DATA SOVEREIGNTY

from a driver of complexity to a strategic advantage
Guest data, content, movement profiles, booking information, AI-driven delivery: Tourist organizations have never been as data-driven as they are today. And the question has never been more pressing: Who actually has control?
These questions are posed by Robert Klauser in his keynote speech for the session "Data Sovereignty and Compliance" on Wednesday. The managing partner of infomax websolutions GmbH in Grassau has been dealing with the challenges in the digital (tourism) world for over 25 years. His particular interest lies in the effects of digitalization on tourism value creation and corporate structures.
Data storage is not yet data sovereignty
Many destinations work with a variety of systems – CMS, data hubs, CRM, booking, newsletters, analysis tools, AI applications. However, data sovereignty does not automatically arise from data storage.
Data sovereignty is determined by interfaces, role models, contract structures, and architectural principles. At the same time, regulatory frameworks such as GDPR, Data Act, AI-Act, and NIS2 intensify the requirements for transparency, documentation, and governance.
Keynote points to a strategic leadership task
Robert demonstrates why data sovereignty for DMOs and tourism companies is not an IT detail or a mere data protection issue, but rather a strategic leadership task. Using typical weaknesses in destinations, it becomes clear where real risks lie – from platform dependencies and unclear data processing agreements to AI tools without governance.
The central question is: How can digital sovereignty be concretely shaped? Which architectural principles create control, auditability, and future-proofing? And how can compliance evolve from a mandatory program into a competitive advantage?








