
Freedom of choice, transparency, control – and greater resilience: Towards digital sovereignty in Europe
What does digital sovereignty mean?
Digital sovereignty describes the ability of states, organisations and companies to develop, operate and control critical digital technologies themselves, or at least to source them within Europe from European companies. To date , this objective has failed primarily due to one central problem – the lack of strong, globally competitive European IT manufacturers in key sectors. From today’s perspective, it is therefore clear that complete technological self-sufficiency for Europe is not realistic in the short term. Nevertheless, it would be wrong to write off digital sovereignty as unattainable. Rather, what is needed is a pragmatic, partnership-based approach that reduces existing dependencies – whilst at the same time ensuring the capacity to act.
Challenges on the path to digital sovereignty
1. Dependence on non-European platforms
In almost all areas of IT, non-European corporations dominate :
- Cloud and AI platforms
- Operating systems and software ecosystems
- Social networks
- Cyber defence platforms
This situation means that sensitive data is frequently processed on non-European infrastructure, European data protection and security requirements can only be monitored to a limited extent, and political and economic dependencies arise. However, completely doing without these technologies is currently neither economically nor technologically realistic.
2. Legal and political risks
Legislation such as the US CLOUD Act clearly demonstrates that even storing data in European data centres does not guarantee complete legal certainty if the provider is subject to non-European law. For European public authorities, critical infrastructure operators and businesses, this means:
- there is no legal certainty regarding data sovereignty,
- enforcement of the GDPR is not possible,
- a loss of trust within society and the business community.
Digital sovereignty thus remains a theoretical construct. This is because data outflow cannot be prevented, and even relevant European laws have proved toothless without appropriate technical controls.
3. Outflow of value creation and lock-in effects
Another drawback is of an economic nature:
- Large parts of digital value creation (licences, subscriptions, cloud usage, AI services) flow to countries outside Europe. Exceptions include Delos Cloud and Stack IT, which can be regarded as sovereign European solutions.
- National companies find themselves caught in lock-in effects – partly due to a lack of consideration for an exit strategy: once on a platform, switching is expensive and technically complex; in particular, the handover and migration of data pose a major challenge.
- Start-ups originally founded in Europe are often acquired by US companies and are then also subject to US legislation.
Whilst there are a few successful European companies such as SAP or – in the hardware sector – ASML, these are exceptions. There is no comprehensive industrial base, and even the companies mentioned usually rely on the leading American providers in this sector for their cloud services.
4. The fragmentation of the European market
Europe is characterised by different languages, national legislation and regulatory diversity. This fragmentation makes it difficult for European IT providers to scale up and achieve rapid market penetration. Massive investment in basic research and infrastructure is required. Whilst American or Chinese companies find a huge single market, European providers have to serve 27 markets simultaneously.
The dilemma of digital sovereignty
The lack of strong European IT manufacturers means that, although digital sovereignty is currently being called for politically and is also being planned strategically, it is not technologically secured. Europe can set rules – for example, on data protection – but is often forced to enforce them using foreign technology, which is a contradiction in terms.
Conclusion: Digital sovereignty in Europe is failing not because of a lack of will, but because of industrial realities. Complete technological self-sufficiency will not be achieved in the short term. Without its own cloud infrastructures, platforms, chips and software ecosystems, it remains a long-term goal, not the status quo. Although there are initiatives by some providers to make European cloud services available, these are mainly based on technologies from American or Chinese manufacturers. Furthermore, it must be noted that, with few exceptions, virtually the entire cybersecurity product sector is in American or Israeli hands.
A realistic approach to achieving greater digital sovereignty in Europe
1. Conscious technology selection rather than dogmatism
- A combination of European and international technologies
- Clear assessment of risks, dependencies and alternatives
- Architectural decisions with exit strategies
2. European and local operational expertise
- Operation of IT infrastructures by European service providers
- Data storage and control in European data centres
- Local contacts who understand regulatory and sector-specific requirements
3. Strong partnerships rather than isolated solutions
- Cooperation between European IT service providers, software manufacturers and research organisations
- Use of open standards and interoperable architectures
- Joint development of sovereign operating models (e.g. sovereign cloud, managed services)
4. Focus on cybersecurity and governance
- Transparent security concepts
- A combination of international security technologies and European operations
- Clear responsibilities, audits and compliance structures
The key point:
Digital sovereignty is not self-sufficiency, but freedom of choice, transparency and control.