Digital sovereignty: what it is, why it matters, and what the EU is doing about it
Digital sovereignty is the ability to decide how your data and the systems that process it are used, and to make that decision stick, even against a foreign government or a supplier on another continent. It is not protectionism, and it is not a demand that everything be built at home. It is the difference between renting your critical infrastructure on someone else’s terms and being able to keep running it on your own.
Europe starts from deep dependence. A handful of mostly US firms control roughly two-thirds of the European cloud market, and by one European Parliament estimate the EU imports well over 80% of its digital products, services and infrastructure. That dependence is also legally fragile: almost every transatlantic data transfer ultimately rests on a single adequacy decision, the EU–US Data Privacy Framework, which in turn rests on a US executive order that any president can rewrite.
We have been here before. The European Court of Justice struck down Safe Harbor in 2015 and Privacy Shield in 2020; the framework that replaced them was upheld by the EU General Court in September 2025 and is, once again, on appeal before the Court of Justice. This article sets out what sovereignty actually means, why the dependence is a genuine risk rather than a slogan, and how Europe’s answer has shifted from regulating the dependence to building an alternative.
Read the full articleShow less
Three kinds of sovereignty
It helps to separate three ideas that are often blurred together. Data sovereignty is about control and jurisdiction: who can lawfully compel access to information, regardless of where it is stored. It is not the same as data residency, which only asks where the bytes physically sit. Digital, or technological, sovereignty is broader, the capacity to build and operate the technology stack itself, from chips and networks to cloud platforms, software and AI models. Strategic autonomy is the political goal the other two enable: the freedom to act, and to keep acting, without being coerced or cut off through infrastructure you do not control.
The distinction matters because most “sovereign” marketing addresses only residency. A datacentre in Frankfurt satisfies residency, but if the company operating it answers to a parent in another jurisdiction, the same data can be residency-compliant and sovereignty-exposed at once. Sovereignty is about who holds the leverage, not where the disk happens to spin. Keeping the three ideas apart is what lets you tell a genuine guarantee from a reassuring label.
Why the dependence is a real problem
The dependence is structural, not incidental. A small number of mostly American firms, Amazon, Microsoft and Google, hold the majority of the European cloud infrastructure market, while European providers are left with a low double-digit share that has barely moved in years. The same pattern repeats up and down the stack, in operating systems, productivity suites, search, browsers, advanced chips and the foundational AI models that everything else is now being built on.
That would matter less if the legal ground were stable, but it is not. United States law reaches American providers extraterritorially. The CLOUD Act compels a provider to disclose data in its control regardless of where that data is stored, and intelligence authorities such as FISA Section 702 operate without the protections or redress that European law assumes. Because the bridge that currently legitimises transatlantic transfers rests on a revocable executive order rather than a statute, it can be weakened with a signature. In 2025, upheaval at the US privacy oversight board that underpins the framework’s redress mechanism was a sharp reminder of how thin that foundation is.
Dependence becomes a concrete operational risk the moment the supplier’s home government, not yours, can change the rules, raise the price, or order a service withheld. Recent European debate has openly discussed scenarios that were once dismissed as paranoia, from a foreign administration leaning on a provider, to the fear of a remote “kill switch” over critical services. You do not need to believe the worst case to conclude that resting essential functions on infrastructure you cannot govern is a risk worth removing.
There is an economic dimension too. When the core of the digital economy is rented from abroad, the margins, the data network effects and the high-value engineering jobs largely accrue elsewhere, and Europe is left maintaining the dependency rather than capturing the value it creates. Sovereignty, in this framing, is not only about security; it is about whether the continent builds or merely consumes the technologies that now underpin every industry, from banking to healthcare to defence.
A short history of broken bridges
The legal arrangement that lets personal data flow from the EU to the United States has been built and rebuilt three times, and twice demolished by Europe’s own highest court. Safe Harbor governed transfers from 2000 until the Court of Justice struck it down in 2015. Its replacement, Privacy Shield, lasted from 2016 until the Schrems II judgment invalidated it in 2020, again because US surveillance law gave Europeans no equivalent protection and no meaningful way to seek redress.
