Digital sovereignty
In shortSovereignty is not a state but the answer to four questions: law, operations, data, capability.
At a glance
- What it does not mean
- Not autarky, not abandoning non-European technology, not returning to your own server room
- Four layers
- Applicable law, operations and access, data format and export path, in-house or reachable capability
- Measurable through
- Switching cost in working hours, date of the last test export, ownership chain of key providers
- Most common error
- Equating sovereignty with server location
- Second most common
- Treating it as all-or-nothing instead of deciding per data category
- Entry effort
- One morning for an inventory of the eight to twelve most important tools
Digital sovereignty is usually discussed as an attitude and rarely examined as a property. The term becomes useful only once you break it into questions that have answers.
Four of them are enough.
The four questions
Law. Which law does the provider answer to, and who can demand disclosure from it? This layer decides the reach of the US CLOUD Act and is the only one that can change overnight — through an acquisition.
Operations. Who holds administrative access to production systems, from which countries, in which cases, logged how? This layer decides everyday reality and rarely appears in the main contract.
Data. What format does it sit in, and how fast can you get all of it out — with attachments, relations and history? This is the only layer that can be improved purely technically, through Open standards and a tested export.
Capability. Could someone in-house or within reach run this if the provider disappeared? This layer is overlooked most often and is the hardest to build at short notice.
What sovereignty is not
Not abandoning non-European technology. Not your own server room. And not a state you reach and then possess.
A provider's registered office is a snapshot; changes of ownership are the norm in this market. The durable measure is therefore not origin but the price of leaving — what is described under Vendor lock-in.
How to start
With a table rather than a decision of principle. Eight to twelve rows for the tools whose failure would halt operations. Six columns: product, parent company, owner, last change of ownership, export path, last successful test export.
The final column is the only one you cannot research. It arises only from doing — which makes it the most meaningful. How such a test runs is set out under Exit strategy.
The measure that holds
Two numbers say more than any explanation: the estimated switching cost for your three most important systems, and the date of the last successful test export. Both can be improved, both can be shown, and both visibly age.
Common questions
- Does sovereignty mean giving up American software?
- No. It means being able to decide. An open-source tool of American origin, operated by you, can be more sovereign than a European subscription product with no export path — because in the first case leaving remains possible.
- How does a mid-sized company start?
- With a table: eight to twelve rows for the tools whose loss would halt operations, and six columns — product, parent company, owner, last change of ownership, export path, last successful test export. Review it twice a year.
- Is this not mainly a public-sector topic?
- Public bodies have additional requirements, but the mechanics are the same. Through NIS2 supply-chain requirements and through tenders, the topic now reaches small suppliers too.
- How do I know we are making progress?
- By two numbers: the estimated switching cost for your three most important systems, and the date of the last successful test export. Both improve measurably, while words like "sovereign" do not.