Public administration runs on software. When a tax office, a hospital, or a ministry depends on tools it cannot audit, relocate, or continue operating if a supplier changes its terms, sovereignty stops being abstract — it becomes operational risk. For years, European governments treated dependence on a handful of US cloud and office providers as normal. That assumption is now breaking.
Court rulings have made lawful data transfers fragile. Geopolitical shifts have turned single-vendor reliance into a concentration risk. And a growing line of public bodies, from Kiel to Copenhagen, has demonstrated that switching is genuinely possible. This article explains why digital sovereignty has become a public-sector priority, what the law actually requires, which projects are working in practice, and how procurement — the single biggest lever governments hold — can be used to build a resilient European alternative.
What sovereignty actually means
Digital sovereignty is not autarky. No serious policymaker wants to rebuild every technology inside national borders. The workable definition is control: the ability to decide who processes public data, under which jurisdiction, with the freedom to inspect, modify, and move systems without a single supplier's permission.
Three dimensions matter. Data sovereignty concerns where information is stored and which law governs access to it. Operational sovereignty is whether you can keep systems running if commercial or political terms change. Technological sovereignty is whether the underlying code and standards are open enough to be understood and adapted. Open-source software and open standards score well on all three, which is why they dominate the projects below. Sovereignty is a spectrum, and administrations move along it deliberately rather than in a single leap.
The legal fault line: Schrems II and the CLOUD Act
The legal pressure is concrete. In 2020, the Court of Justice's Schrems II ruling struck down the Privacy Shield and held that standard contractual clauses cannot override foreign surveillance law. The 2023 EU-US Data Privacy Framework restored a transfer mechanism, but it rests on a US executive order that a future administration could weaken, and it already faces fresh legal challenges.
Meanwhile the US CLOUD Act lets American authorities compel US-headquartered providers to hand over data regardless of where the servers sit — including data centres in Frankfurt or Paris. The European Data Protection Supervisor investigated the Commission's own use of Microsoft 365 and found the supplementary safeguards insufficient. For public bodies handling health, justice and citizen records, 'the data stays in the EU' is not, on its own, a legal guarantee.
Schleswig-Holstein: the reference migration
The German state of Schleswig-Holstein has become Europe's reference case. Following a 2024 cabinet decision, it is migrating roughly 30,000 workstations off Microsoft Office and 365 onto LibreOffice, Linux, Nextcloud, Open-Xchange and Thunderbird, plus an open directory service to replace Active Directory. This is not a pilot.
By late 2025 the state reported that a large majority of the relevant workstations were already running LibreOffice, and it completed the migration of tens of thousands of mailboxes and a vast email archive away from Exchange. The government frames the move explicitly around digital sovereignty and 'public money, public code,' and reports meaningful licence savings. Crucially, it treats the effort as multi-year and staged — proof that a full-stack exit is hard but achievable.
openDesk and ZenDiS: a ready-made sovereign stack
Migrations need a product, not just a principle. That is the role of openDesk, the sovereign workplace suite built for German public administration and now stewarded by ZenDiS, the federally owned Centre for Digital Sovereignty founded in 2022.
openDesk reached version 1.0 in October 2024. It bundles proven open-source components — Collabora and OnlyOffice for documents, Nextcloud for files, Open-Xchange for mail and calendar, Element on the Matrix protocol for chat, Jitsi for video, plus OpenProject and XWiki — into one integrated, self-hostable platform. It was used at a Conference of Minister Presidents within a week of launch. The significance is structural: a state-backed integrator now maintains a coherent alternative to Microsoft 365, so individual agencies no longer have to assemble one alone.
France, Denmark and a wave of cities
The pattern is Europe-wide. France's inter-ministerial digital directorate, DINUM, runs La Suite numérique — including Tchap (encrypted messaging on Matrix, used by hundreds of thousands of civil servants), the Visio video tool, and the Docs collaborative editor — alongside the SecNumCloud 'trusted cloud' qualification for sensitive workloads.
Denmark's Ministry of Digitalisation began moving off Microsoft Office and Windows in 2025, with its minister warning against dependence on 'very few foreign suppliers'; Copenhagen and Aarhus launched parallel efforts. France's third city, Lyon, is shifting to Linux, OnlyOffice, Nextcloud and PostgreSQL. Each project differs, but the direction is consistent — and every migration makes the next administration's business case easier by enlarging the pool of experience and shared tooling.
Procurement is the real lever
Procurement is where sovereignty is won or lost. European public bodies spend enormous sums on IT, and Microsoft alone is estimated to hold roughly three-quarters of the EU public-sector productivity-software market — a concentration that is itself a risk.
The regulatory toolkit is growing. The Data Act, in force from 2025, mandates cloud portability and switching to attack lock-in. NIS2 raises security obligations for public bodies. The EUCS cloud-certification scheme and Gaia-X aim to define trustworthy providers, though the fight over explicit sovereignty criteria shows how contested this remains. Buyers can act now: weight open standards, data portability, exit costs and self-hosting in tenders; avoid multi-year all-or-nothing licences; and favour 'public money, public code' so that publicly funded software is reusable across administrations.
Lessons and takeaways
Several lessons stand out. First, sovereignty is a migration, not a purchase — budget for years, training and change management, not the flip of a switch. Second, interoperability and open formats are the real insurance, because they let you leave. Third, collaboration compounds: shared codebases like openDesk turn one state's investment into every state's option. Fourth, procurement discipline matters more than any single product, because what you require in a tender shapes the market.
For European businesses and public bodies alike, credible alternatives now exist across office, mail, chat, video, cloud and identity — and a growing directory of European providers makes them easy to find. The strategic question is no longer whether sovereign IT is feasible, but how deliberately you choose to pursue it.