The current Data Privacy Framework, adopted in July 2023, was upheld by the EU General Court in September 2025, but that decision is under appeal to the Court of Justice, the same court that has twice ruled against earlier arrangements. The lesson is not that any single framework is doomed, but that anything resting on the goodwill of another jurisdiction’s domestic politics is inherently provisional. An organisation that has built its data flows on the assumption that the bridge will always stand has taken on a risk it neither controls nor can price, and that it may have to unwind under deadline if the court rules again.
The rules Europe has built
Europe’s legislative response has two layers. The first is protective. The GDPR, in force since 2018, restricts moving personal data outside the European Economic Area, and the Schrems II ruling made clear that contractual clauses alone cannot cure exposure to foreign surveillance, a transfer needs supplementary technical measures to be lawful. The second layer pushes control deeper into the stack. The Data Governance Act and the Data Act, most of which applies from 12 September 2025, make data portable between providers and, crucially, require cloud services to take measures against unlawful access by non-EU governments, with the switching fees that entrench lock-in due to disappear entirely by 2027.
Alongside them sits a wave of structural regulation. NIS2 raises the baseline for cybersecurity, governance and incident reporting across thousands of essential and important entities, though by 2026 several member states, the Netherlands among them, were still finishing transposition into national law. The AI Act, in force since August 2024, phases in through 2025 to 2027; in a sign of how contested the pace has become, lawmakers agreed in May 2026 to push its heaviest high-risk obligations back further still. The Digital Markets Act and Digital Services Act, meanwhile, take direct aim at the dominance of a handful of non-EU “gatekeeper” platforms.
Taken together, these rules are not merely consumer protection. They are a deliberate attempt to make European control of data the default condition of doing digital business in the Union, and to give regulators, courts and customers concrete levers when it is not. The effect is cumulative: each instrument narrows the room in which an organisation can treat sovereignty as optional.
- 2015CJEU strikes down Safe Harbor
- 2018GDPR applies across the EU
- 2020Schrems II strikes down Privacy Shield
- 2022DGA, DMA, DSA and NIS2 adopted
- 2023EU–US Data Privacy Framework adopted
- 2024AI Act enters into force
- 2025Data Act becomes applicable
- 2026European Technology Sovereignty Package
From regulating to building
Regulation alone cannot manufacture an alternative, and Europe has begun to admit as much. Two influential 2024 reports, Enrico Letta’s on the future of the single market and Mario Draghi’s on competitiveness, both placed digital dependence at the centre of Europe’s economic problem. Draghi argued for additional investment on the order of hundreds of billions of euros a year, a scale the continent has not attempted in a generation, and warned that without it Europe would remain a taker of other people’s technology. Policy has started, slowly, to follow.
In June 2026 the European Commission unveiled a European Technology Sovereignty Package, pairing a second Chips Act with a Cloud and AI Development Act intended to at least triple the EU’s datacentre capacity over the next five to seven years. Around it sit the AI Continent Action Plan, the €200 billion InvestAI programme and a series of large “AI gigafactories”, and, more concretely, a €180 million sovereign-cloud framework awarded in April 2026 to several European provider groupings and graded against formal, published sovereignty levels rather than marketing claims. The direction of travel, from buying capability abroad to building it at home, is unmistakable even where the budgets remain modest against the scale of the problem.
It is worth being honest that not everything has worked. The EU’s cloud certification scheme had its strongest sovereignty requirements, the ones that would have demanded immunity from non-EU law for the most sensitive workloads, stripped out after objections from some member states and US providers, and has been stuck ever since. Gaia-X, the federated-cloud project once held up as Europe’s answer, is widely judged to have underdelivered. Industrial and infrastructural sovereignty is proving far harder to legislate than data protection, because it has to be built, funded and bought, not merely required.
The scale of the bet
The figures give a sense of both the ambition and the gap. The original Chips Act set out to mobilise more than €43 billion in public and private investment and to double Europe’s share of global semiconductor production to a fifth by 2030, a target it is not currently on course to meet. InvestAI, launched in early 2025, aims to mobilise €200 billion for artificial intelligence, including a dedicated €20 billion fund for the “gigafactories” that would train large models on European soil. The 2026 Cloud and AI Development Act sets a goal of at least tripling the Union’s datacentre capacity within five to seven years.
