"Digital sovereignty" has moved from academic panels into cabinet meetings and procurement committees. When a change of US administration can alter the rules governing a data transfer overnight, when a single cloud outage can halt public services, and when the software running Europe's hospitals, schools and ministries is licensed from three American companies, the question of who ultimately controls Europe's digital infrastructure stops being theoretical. This article explains what EU digital sovereignty means, why it matters, and what "sovereign by design" looks like in practice.
What digital sovereignty actually means
At its core, digital sovereignty is the ability of European institutions, businesses and citizens to exercise autonomous control over their digital systems — the data they create, the software they run, and the infrastructure they depend on. It is usually broken into three related ideas. Technological sovereignty is the capacity to develop, operate and control critical technologies without being at the mercy of a single foreign supplier. Data sovereignty means that data is governed by the laws of the jurisdiction where it is collected, processed and stored. And the umbrella term, digital sovereignty, ties these together with the ability to act independently online.
A crucial distinction that marketing often blurs: data residency is not data sovereignty. Residency simply means your data physically sits in a data centre inside the EU. Sovereignty means it is also beyond the legal reach of foreign governments. A US-owned data centre in Frankfurt satisfies residency but not sovereignty — because the company that operates it can still be compelled by US law to hand the data over. That gap is the whole game.
The three levers: data, law and vendor
Analysts typically assess sovereignty along three levers. Data control: who can access the data, and where is it stored and processed? Legal control: which legal framework governs the infrastructure and the provider — EU law, or a foreign jurisdiction with extraterritorial reach? And vendor nationality: where is the provider headquartered, and where do its key decision-makers actually sit?
A provider can tick the "EU data centre" box while failing the other two. True sovereignty requires all three levers to point in the same direction. This is why sovereignty cannot be reduced to a map pin — it is as much a legal and corporate question as a technical one.
Why Europe depends on US hyperscalers
Europe's dependence is concrete. A large majority of the European cloud market — commonly estimated at around two-thirds — is served by three US hyperscalers: Amazon Web Services, Microsoft Azure and Google Cloud. Public administrations run on Microsoft 365; ministries, universities and hospitals build on the same stack.
The dependence is sticky by design. Proprietary formats, deeply integrated ecosystems and data egress fees make switching costly and slow — a phenomenon known as vendor lock-in. And the risk is not hypothetical. Concentration means a pricing change, a licensing shift, an outage or a geopolitical dispute can cascade across the critical services of an entire continent at once.
The legal fault line: CLOUD Act and Schrems II
The heart of the problem is a clash of laws. The US CLOUD Act (2018) allows American authorities to compel US-headquartered providers to produce data they control — regardless of whether that data physically sits in Oregon or Frankfurt. This collides directly with the GDPR.
In July 2020, the Court of Justice of the EU, in the Schrems II ruling, struck down the Privacy Shield transfer mechanism, finding that US surveillance law — notably FISA Section 702 and Executive Order 12333 — gave Europeans no adequate protection and no effective redress. Its successor, the EU-US Data Privacy Framework adopted in July 2023, restored a legal basis for transfers through a US executive order and a new Data Protection Review Court. But it does not neutralise the CLOUD Act, and — like its two predecessors — it faces the near-certainty of a fresh legal challenge and shifting political winds in Washington. Relying on it means building on a fault line.
The rulebook Europe is building
Europe's answer is partly regulatory. The GDPR set the global benchmark for data protection. The Digital Markets Act and Digital Services Act rein in the largest gatekeeper platforms. The Data Act, whose cloud-switching provisions took effect in September 2025, is designed to break lock-in by mandating easier portability and cheaper data egress. NIS2, in force since October 2024, raises cybersecurity obligations across essential and important sectors.
Alongside these sits the EU Cloud Services Scheme (EUCS), which aims to certify cloud providers — though its most contentious element, sovereignty requirements that would have restricted certification based on provider headquarters, was watered down and remains politically live. Beyond the laws, initiatives such as Gaia-X promote a federated data-infrastructure framework built on European rules and open standards.
What "sovereign by design" means
Regulation sets the floor; architecture does the real work. "Sovereign by design" means building systems so that sovereignty is a structural property, not a contractual promise bolted on afterwards.
In practice that means open-source software you can audit and self-host; open standards and formats that prevent lock-in; hosting under exclusively EU jurisdiction; and — crucially — encryption where the customer holds the keys inside the EU. The European Data Protection Board has highlighted customer-held encryption keys as the strongest technical safeguard against foreign access demands, because they make a CLOUD Act order technically unenforceable against the data's content. A system that is sovereign by design does not depend on a foreign government's goodwill or a fragile adequacy decision — it removes the exposure at the root.
What this means for you
The encouraging news is that this is no longer aspirational. The German state of Schleswig-Holstein is migrating roughly 30,000 public-sector workstations off Microsoft. By late 2025 LibreOffice was running on around 80% of them, Exchange and Outlook had been replaced by Open-Xchange and Thunderbird, and the state reports saving well over 15 million euros — while explicitly framing the move as a sovereignty decision, not merely a cost-cutting one. Federal tools such as openDesk offer a fully sovereign digital workplace.
For most business and public-sector needs — email, office suites, storage, video calls, collaboration — mature European and open-source alternatives now exist. You do not have to migrate everything overnight. Start by mapping where your data lives and under whose law it falls, prioritise the systems holding your most sensitive information, and choose sovereign-by-design options as contracts come up for renewal. Sovereignty is built one deliberate decision at a time.
