The second architectural principle behind Canton is Data Sovereignty. It is often understood as a question of where data is physically stored and which jurisdiction applies to it, but in a multi-party application it goes further, including who receives the data, who can access it and who has the right to change it as a process moves between organizations.
This is one of the areas where Canton takes a fundamentally different approach. Privacy is not based on placing data on a shared network and then trying to hide it behind pseudonymous addresses or additional privacy layers. Instead, data is disclosed only to the parties that are explicitly meant to receive it.
Each organization can run its own Participant Node and retain control over where its data is stored, while still operating through a synchronized workflow with others. The network does not require every participant to hold a full copy of every transaction. It distributes only the relevant part of a transaction to the parties involved.
The more I look into Canton’s architecture, the more I see that data sovereignty here is not only about compliance or data residency. It is a different model for how organizations can work together without turning a shared process into unrestricted data sharing.





