Why digital sovereignty matters now
Digital sovereignty has moved from specialist policy circles into the mainstream of public administration, industrial strategy and security planning. Governments increasingly depend on digital infrastructure to deliver welfare, run tax systems, manage borders, coordinate emergency response and support healthcare. Businesses rely on cloud computing, software supply chains, global payments networks and cross-border data flows. Citizens, meanwhile, live much of their social, professional and civic lives through systems they neither own nor govern.
This dependence is not inherently problematic. The modern digital economy was built on openness, interoperability and transnational networks. Yet recent years have made the vulnerabilities harder to ignore. Cyber attacks on public institutions, disruption to semiconductor supply chains, geopolitical competition over telecommunications infrastructure, and concerns over data access by foreign authorities have all sharpened a basic question: who ultimately has control?
That question sits at the heart of digital sovereignty. It is not simply about where servers are located or whether software is developed domestically. It concerns the ability of a polity to govern critical digital functions according to its own laws, democratic choices and security interests.
Digital sovereignty is not autarky. It is the ability to remain open without becoming structurally dependent.
The concept is often invoked loosely. Sometimes it is used to justify industrial policy. Sometimes it serves as shorthand for data protection, cyber resilience or strategic autonomy. A clearer framework helps. The aim is not to retreat from global digital integration, but to ensure that essential capabilities, rules and oversight remain aligned with public interest rather than external compulsion.
What digital sovereignty is — and is not
A useful definition begins with capacity. Digital sovereignty is the ability of a state, public institution or community to exercise effective authority over critical digital assets, decisions and dependencies. That includes data governance, technical standards, identity systems, communications networks, compute infrastructure, software assurance and legal jurisdiction.
It is not the same thing as digital nationalism. Nationalist approaches tend to privilege domestic ownership for its own sake, often at the expense of interoperability, innovation or civil liberties. Nor is digital sovereignty identical to protectionism. Restricting foreign providers may reduce one risk while deepening others, such as cost, fragility or technological stagnation.
Nor should sovereignty be confused with total control. No state, not even the largest, can independently produce every layer of the digital stack, from lithography equipment and advanced chips to undersea cables, operating systems and specialist cybersecurity tools. The digital ecosystem is too complex and too globally distributed.
The more realistic objective is selective control over the most consequential layers of dependency. This means identifying where loss of access, visibility or legal authority would create unacceptable risk. It also means distinguishing between strategic functions, where redundancy and public oversight are essential, and commodity services, where open competition may suffice.
The four layers of sovereignty
To make the idea operational, it helps to think in layers.
Infrastructure
This includes connectivity, data centres, cloud environments, edge systems, cables, satellites and electricity-intensive compute. Sovereignty at this layer concerns resilience, continuity of service and jurisdictional clarity.
Data
Data sovereignty concerns who can access, process, transfer and monetise data, and under which legal regime. Not all data require the same treatment. Health records, biometric identifiers and defence-related information raise different sovereignty questions from anonymised industrial data or public weather information.
Software and standards
Code dependencies matter as much as hardware ones. Public bodies may rely on proprietary software they cannot inspect, modify or easily replace. Standards-setting also has sovereignty implications, because technical standards can embed market power and shape future compliance costs.
Governance
The highest layer is institutional: procurement rules, regulatory capacity, incident response, auditability, competition policy and democratic oversight. A country may host data domestically yet still lack sovereignty if it cannot inspect systems, enforce law or switch providers in a crisis.
Seen in this way, sovereignty is less about ownership alone than about leverage, exit options and accountable governance across these layers.
Digital sovereignty is not autarky. It is the ability to remain open without becoming structurally dependent.
Data localisation is not a complete answer
One of the most common policy responses has been data localisation: requiring certain data to be stored or processed within national borders. In some cases this is justified. Sensitive public-sector datasets, critical infrastructure telemetry or national security information may warrant strict residency and access controls.
But localisation is a blunt instrument. Storing data domestically does not necessarily prevent remote administrative access, foreign legal claims or software-level dependence. Nor does it guarantee better security. A poorly secured local system may be more vulnerable than a well-managed distributed one.
