The term “digital sovereignty” has become a broad heading for discussions concerning cloud infrastructure, artificial intelligence, chips, and platform regulation. European governments use it to reduce dependence on foreign infrastructure and companies, while countries in other regions see it as a means of strengthening control over data and communications and building local technological capabilities. However, the EFF believes that the term remains ambiguous and that its value should not be reduced to replacing major technology companies with others or creating new “walled gardens.”
In its simplest definitions, digital sovereignty means having the ability to control one’s digital destiny. What this means varies according to the party concerned: it may involve an individual’s right to know where their data is stored and who has the right to access it, or a state’s ability to independently and securely develop, provide, use, adapt, and control infrastructure and technologies. The source notes that a joint French-German paper defined the concept as the ability to develop digital technologies, including hardware, and to provide, use, adapt, and control them in an independent, self-determined, and secure manner.
Why does this discussion matter?
The importance of digital sovereignty stems from the fact that essential infrastructure may be owned by companies operating under another jurisdiction, placing data and services under the influence of foreign laws and political priorities. These concerns increase with wars, sanctions, and the fragmentation of the internet—factors that have shown that the physical infrastructure underpinning digital services is not always neutral or protected.
In Europe, the discussion focuses on reducing dependence on foreign cloud-computing services, chips, and platforms, particularly American ones. Germany has begun funding this effort through the Sovereign Tech Agency, which invests globally in open-source software components that support competitiveness and innovation in Germany and Europe. European organizations are also pushing for alternative platform ownership models and clearer definitions of technology companies’ objectives, while EDRi believes that European digital sovereignty begins with open source.
Outside Europe, the concept takes different forms. Discussions among Indigenous peoples focus on their right to manage their digital systems, while debate in Southeast Asia is linked to the growth of “sovereign cloud” services and the jurisdiction under which data falls. In Latin America, public digital infrastructure stands out, while African countries speak of moving from consuming technology to designing infrastructure and data systems. In the Middle East and North Africa, concerns are emerging about dependence on American technology companies because of their roles in conflicts and surveillance, including matters relating to Palestinian voices.
The risk: state sovereignty at the expense of the user
Reducing dependence on major companies does not automatically increase users’ rights. The source warns that some governments may use digital sovereignty to isolate their citizens or fragment access to the internet, as has occurred in Iran, Russia, and elsewhere. Giving the state greater influence over citizens’ data, communications, and locations may produce troubling outcomes, particularly in countries that impose high levels of surveillance or operate unaccountable monitoring programs.
For this reason, some voices—including an Iranian professor whom the source identifies as Azadeh Akbari—criticize the current wave that presents digital sovereignty as a solution for ending dependence on American and Chinese technology, considering that it may carry a European bias. The Jordan-based researcher Reem Almasri likewise believes that digital sovereignty should mean the ability of people and communities to choose, control, and use technology in ways that serve their needs and values, rather than merely expanding the power of governments.
What is changing in practice?
According to the EFF’s vision, digital sovereignty should be based on user independence, not on shifting the center of power from one group of companies to a group of governments or other companies. This includes supporting free and open-source tools and projects, building services according to the principles of interoperability and data portability, and providing permanent teams of developers, user-experience designers, and community managers within government entities.
- Give users clearer control over their data, including knowing where it is stored and who is legally entitled to access it.
- Enable data to be easily transferred between services and platforms in structured, machine-readable formats, reducing users’ lock-in to a single platform.
- Reject manipulative designs, coercive terms, and default settings that restrict user choice.
- Support full end-to-end encryption and strong encryption for stored data, and refrain from imposing backdoors or blanket mandates for “lawful access.”
- Reduce data collection and processing to what is necessary, and obtain explicit consent explaining what is collected, where it is stored, and who can access it.
certi.news’s reading
The real change here is not the launch of a single technology or standard, but a redefinition of the objective of digital policies. Rather than viewing sovereignty simply as local ownership of data centers or the development of national alternatives to platforms, the reading presented here proposes measuring it by the user’s ability to understand, transfer, and protect their data and leave a service without losing their digital history.
This vision leaves open questions: How can states build local capabilities without turning them into surveillance tools? How can open-source projects secure long-term funding and maintenance? And what mechanisms can prevent local companies from reproducing the same lock-in criticized in global companies? The source does not provide detailed implementation answers to these questions, but it identifies a fundamental constraint: digital sovereignty that places the state or company before the user may reproduce dependence rather than end it.