Operational sovereignty is the ability to keep operating — accessing your data, running your systems, delivering your processes — regardless of decisions made by parties outside your control. It is not measured by where the server sits, but by who can interrupt, read or condition your processes. And it can genuinely be measured: with five tests, one per critical dependency.
01What is operational sovereignty?
Working definition, the one we use with clients: operational sovereignty is an organisation's ability to keep operating regardless of decisions made by parties it does not control. A vendor doubling the price or changing its terms of service. A non-EU jurisdiction ordering access to data. A sanction, an embargo, a political decision switching off a service. If any of these events stops one of your critical processes, that process is not sovereign — whatever the brochure says.
The distinction to hold on to is the one between data residency and sovereignty. Residency answers "where does the server sit"; sovereignty answers "who can compel the provider, who can read the data, what does it cost me to leave". The first is geography. The second is control. Nor is it the "digital sovereignty" of conference panels: it is an operational property that is either demonstrated with evidence — contracts, architectures, exit times — or does not exist.
02Why is "a datacenter in Europe" not enough?
Because jurisdiction follows the company, not the server. The US CLOUD Act (2018) made explicit that providers subject to US jurisdiction must preserve and produce data in their possession, custody or control regardless of where it is stored (US DoJ, CLOUD Act Resources; Congressional Research Service, R45173). A datacenter in Frankfurt operated by an American company answers to Washington before it answers to Brussels. As early as July 2019 the EDPB and EDPS, in the joint assessment requested by the European Parliament, found that this extraterritorial reach can place providers in a conflict of laws with the GDPR (EDPB-EDPS, joint response to the LIBE Committee, 2019).
For years the vendors' answer was "it has never happened, and we push back on requests". Then came the moment the question was asked under oath. On 10 June 2025, before the French Senate inquiry committee on public procurement and digital sovereignty, the director of public and legal affairs of Microsoft France was asked whether he could guarantee that French citizens' data would never be transmitted to US authorities without the agreement of the French authorities. The answer: I cannot guarantee it (ActuIA, French Senate hearing, June 2025). That is not a scandal: it is American law working as designed. The scandal is continuing to call "sovereign" what is not. We took the contractual mechanics apart piece by piece in the Cloud Act explained to a CFO.
03How dependent is Europe on non-EU cloud?
The numbers describe a structural dependency, not a footnote. According to Synergy Research Group, Amazon, Microsoft and Google together account for about 70% of the European cloud market, while European providers' share of their own market has fallen from 29% in 2017 to 15%, where it has sat flat since 2022 — with the leading local players, SAP and Deutsche Telekom, at 2% each. All this in a market worth €61 billion in 2024 and growing at double digits (Synergy Research Group, July 2025).
The point is not that the three hyperscalers are bad vendors: it is that a 70% dependency on three companies subject to the same non-EU jurisdiction is a single point of failure — technical, contractual and geopolitical. The European Commission itself has now put this in writing: the proposal for a Cloud and AI Development Act presented on 3 June 2026, the centrepiece of the tech sovereignty package, states that over-reliance on non-EU cloud providers "poses a significant risk to Europe's digital autonomy and resilience" and aims to triple the EU's datacenter capacity within 5-7 years (European Commission, CADA, June 2026). The proposal is at the start of the legislative procedure: it will bear fruit in years. Your exposure, however, exists today.
04How do you measure operational sovereignty? The five tests
Sovereignty is not an adjective for a tender document: it is a verifiable property. For every critical vendor — cloud, business SaaS, AI, email — apply five tests. Every answer must be documentable evidence, not an opinion.
- 1. Jurisdiction test. Which non-EU laws reach the vendor? Do not look at the registered office of the subsidiary signing the contract: look at the parent company and at who controls the data. If the corporate chain reaches a jurisdiction with extraterritorial obligations (Cloud Act, FISA 702), that law reaches your data.
- 2. Keys test. Who can technically read the data? Encryption at rest with keys held by the vendor means the vendor can read — and therefore hand over. Sovereign is only what is encrypted with keys you hold, or what runs on your own infrastructure.
- 3. Exit test. How much does it cost and how many days does it take to migrate — to another vendor or on-premises? Data exportable in open formats, rehearsed procedures, known costs. If you have never rehearsed the exit, you do not have an exit plan: you have a hope.
- 4. Continuity test. If tomorrow the vendor doubles the price, changes the terms or is blocked by a decision taken elsewhere: which processes stop, and for how long? The answer is a list of processes with timings, not a probability judgement.
- 5. Competence test. Can the process run without the vendor? People, documentation, rehearsed alternatives. The deepest dependency is not in the contract: it is in no longer knowing how to do without someone.
05What does the Data Act change (and what doesn't it)?
On the exit test, Europe has just shifted the balance towards the customer. The Data Act (Regulation EU 2023/2854), applicable since 12 September 2025, gives customers of data processing services — IaaS, PaaS, SaaS — the right to switch providers with a maximum notice period of two months and a 30-day transition period, and explicitly includes the right to move data and digital assets back to on-premises infrastructure (European Commission, Data Act; EUR-Lex, Reg. EU 2023/2854). On costs, two dates: since September 2025, switching charges must be limited to the costs actually incurred; from 12 January 2027 they are banned entirely.
What the Data Act does not do: it does not turn the right of exit into the capability to exit. The regulation covers "exportable data" — not the skills, not the architecture you have meanwhile built around the vendor's proprietary services, not the AI models trained inside a closed platform. And it does not touch the jurisdiction test: you can change hyperscaler in 30 days and remain under exactly the same extraterritorial law as before. The Data Act lowers the cost of the door. Walking through it — and choosing where it leads — remains an architecture job.
06Where to start, concretely
Not with a position paper: with a dependency map. One sheet with three columns — critical process, vendor, jurisdiction — and the five tests applied to every row. It is the same method we use for NIS2 and DORA: first the snapshot, then the decisions. That is where the real priorities come from: the processes that need on-premises (critical data, keys, AI on sensitive data — the case for AI without vendor lock-in), those where an EU-hosted vendor with your keys is enough, and those where lock-in is acceptable because the exit is rehearsed and cheap.
It is the principle our operational sovereignty page and the whole P3 product line are built on: sovereign software, on-premises or EU-hosted, lock-in-free by design. If you want to start from the snapshot — network, data, vendors, jurisdictions — the first step is a seven-day on-prem audit. To discuss your case, write to us.