Data sovereignty is a hot potato for politicians these days with some countries seeing it as an opportunity to strengthen economic independence and invest in local infrastructure. Other commentators raise concerns about whether creating barriers to using non-European vendors will limit productivity and collaboration.
In all this heated debate, spare a thought for the head of IT at a local municipality or a central government department somewhere across Europe. That person has a day job focused on modernising ageing legacy IT systems while saving money and improving services delivered to citizens – all while navigating a minefield of legal regulation.
The obvious choice to help scale services, streamline business processes and enable greater agility is moving to the cloud. However, this brings the sovereignty question into sharp focus as understanding where cloud services store and process data is not necessarily straightforward. In fact, the answer is multi-layered as sovereignty touches on who processes the data, the infrastructure where it is stored and how it interacts with applications such as artificial intelligence (AI). Part of the answer, as we’ll see, starts with recognising that not all data is equal.
Data legislation
The position is nuanced, because across Europe there are a number of legal frameworks which affect the management and protection of data and critical infrastructure. They include Critical National Infrastructure (CNI) designation, NIS2 (Network and Information Systems), Digital Operational Resilience Act (DORA), Cloud and AI Development Act (CADA), GDPR, the EU AI act and the EU Data Act. Potentially, a number of these could affect decisions by that IT director on how best to manage data as they look to modernise their IT environment.
GDPR is well established as a regulatory framework for the management of data. DORA affects financial services, but it shows that the EU has a growing understanding of the role ICT third-parties play in managing IT systems and the need to limit reliance on a handful of global providers. The proposed CADA regulations reveal what a datacentre provider would need to do to achieve higher ‘Union assurance levels.’ It includes demonstrating “operational independence from third countries, strict EU ownership and control, and absolute transparency over the software supply chain.”
Planning for change
If you’re the head of that IT department in a central government department or a local municipality, how much time and resource do you have to devote to checking whether your service provider will comply with these criteria?
Add to this, the situation is fluid as proven by the chopping and changing of the US Government’s rules on access to Anthropic’s Mythos and Fable models. It feels like every public sector body is faced with an incredibly dynamic situation which requires careful preparation.
A lot of the planning boils down to discussions around data and requires every IT leader to ask questions about:
- Who can access data when it is stored in a data centre or in the cloud?
- Who has the right to operate or suspend a service as that provider may be subject to third-country laws?
- Who supports the application or service and what jurisdiction do they fall under?
- Who has the right to administer privileged access and disclose information?
- Could the application or service provider be subject to foreign judicial or law-enforcement demands?
These are crucial questions, but across Europe the picture is mixed in terms of how governments apply these rules to data sovereignty and protection. For example, reports suggest in the UK schools have the flexibility to use platforms like Google Workspace or Microsoft 365 as long as GDPR protections are in place. In Germany several states have banned or tightly restricted state-run schools from using US cloud providers. Swedish schools can use EU-based datacentres for school administration data, but student performance data cannot leave the country. In the Netherlands, schools have more flexibility as long as data is stored in the EU, but they must deploy custom EU-only data boundaries to limit US metadata access. While in Belgium school boards and regional education authorities can use EU-based datacentres as long as they operate within the EU GDPR framework.
Why a one size fits all approach doesn’t work
Ultimately, despite all the noise about sovereignty and protecting critical data, each public sector body must decide what is the right strategy for them. The reality is that budgets remain tight, so organisations must weigh up the relative merits of choosing a strictly local provider over a global alternative. Given the size and scale of global providers and the resources they can apply, public sector bodies must do a proper cost-benefit analysis of which provider will deliver the best product or service to meet that organisation’s legal, financial and operational needs. Sometimes knowing that the local council or central government department has the resources of a global tech player behind it to minimise cyber threats and speed up access to innovation, has its benefits, but this has to be evaluated dispassionately against budget and regulatory requirements.

However, if sovereignty is critical to a modernisation strategy, then the key question must be: what data must be kept safe according to local or European regulations? Frankly, not all data is equal, so it does not require the same treatment. This is good because it offers the IT director more flexibility to adopt a multi-layered approach based on which data must be stored locally and what can potentially be handed over to a technology provider subject to third-country legislation.
As a result, the IT leader will be able to balance the political, financial and operational pressures to use resources wisely while ensuring the organisation stays resilient in a changing world.
By Christoffer Crona, SVP Global Sales Public Sector, Unit4.
- Data & AI
- Digital Strategy
- Infrastructure & Cloud













































