Blog

Data sovereignty: reducing dependence on US big tech

Data sovereignty is high on every public organisation's agenda in 2026. The question is no longer whether you work with the cloud and AI, but where your data lands and who can access it under which law. In this article we explain what data sovereignty is, why dependence on US big tech is a real risk, and how public bodies can make deliberate, durable choices without getting in the way of innovation.

In short
  • Data sovereignty = knowing where your data sits, under which law, and who can access it.
  • EU servers ≠ EU law: a US provider falls under the CLOUD Act.
  • Copilot/ChatGPT/Claude are fine — with the right variant, agreements and data residency.
  • Avoid vendor lock-in: keep an exit strategy open.
  • Not about avoiding technology, but choosing deliberately — start with your most sensitive data.

What is data sovereignty, and why now?

Data sovereignty means keeping a grip on your own data: you know where it is stored, which law it falls under and who can access it. For government this is not a technical detail but a core value, because you process data belonging to citizens who have no choice about whether to deal with you.

The urgency has grown in recent years. More and more services run in the cloud, AI tools process sensitive data, and at the same time there is a growing awareness that many of those services are in the hands of a handful of US companies. Sovereignty is about the question: when it matters, do I stay in control, or am I at the mercy of someone else's terms and jurisdiction?

Where does your data actually land?

Most organisations are surprisingly unclear about where their data physically sits and which law applies to it. That is exactly the problem. A service may have servers in the EU, but if the parent company is American, it falls under US legislation such as the CLOUD Act. That law can give US authorities access to data, even when it is stored in Europe.

For ordinary business data that is a manageable risk. For the sensitive personal data government works with, it is a question you want answered up front: who can access it in the last resort, and can we explain that to our citizens and to the regulator?

Copilot, ChatGPT and Claude: powerful, but American

The rise of AI has made the question more urgent. Tools such as Copilot within the Microsoft environment, or ChatGPT and Claude, are powerful aids that genuinely save staff time. But each of them is a US service, and the moment you put sensitive data into them, that data leaves your own walls.

That does not mean you should avoid these tools. It means you must consciously choose which data you process in them, under which agreements, and whether there is a variant that stays within the EU. Many providers now offer enterprise or government versions with data residency in Europe and firmer guarantees than the consumer version. The difference between "we just use the free version" and "we use the EU variant with a data-processing agreement" is enormous.

The risk of vendor lock-in

Alongside jurisdiction, dependence plays a second role: vendor lock-in. If your entire work process, your data and your integrations are tied to a single supplier, then that supplier sets your price, your terms and your pace. If the policy or pricing changes, you are stuck.

Sovereignty therefore also means: make sure you can leave. Can you export your data in a usable format? Can you switch without bringing your whole organisation to a halt? An exit strategy sounds defensive, but it is precisely what protects your negotiating position and your freedom.

What sovereignty is not

Importantly, data sovereignty is not a call to avoid US technology or to build everything yourself. That would be unaffordable and would slow the very innovation the public sector badly needs. It is not about digital isolationism, but about deliberate choices.

The essence is control. You may absolutely use the best tools in the world, as long as you know where your sensitive data lands, record that in solid agreements, and keep a way out. Sovereignty is an attitude, not a ban.

How to make a sovereign choice

Start with a simple inventory: what data do we have, how sensitive is it, and where does it sit now? Classify your data, so you know which category deserves extra protection. For sensitive processing, arrange a clear data-processing agreement and, where possible, data residency within the EU.

Then look seriously at European or sovereign alternatives for the heaviest applications, and record an exit scenario for every important supplier. You do not have to change everything at once. Start with the most sensitive data and work outward from there. That is how you build, step by step, a landscape in which you hold the wheel.

How to take the first step

Data sovereignty is not a one-off project but a way of choosing that you carry into every new service and every AI application from now on. It is precisely at that intersection of technology, information security and public frameworks that we work as DWDA.

Want to know where your organisation stands? Take our free maturity scan and receive an immediate report with concrete next steps. Prefer to spar about a specific decision, for instance around an AI tool or a cloud supplier? With our starter vouchers we deliver a first analysis for a fixed price, without long-term commitment. Feel free to get in touch and we will look together at where your biggest risks and opportunities lie.

Frequently asked questions

What is data sovereignty?

Data sovereignty is the degree to which you keep a grip on your own data: where it physically sits, which law it falls under and who has access. It is about control, not about avoiding technology.

Do EU servers fall under the US CLOUD Act?

Yes, they can. If a cloud service's parent company is American, the service can fall under the CLOUD Act — even if the data physically sits in Europe. US authorities can then in principle request access.

Can a government use ChatGPT or Copilot?

Yes, if done carefully. Deliberately choose which data you process, record it in a data-processing agreement, and where possible use an enterprise or government variant with data residency in the EU. The free consumer version is not suitable for sensitive data.

How do I avoid vendor lock-in?

Make sure you can leave: choose exportable, open data formats, record an exit scenario per supplier, and avoid tying your entire work process to one provider. An exit strategy protects your negotiating position and freedom.

Control over information security — together

Take the free scan or let us take a no-obligation look.

TdW
Tom de WaardFounder · Interim CMO & digital transformation partner

Founder of DWDA and interim CMO. For over thirty years — since 1993 — Tom has helped organisations from SME to multinational with digital strategy, marketing and transformation. As the face of an award-winning digital case at Nutricia (Danone) he won several public awards, including the Customer Data Award and the LOVIE Awards. As Marketing Director he built a distinctive sustainability positioning at FlexIT — from evidence to revenue model. In recent years he has focused strongly on the public sector: he helps (semi-)government organisations, such as Sabewa Zeeland, modernise and make use of today's systems and techniques — with information security and compliance as the fundamental starting points. Tom translates strategy into execution, with AI and governance as the common thread.

More about the team → Connect on LinkedIn