Set against the Draghi report’s estimate that closing Europe’s competitiveness gap requires hundreds of billions of euros in additional investment every single year, even these sums are a down payment rather than a settlement. But the significance is directional. For the first time the European response to digital dependence is being counted in fabs, datacentres and compute, not only in articles and recitals. Sovereignty has acquired a capital budget, and with it a constituency that wants to see the money turn into capacity.
Sovereignty is not isolation
It is worth heading off the obvious objection. Sovereignty in this sense is not autarky, and it is not a boycott of American technology. The aim is not to cut Europe off but to remove single points of foreign control over things that matter, so that a change of weather in another capital cannot disrupt a hospital, a bank or a government service. Open standards, interoperability, open-source software and the freedom to switch providers are part of the same agenda; they are what keep sovereignty from collapsing into a different kind of lock-in.
Framed that way, sovereignty is less a political slogan than a risk-management discipline. It asks a familiar question, the same one any board asks about a critical supplier, and applies it to the digital foundations most organisations have stopped thinking of as a choice at all.
What it means for you
For an organisation, the politics resolve into a simpler question. European control of data is becoming both a legal expectation and a commercial one, written into procurement rules, sectoral guidance and the due-diligence questionnaires that customers increasingly send before they sign. The sensible response is not to wait for the next court ruling, but to ask whether your own stack would survive one.
That pressure is already arriving through ordinary commercial channels. Public bodies now score sovereignty in their tenders, regulated sectors fold it into supervision, and private buyers ask for data-flow and sub-processor detail as a condition of the contract. An answer that amounts to “our provider assures us it is fine” is becoming harder to give with a straight face. The organisations that will find this transition easy are the ones that treated it as an architecture question early, rather than a compliance scramble under deadline later.
That turns out to be a question of engineering as much as policy: where your data physically flows, which companies touch it along the way, and who could be compelled to hand it over or to surrender the keys. It is the subject of our companion piece, which follows a single request through the full stack, from DNS to the AI model, and shows exactly where sovereignty is won or lost.
Sources
- 1.Regulation (EU) 2016/679 (GDPR), EUR-Lex
- 2.Judgment C-311/18, Schrems II, Court of Justice (EUR-Lex)
- 3.Implementing Decision (EU) 2023/1795, EU–US Data Privacy Framework adequacy decision (EUR-Lex)
- 4.EU–US data transfers, European Commission
- 5.Judgment T-553/23, Latombe v Commission, General Court, 3 September 2025 (EUR-Lex)
- 6.Appeal C-703/25 P, Latombe v Commission, Court of Justice (EUR-Lex)
- 7.Regulation (EU) 2022/868 (Data Governance Act), EUR-Lex
- 8.Regulation (EU) 2023/2854 (Data Act), EUR-Lex
- 9.Directive (EU) 2022/2555 (NIS2), EUR-Lex
- 10.Regulation (EU) 2024/1689 (AI Act), EUR-Lex
- 11.Digital Omnibus: simpler digital rules, European Commission (19 November 2025)
- 12.Regulation (EU) 2022/1925 (Digital Markets Act), EUR-Lex
- 13.Regulation (EU) 2022/2065 (Digital Services Act), EUR-Lex
- 14.Strengthening Europe’s tech sovereignty, European Commission (3 June 2026)
- 15.Cloud and AI Development Act, European Commission
- 16.InvestAI: mobilising €200 billion for AI, European Commission (11 February 2025)
- 17.Commission advances cloud sovereignty through strategic procurement (17 April 2026)
- 18.EUCS cloud services certification scheme, ENISA
- 19.The Draghi report on EU competitiveness, European Commission (September 2024)
- 20.Letta report, “Much more than a market”, European Research Area (April 2024)
- 21.The European Chips Act, European Commission
- 22.European cloud providers’ market share holds steady at 15%, Synergy Research Group