Economic costs matter too. The OECD has warned that restrictive data policies can impede trade, raise barriers for smaller firms and reduce access to digital services. For countries with limited domestic capacity, stringent localisation mandates may entrench dependence on a small number of local intermediaries rather than genuinely improving autonomy.
A more sophisticated approach distinguishes among data categories, threat models and operational requirements. Policymakers need to ask not only where data sit, but who can reach them, under what authority, with what audit trail, and whether institutions can migrate workloads if legal or strategic conditions change.
Where data are stored is less important than who can compel access, administer systems and verify what is happening inside them.
Cloud dependence and the question of exit
Much contemporary debate about digital sovereignty revolves around cloud computing, and for good reason. Public agencies increasingly use remote infrastructure for everything from collaboration tools to high-performance computing and archives. The efficiency gains can be substantial. So can the concentration risk.
Dependence becomes strategically significant when switching costs are high, technical architectures are tightly coupled, or contractual terms limit visibility and recourse. In such conditions, sovereignty is weakened not because a service is foreign, but because the customer lacks credible alternatives and meaningful oversight.
This suggests three practical tests. First, portability: can data and workloads be moved without prohibitive cost or delay? Second, observability: can the customer inspect logs, configurations and supply-chain assurances to a level appropriate for the risk? Third, continuity: is there a viable fallback if the provider suffers outage, legal conflict or political restriction?
Open standards, modular procurement and multi-vendor architectures can help, though each adds complexity. In some cases, public authorities may need sovereign hosting arrangements for especially sensitive functions. In others, the best answer may be contractual discipline and stronger technical governance rather than bespoke infrastructure.
The point is not to reject scale, but to prevent convenience from maturing into lock-in.
Semiconductors, networks and hard dependencies
The public conversation often focuses on platforms and data, yet the deeper sovereignty question lies in physical and industrial dependencies. Advanced semiconductors, telecoms equipment, rare materials, chip design tools and network components are produced through highly specialised international chains. Disruption at any one point can cascade across the economy.
The European Commission, the OECD and a range of security agencies have all highlighted the concentration of critical technologies in a limited number of jurisdictions and firms. This does not imply that every country should attempt full-scale domestic production. That would be economically unrealistic for most. But it does argue for mapping dependencies carefully and identifying where diversification, stockpiling, alliance-based sourcing or domestic capability is warranted.
Telecommunications offers a useful example. Decisions about network equipment are not merely commercial. They shape long-term upgrade paths, maintenance access and vulnerability surfaces. Similar logic applies to trusted hardware in public administration, secure identity documents and industrial control systems.
Hard dependencies deserve special attention because they are slow to build and difficult to replace. Unlike software licences, they cannot usually be unwound in a single budget cycle.
Open source, public code and strategic flexibility
Open-source software is sometimes presented as the natural route to digital sovereignty. The reality is more nuanced. Open code can support sovereignty by improving auditability, reducing vendor lock-in and allowing institutions to share improvements. Public administrations in several countries have used open standards and reusable code to build more adaptable digital services.
Yet open source is not sovereign by default. Many crucial projects are maintained by small communities with limited funding and variable security practices. Institutions that depend on open code still need internal capability to evaluate, maintain and secure it. Without that capacity, nominal freedom may become another form of dependence, this time on external integrators or under-resourced maintainers.
The strongest case for open approaches is strategic flexibility. If governments adopt interoperable architectures, require documentation and avoid proprietary dead ends, they preserve room to change suppliers, inspect systems and collaborate across agencies. Public code policies can reinforce this by treating some digital components as shared public infrastructure rather than one-off procurements.
Sovereignty grows when institutions can understand, adapt and replace the systems they rely on.
Where data are stored is less important than who can compel access, administer systems and verify what is happening inside them.
Law, jurisdiction and democratic authority
Digital sovereignty is ultimately a legal and political issue as much as a technical one. The central concern is whether democratically accountable institutions can apply their laws to the digital systems on which society depends. This includes privacy rights, competition rules, consumer protection, national security powers and due process standards.
Cross-border data requests illustrate the tension. If data relevant to citizens or public services can be accessed under foreign legal orders, domestic authorities may find their ability to guarantee confidentiality or redress constrained. Equally, excessive assertions of sovereignty can fragment the internet and undermine legitimate international cooperation on law enforcement or research.
