulation — years of relationship history is the asset hardest to rebuild, and where most gets lost during a migration.
The e-commerce business
The data sits on the platform and the platform sets the rules. Customer lists, order history and reviews carry different portability levels. A business that also builds its own channel balances that dependency: the platform stays a sales channel rather than the only channel. One holding its own list survives a rule change.
The manufacturer
Machine records and quality data can be the most valuable asset. That data usually sits in a supplier’s system. Does the contract state that the data is yours and can be exported? That question belongs at the purchasing stage. Asked afterwards, the answer cannot be changed, and once signed the negotiating power is gone too.
Anyone using AI tools
The question here differs: is the data you enter stored, and is it used in model training? In corporate accounts it generally is not; in free versions the situation can differ, and the two sets of terms may not match. That single clause needs checking before critical data goes in. Ten minutes of reading shapes months of use.
Decision Order
BU BÖLÜMÜN ÖZETİ
- One: draw the inventory
- Two: mark the critical ones
- Three: test portability
- Four: scan the terms
Four steps.
One: draw the inventory
Which data sits where, in whose name, reachable by whom? Half a day, and it lays the ground for everything else. Keep the table under twenty rows.
Two: mark the critical ones
Data whose loss or exposure would stop the work. Four headings usually top the list. Customer records, pricing logic, signed contracts and personal information.
Three: test portability
Pick the tool holding the critical data and run the export. An hour, and it shows your dependency level clearly. If the result is bad, you learn it today rather than during a crisis.
Four: scan the terms
Look at three clauses in the same tools’ data terms. Ownership, retention and liability. Note what you found in two sentences beside the inventory; you will not need to read them again.
Where to Start?
BU BÖLÜMÜN ÖZETİ
- Write down your most critical data
- Test that tool
- Search three clauses in its terms
- Put the result into a written note
Four jobs, one week.
Write down your most critical data
One line suffices. Usually it is the customer list. Where does it sit, in whose name?
Test that tool
Run the export and open the resulting file in another programme. The real test is that second step.
Search three clauses in its terms
Data, retention, liability. The search function finds them in ten minutes.
Put the result into a written note
Two sentences are enough. That note gets used in your next tool selection and saves you repeating the work.
What Not to Do?
BU BÖLÜMÜN ÖZETİ
- Keeping critical data in a personal account
- Not naming a single source
- Leaving the exit plan until later
- Not tracking contract changes
Four traps.
Keeping critical data in a personal account
When corporate data sits in a personal account and its owner leaves, a loss of access turns into a loss of data. A corporate account removes that risk from the outset.
Not naming a single source
Where three copies of the same data exist, which one is correct stays unclear. Name a single source for critical data. Let the other copies be references, not sources.
Leaving the exit plan until later
A question not asked when buying the tool gets expensive when leaving it. Ten minutes spent before subscribing saves weeks afterwards.
Not tracking contract changes
Terms change and the notifications get deleted unread. Looking again at your critical tools’ terms once a year is enough. A ten-minute job.
A Solid Digital Foundation
BU BÖLÜMÜN ÖZETİ
- The data inventory
- The critical data list
- The portability note
- The terms summary
Four stones.
The data inventory
Four columns, at most twenty rows. Updated yearly, with one row added per new tool.
The critical data list
Data whose loss stops the work. This list sets the priority for protection; not every row deserves the same care.
The portability note
Which tool releases data, which does not? That note underpins tool selections and renewal negotiations.
The terms summary
Ownership, retention and liability clauses. Two sentences per critical tool, reviewed once a year.
Frequently Asked Questions
Sık Sorulan Sorular
Which data, in which system, under which account? If that question has no answer, the other three cannot be asked. The sequence starts here. A data inventory produces the answer in half a day.
Is the account in the business’s name, or is it an employee’s personal one? Corporate data sitting in a personal account becomes a problem when that person leaves. This distinction is the most commonly skipped point in small businesses — and opening a corporate account is usually a few minutes’ work with no reason to defer it.
The real test of ownership. Does the export work? Does the resulting file open elsewhere? Does everything come? The portability test answers in an hour.
For what purposes can the provider process the data, how long do they keep it, how does deletion work? Those answers sit in three clauses of the contract and get scanned in ten minutes.
You do not have to drop it immediately. There is a three-tier remedy. Start taking regular manual backups; even a monthly export reduces the dependency markedly. Then ask the provider — some systems open a fuller export on request. Finally, set that condition upfront in your next tool selection. Switching only makes sense if there are other reasons too; the migration itself carries cost, data-loss risk and a learning period.
The cloud itself is not the risk; it is usually safer than your own server. The real risk is lack of control: not knowing what sits in which cloud, never cleaning up access, never testing the exit. Once those are done the cloud becomes an advantage and both access and backup get easier. But scattered use across many clouds raises cost and risk alike; where possible, critical data gets consolidated under one roof.
It depends on the terms and the type of data. Records containing personal data need anonymisation or legal advice first. For business data without personal information, one question remains: is this data used in model training? In corporate accounts it generally is not. If you are unsure, a simple rule works. Customer names and identifying details stay out; content goes in.
Inventory yearly, portability test yearly, terms scan yearly. Together they take a few hours and none of them costs money. Three situations also call for an interim check. A new tool arriving, an employee leaving, and a change-of-terms notification from a provider. Those three triggers keep the arrangement alive; calendar-based checks get forgotten, event-based ones do not.
