Digital Sovereignty
A Pragmatic Approach Beyond Ideology
1. Why Digital Sovereignty Matters Now
Digital Sovereignty has become one of the most discussed topics in European IT. For many years, technological dependencies outside Europe were accepted as part of an increasingly globalized digital economy. Technology worked, supply chains were relatively predictable, global platforms offered enormous capabilities and many of the risks associated with those dependencies remained largely theoretical.
The events of recent years changed that perception. The pandemic exposed vulnerabilities in global supply chains. Geopolitical tensions added uncertainty to international relationships previously considered relatively stable. Transportation costs, tariffs, export restrictions, regulatory changes and different jurisdictions have become relevant factors in technological decisions. Dependencies that already existed suddenly became much more visible.
But geopolitics and supply chains are only part of the problem. Europe also has a technological capability gap in several strategically important areas. In semiconductors, hyperscale infrastructure, computing capacity and important areas of software and cloud technology, Europe has fallen behind North America and Asia. This is certainly not true everywhere — Europe remains strong in several fields of enterprise technology — but the overall dependency is significant.
And this technology gap is itself part of the sovereignty problem. We cannot eliminate a dependency simply by deciding that we no longer want it. An alternative has to exist — and it has to work.
This is why we believe Digital Sovereignty should no longer be discussed only at political or institutional level. The consequences of technological dependencies ultimately reach individual organizations. A decision, disruption or change outside your control can affect the availability, cost, legality or operation of technology your business depends on.
A dependency is not automatically unacceptable. But it should be understood.
2. Beyond Politics and Ideology
Digital Sovereignty is often discussed through political or ideological positions. On one side are those who question whether there is a meaningful problem at all: the cloud works, we have used these platforms for years, why should we change anything? At the opposite extreme, sovereignty is sometimes reduced to a set of absolute principles: data must remain in Europe, software should be open source, proprietary technologies should be avoided, licence costs should disappear and foreign technologies should be replaced as quickly as possible.
We consider many of the concerns behind the second position legitimate. We support stronger European technological capabilities. We generally prefer open technologies where they provide a suitable solution. We consider unnecessary vendor lock-in a business risk, and we believe European alternatives deserve priority where they meet the actual requirements.
But technological decisions should not be determined by ideology alone. A technology can be excellent and still create a dependency. A technology can be open source and still create substantial lock-in — or simply be operationally inadequate for a particular business.
Access to source code provides important freedoms, but it does not automatically guarantee independence. A project maintained by a single developer, built around non-standard interfaces or storing information in formats that are difficult to exchange can create a stronger practical dependency than a widely supported commercial platform.
Sovereignty depends not only on whether you can inspect the software, but also on whether you can realistically maintain it, replace it and take your data somewhere else.
The relevant question is therefore not which technological camp an organization belongs to. It is:
What do you depend on, what do you actually control
— and what happens if something changes?
This turns Digital Sovereignty into something businesses already understand: risk management.
Europe Cannot Procure Its Way to Technological Sovereignty
Recognizing a strategic dependency is relatively easy. Replacing it is much harder.
Over the last decade, we have seen European public-sector technology strategies strongly influenced by political and ideological objectives. We consider the intention behind many of these initiatives legitimate and necessary. In our view, however, some approaches concentrated too heavily on which technologies should be replaced and insufficiently on how viable alternatives would be developed, financed and gradually introduced into real operational environments.
Complex environments contain years of accumulated documents, applications, integrations, workflows, skills and user experience. Political preference cannot make those dependencies disappear overnight. When migrations move faster than the maturity of the alternative, the result can be reduced productivity, compatibility problems, frustrated users, unexpected costs and eventually a return to established proprietary or hyperscale platforms.
We do not consider this evidence that open source failed. We consider it evidence that migration can fail when ideology moves faster than engineering capability, investment and realistic transition planning.
There is also a more fundamental problem. Europe increasingly recognizes open technologies as part of the answer to technological dependency, yet many of the world’s most successful open-source technologies did not reach their current maturity through volunteer work alone. Behind them are often professional engineers financed by major technology companies, foundations and commercial ecosystems. In many cases, global Big Tech itself employs entire teams working on open-source technologies because those technologies are strategically important to its business.
Europe should learn from that model.
If Europe considers certain open technologies strategically important, Europe must also take responsibility for financing their development.
It is not enough for public administrations to select an open-source product and expect its community to close functionality, integration, usability and support gaps. If Europe wants alternatives capable of competing with mature global platforms, somebody has to employ the engineers who build them.
