Over the past fifteen years, organisations moved en masse to the cloud, drawn by scalability, lower management overhead and access to advanced services. The downside of that shift, a heavy dependence on a handful of American hyperscalers, is now being felt in concrete terms. Geopolitical tensions, new European regulation and concerns about data governance have pushed the concept of digital sovereignty high on the agenda of government bodies, businesses and technology experts.
Experts from Cloudera, Dynatrace, Eurofiber, Rubrik and Thales recently debated what digital sovereignty means in practice and what steps organisations can take. Their analyses show that the discussion is moving away from principled positions towards concrete architectural choices and procurement policy.
What digital sovereignty means in practice
Digital sovereignty concerns the degree to which an organisation, country or region has control over its own digital infrastructure, data and software. In Europe, the debate is driven by legislation such as the GDPR, the Data Act and the EU AI Act, as well as practical concerns about the accessibility of data to American authorities under laws such as the CLOUD Act.
Ivo Veerman, Sales Director at Eurofiber Cloud Infra, stresses that sovereignty does not automatically mean organisations must manage everything themselves or avoid American providers entirely. It is more about organisations making conscious choices about where data is stored, who has access to it and under which legal framework that falls. Eurofiber positions itself as a European cloud infrastructure provider and points to the growing number of organisations that deliberately opt for data centres that are physically and legally located within the EU.
Filip Verloy, Field CTO EMEA at Rubrik, emphasises data resilience and access management. According to him, the question is not only where data resides, but also who can access it and what happens when systems fail or come under attack. Rubrik focuses on data protection and recovery after incidents, two aspects of sovereignty that are frequently underexposed in the policy debate.
Identity management as a foundation
Guido Gerrits, VP IAM Sales Europe at Thales, points to identity and access management as a frequently overlooked building block of digital sovereignty. Who decides who gains access to which systems and data, and through what technology is that governed? If that layer runs on software from a non-European vendor, an organisation effectively has less control than it realises, even if the data itself is held in a European data centre.
Thales supplies, among other things, encryption and key management solutions that allow organisations to manage their own cryptographic keys independently of the cloud provider operating the underlying infrastructure. That model, also known as bring your own key or hold your own keyis gaining traction among governments and financial institutions that must comply with strict supervisory requirements.
The combination of physical data location, legal protection and technical key management together forms a layered approach that is increasingly regarded as standard in sectors with high compliance demands.
Tension between efficiency and control
A recurring theme in the discussions is the tension between operational efficiency and the desire for greater autonomy. The major American cloud platforms offer a breadth of services, from machine learning to observability, that European alternatives cannot yet fully match. Organisations that want to operate strictly within Europe sometimes accept functional limitations or higher costs.
Experts from Dynatrace and Cloudera highlight the importance of a hybrid approach, in which critical data and processes run on European or on-premises infrastructure while less sensitive workloads can remain with hyperscalers. That split does require a clear classification of data and systems, something many organisations are still working to achieve.
The introduction of the EU Data Act, which takes effect in 2025, will oblige providers of connective products and cloud services to make switching to other providers easier, among other requirements. This lowers barriers for organisations looking to spread their dependencies, but the technical and organisational complexity of such a transition remains considerable.
From policy principle to procurement criterion
The most concrete sign that digital sovereignty is maturing as a topic is its inclusion in tender criteria and procurement policy. Dutch government bodies are increasingly referencing requirements around data location, audit rights and the origin of software in their tenders. The national government has designated sovereignty as one of the guiding principles within the Werkagenda Waardengedreven Digitaliseren framework, although the concrete implementation and enforcement are still being developed.
For private organisations the urgency is often less immediately apparent, but incidents such as outages at major hyperscalers and reports of access by foreign authorities have placed the subject on boardroom agendas. Insurers and regulators are also asking more frequent questions about the risk distribution of digital dependencies.
For the Dutch and European technology sector, the growing demand for sovereign alternatives creates opportunities for providers that can demonstrate they meet the legal, technical and organisational requirements set by large customers. At the same time, it calls for patience from founders and investors: the market for sovereign cloud infrastructure and security solutions is growing steadily, but sales cycles are long and competition from established American players remains intense. Policymakers can accelerate that growth by setting clear and enforceable requirements, enabling European providers to compete on equal terms.