What is digital sovereignty?
On February 6, 2025, US president Donald Trump ordered sanctions against Karim Khan, chief prosecutor at the International Criminal Court in The Hague, the court that prosecutes war crimes. The International Criminal Court was a customer of Microsoft, an American corporation. Microsoft complied with the order by blocking the prosecutor’s account. Khan and others lost access to their email, which disrupted the court’s operations for months.
A common definition of sovereignty is supreme authority within a territory. Digital sovereignty then, must be supreme authority within the digital landscape: the software and computer systems we use. If a foreign ruler can cause your digital infrastructure to stop working simply by publishing a document, then your authority is not supreme, and you are not digitally sovereign. There is nuance to this though. The world today is interconnected, supply chains are deep and global, and digital infrastructure is a cross-border collaborative effort. Sovereignty is not the same as complete independence. In this article we will explore what it means to be digitally sovereign and digitally autonomous.
Data residency is not sovereignty
Part of digital autonomy is the ability to decide who to share your data with. In digital systems, the only reliable way to protect data is through encryption. When data is encrypted, the physical location of the computers that store it, is irrelevant for privacy. Conversely, a promise that data is processed only by servers in a specific geographic location is not a privacy guarantee when foreign parties can assert authority over the software that handles the data.
If you want to make a third party responsible for storing your data at all, there are two ways to do so that preserve sovereignty. Either the third party must fall completely, unambiguously, under your authority. Privacy in this case is a legal requirement, but not guaranteed by construction. Hackers can still steal your data, for example. The safer alternative is to encrypt your data with a key not known to the third party. Note that the transparent encryption features that clouds offer do not satisfy this requirement, as the encryption key is known to the cloud provider. While it protects your data against physical theft, it does not shield it from access by foreign governments.
American clouds cannot provide European sovereignty
The software that makes the American hyperscaler clouds tick is global. Whether in the United States, Europe, or elsewhere on the planet, each of their data centers runs the same software. Uniformity is the power of the hyperscalers, and their economy of scale. But with this power comes a weakness: the corporation that controls the software is subject to US jurisdiction, and to the capriciousness of their ruler, who is increasingly meddling in matters of private businesses.
Because the US government has supreme authority over what happens in the hyperscalers’ data centers — even when they are built on European soil — a Europe whose infrastructure depends critically on American hyperscalers, is not digitally sovereign. No matter how many times the hyperscalers cram the word sovereign into their marketing copy, and no matter how many local subsidiaries they set up to give decisionmakers a convenient excuse to evade responsibility, the hyperscalers’ internal software remains governed by the United States. When that software starts to interfere with European institutions, society stops functioning. Never mind taking legal action against the local subsidiaries when the courts’ IT systems no longer work. The only way for Europe to become digitally sovereign, is to start reducing our dependence on US big tech.