That does not require the European Institutionsthemselfs to become a software company. Development can be financed through European private companies, foundations, dedicated development organizations, publicly financed engineering teams or combinations of these models. The organizational model can vary. The principle cannot: strategic technological capability requires sustained professional investment.
Public procurement can buy technology. Strategic investment must also help create technological capability.
If a public organization replaces a proprietary product with an open-source alternative but contributes nothing meaningful to the development and sustainability of that ecosystem, it has changed what it consumes. It has not necessarily strengthened European technological capability.
Europe cannot demand greater technological independence while expecting strategically important alternatives to emerge primarily from unpaid community work. If Europe wants European organizations to choose European technology, Europe must help create technology worth choosing.
We want greater European technological sovereignty. Precisely because we want it to succeed, we do not believe political preference can substitute for engineering capability.
Open Source Is Important — but It Is Not Sovereignty by Itself
Open source remains an important part of this strategy. The ability to inspect software, understand how it operates, contribute to its development and reduce dependence on a single supplier can provide substantial advantages.
But open source, free software, zero licence cost and Digital Sovereignty are not interchangeable concepts. Open software still requires maintenance, security work, integration, documentation, infrastructure, expertise and sustainable financing. A zero licence invoice does not mean zero cost, just as a commercial licence does not automatically mean that an organization has surrendered technological control.
We therefore do not consider commercial software or intellectual property inherently incompatible with Digital Sovereignty. At the same time, we do not ignore the dependencies that proprietary ecosystems can create. A good product does not stop being a dependency simply because it works extremely well.
Both open and proprietary models have advantages and disadvantages. What matters is understanding the resulting dependencies, costs, operational requirements and ability to change direction later.
Open Formats May Matter Even More Than Open Software
Software can eventually be replaced. Data that cannot be extracted, understood or exchanged with another system is a much more difficult problem.
This is why we consider open and interchangeable formats, documented interfaces and APIs fundamental components of Digital Sovereignty. A format being documented or technically accessible is not enough if, in practice, only one application can meaningfully use it.
Well-designed exchange formats allow different applications to interpret the same information, systems to coexist and data to survive the software that originally created it. This reduces migration costs and makes gradual transitions possible.
An organization does not necessarily need to replace an entire ecosystem to increase its sovereignty. Sometimes the first important step is simply ensuring that its information can leave it in a form another system can actually use.
The ability to change tomorrow can be more important than changing everything today.
3. From European Sovereignty to Your Business
Data Location Is Not the Same as Jurisdiction
A common simplification in discussions about Digital Sovereignty is to focus primarily on where data is physically stored.
Data location matters, but it is only one part of the question.
A service may store its data entirely within European data centers while the company operating, administering or ultimately controlling the service belongs to a non-European jurisdiction. Depending on the corporate structure, applicable legislation and circumstances, obligations originating outside Europe may therefore still affect the provider and potentially the data or services it controls.
European data location does not automatically mean European jurisdiction — and neither automatically means that the customer has operational control.
These are three different questions:
Where is the data located? Who operates and controls the infrastructure? Under which jurisdiction does the organization controlling it operate?
This does not automatically make a non-European provider unsuitable. It means that the dependency should be understood rather than reduced to a data-center address.
Where jurisdiction represents a relevant risk, the answer may again be architectural rather than ideological: limiting which information is entrusted to the service, maintaining independent European or local copies, separating critical functions, preserving portability and creating realistic recovery or exit options.
Sovereignty begins with knowing which parts of your infrastructure remain outside your control — legally as well as technically.
What if There Is No Suitable European Alternative?
This is one of the questions that sovereignty discussions sometimes prefer to avoid. For us, it is one of the most important.
If a European solution provides the required functionality, quality, security and sustainable cost, we give it priority. If an alternative is approaching the required maturity, a gradual transition can be planned. But if no suitable European alternative currently exists, pretending otherwise does not make the business or Europe more sovereign.
Use the technology you need — but understand and manage the dependency you are accepting.
A non-European platform does not have to control everything around it. Critical data can be independently backed up or replicated locally or within European infrastructure. Services can be separated where appropriate. Open interfaces and formats can preserve portability. Independent recovery capabilities can be maintained, contractual and jurisdictional dependencies can be evaluated, and realistic exit strategies can be prepared before they are needed.
The alternative infrastructure does not always have to reproduce the primary platform perfectly. A local or European recovery environment may be slower or less capable than the global platform used for daily operations and still have enormous value during an exceptional situation.
Better a limited independent capability than no independent capability at all.