The challenge, then, is to build legal arrangements that preserve rights and clarity across borders. Data-transfer frameworks, mutual legal assistance mechanisms, procurement rules and cybersecurity certification all matter here. So does institutional competence. Regulators and public auditors need the expertise to interrogate technical claims, not merely accept them.
Democratic authority also means preserving contestability. If essential digital functions are effectively governed by opaque contractual terms or technical standards beyond public scrutiny, sovereignty is hollowed out even if formal jurisdiction remains intact.
How public institutions can assess their exposure
For policymakers and public leaders, digital sovereignty becomes manageable when translated into a structured assessment. Five questions are especially useful.
-
Which systems are truly critical? Not every application merits sovereign treatment. Priority should go to functions whose failure would significantly impair public safety, constitutional processes, fiscal operations or core services.
-
Where are the single points of dependency? These may sit in infrastructure, identity, payments, software libraries, specialist personnel or contractual arrangements.
-
What powers do external actors hold? Consider legal access, administrative control, update authority, and the ability to suspend or degrade service.
-
What is the exit path? Institutions should know how long migration would take, what it would cost and which capabilities are needed to execute it.
-
Who inside government understands the system? Sovereignty is weakened when knowledge resides entirely with suppliers.
This type of review often reveals that the biggest weakness is not absolute dependence, but unexamined dependence. Many institutions simply do not maintain accurate maps of their digital supply chains, let alone tested continuity plans.
A sensible policy agenda
A serious digital sovereignty strategy need not be ideological. It should be discriminating, risk-based and proportionate. Several priorities recur across credible policy frameworks.
-
Classify critical digital functions and set higher assurance requirements for them.
Sovereignty grows when institutions can understand, adapt and replace the systems they rely on.
-
Use procurement to demand interoperability, audit rights, portability and transparent subcontracting.
-
Invest in public-sector technical capability, including architecture, cybersecurity, software assurance and data governance.
-
Support open standards and shared public digital infrastructure where appropriate.
-
Diversify critical supply chains through alliances, redundancy and targeted industrial policy.
-
Align privacy, competition and security objectives rather than treating them as separate silos.
-
Develop crisis playbooks for disruption involving cloud services, telecoms, identity systems and key vendors.
What should be avoided is theatrical sovereignty: symbolic localisation rules, expensive duplication of non-strategic systems, or broad restrictions that reduce openness without improving control. The goal is not to own everything. It is to avoid being unable to act when it matters.
The balance between openness and control
The hardest part of digital sovereignty is balancing legitimate control with the benefits of openness. Open networks, international research collaboration, common standards and cross-border data flows have delivered enormous gains. Overcorrection could impose high economic costs and fragment the digital commons.
Yet openness without governance is equally flawed. It can leave public institutions exposed to legal ambiguity, commercial lock-in and strategic coercion. The answer lies in disciplined interdependence: remaining connected to global systems while reducing the asymmetries that make dependence dangerous.
For smaller countries especially, sovereignty will often be achieved through coalitions rather than self-sufficiency. Shared standards, pooled procurement, regional infrastructure and common certification can increase bargaining power and resilience. Sovereignty in the digital age may therefore be more relational than territorial.
The most effective states will not be those that attempt to build every layer themselves. They will be those that know which layers matter most, preserve choice at those layers, and maintain the institutional competence to govern them with legitimacy and foresight.
From slogan to statecraft
Digital sovereignty is at risk of becoming an empty slogan, invoked whenever technology and geopolitics intersect. To avoid that fate, it must be treated as a matter of statecraft: defining essential interests, understanding dependencies, designing proportionate safeguards and preserving democratic accountability.
That requires a shift in mindset. The question is not whether a country is sovereign in some absolute digital sense. None is. The practical question is whether its institutions can continue to function, uphold rights and make autonomous choices under pressure.
In that narrower but more consequential sense, digital sovereignty is both achievable and necessary. It depends less on rhetoric than on architecture, procurement, law and capability. Above all, it depends on recognising that in a networked world, resilience and autonomy are built not by isolation, but by governing interdependence intelligently.