And this leads to another important distinction: Digital Sovereignty is not only a European geopolitical problem.
It is also an individual business problem.
Even if every cloud provider your company used were European, your dependencies would not disappear. Your account can have a problem. An identity system can fail. A subscription can be suspended. A configuration error can affect your environment. An automated security mechanism can restrict access. Commercial conditions can change. A service can disappear. Or your individual tenant can simply malfunction while the global platform continues operating normally.
“We’ve Used It for Ten Years and Never Had a Problem.”
That may be completely true. Global cloud platforms have achieved extraordinary levels of reliability.
But historical reliability and individual business continuity are not the same thing. The fact that you have never lost an important email does not make a backup unnecessary, and the fact that a global platform is operating normally does not guarantee that your individual environment is available.
Think about electricity. If an entire district loses power, the problem is immediately visible. The infrastructure provider knows that thousands of customers are affected and significant resources will be dedicated to restoring service. If only your apartment loses power, the situation is different. Is the problem in the distribution network, the meter, the building or your own installation? Before service can be restored, somebody may first have to establish whose problem it actually is.
Digital infrastructure is not so different. A global outage affecting millions of users receives immediate attention. A problem affecting one tenant, one account, one configuration or one customer may follow a very different troubleshooting and escalation path.
A provider can be too big to fail while your individual service is still capable of failing you.
This has nothing to do with whether the provider is European, American or Asian. It is simply dependency risk — and it existed long before Digital Sovereignty became a political topic.
4. Building Your Sovereignty
We prefer gradual evolution over technological cut-off dates.
Replacing an established platform means much more than installing different software. Users need training, documents must be migrated, integrations rebuilt, workflows adapted, applications tested, technical expertise developed and contracts reconsidered — while the business must continue operating.
A badly executed sovereignty project can therefore reduce resilience instead of increasing it.
Our approach is straightforward:
What is ready can move.
Where European and Open solutions already meet the technical, operational and economic requirements, they should be seriously considered and, where appropriate, prioritized.
What is becoming ready can be planned.
Create interoperability, test alternatives, prepare integrations, train users and use natural technology cycles to make migration progressively easier.
What cannot yet move should be protected.
Understand the dependency. Keep critical information independently accessible. Maintain appropriate backup and recovery capabilities. Preserve portability and avoid extending the dependency unnecessarily into other parts of the infrastructure.
Gradual does not mean doing nothing. It means creating the conditions under which tomorrow’s migration becomes a rational business decision rather than today’s ideological experiment.
Sovereignty Also Has an Economic Dimension
European and national policies increasingly support digital transformation, cybersecurity, infrastructure and strategic technological capabilities. Where modernization projects are already being considered, available incentives and funding programs can therefore become another legitimate part of the assessment.
The objective should not be to invent a project merely to obtain public funding. But businesses should not ignore legitimate incentives that can improve the economics of investments they already need to make.
A transition toward greater sovereignty may therefore be driven by several factors at once: reduced dependency, improved resilience, modernization requirements, natural lifecycle events and, where applicable, available support for the investment.
Our Approach
For us, Digital Sovereignty goes beyond data location. Access, control and jurisdiction matter — but so do functionality, quality, operational continuity and cost.
We are explicitly in favor of greater European technological independence. We prioritize European technology where it provides a viable solution, generally favor open technologies where they reduce dependency and provide operational value, support open standards and portable data, and believe strategic technologies require commercially sustainable and professionally financed development.
But the objective is not European technology at any cost.
Where dependencies cannot yet reasonably be removed, they should be understood and managed. Where alternatives become viable, they can progressively replace them. And migrations should respect the business, its processes, integrations and people rather than forcing them to follow an arbitrary technological deadline.
Our approach can ultimately be reduced to four principles:
Identify what you don’t control. Understand what happens if it changes.
Reduce the dependencies that can reasonably be reduced.
Protect yourself against the ones you choose to keep.
The objective is to move towards greater European Digital Sovereignty at a sustainable pace — while consciously managing the dependencies that remain.
Digital Sovereignty is not a product that can simply be purchased and installed. It is an architectural, operational and strategic process.
Europe cannot choose alternatives that do not yet exist, and closing that technology gap requires investment, professional engineering and time. Individual businesses, however, do not need to wait before starting. They can understand their dependencies, protect critical data, improve portability, create recovery options and progressively adopt European alternatives where they make sense.
Where do you depend on technology you don’t control?
You don’t need to know the answer before talking to us. We can start from there.
Talk to us about Digital Sovereignty →