Identify Risks, Reduce Dependencies
IT Sovereignty in Practice
06.08.2025
Today, digital infrastructures are an indispensable foundation for economic activity. At the same time, requirements regarding data protection, availability, and legal safeguards are increasing. With the current discussions surrounding the CLOUD Act, the impact of international sanctions, and the debate over training data for AI systems, one question has come to the forefront:
How can companies ensure their technological autonomy and independence in the long term?
IT sovereignty—defined as the ability to exercise full control over data, systems, and technological decisions in all respects—is becoming a strategic corporate goal.
In this article, we discuss which specific technical and organizational measures help companies regain and sustainably secure freedom of decision-making and control over critical systems and data. To this end, we examine the concept of IT sovereignty through the lens of our practical consulting experience—always in relation to real-world project requirements. Our focus is not on a universal definition or political stance, but on practical questions: What challenges related to IT sovereignty are emerging in today’s IT projects, and what approaches help companies weigh the associated risks?
Why IT Sovereignty Is Becoming Increasingly Critical for Businesses
Digital dependencies can quickly become a business-critical vulnerability—for a wide variety of reasons. According to a study by BARC [1], companies cite, in particular, regulatory requirements (69%), political developments in the U.S. (46%), cybersecurity incidents (42%), and general risks associated with reliance on public cloud services (40%) as key drivers of this issue.
This sentiment stems from a variety of developments.
On the regulatory front, legal tensions between European regulations such as the GDPR and international laws such as the U.S. CLOUD Act—which also allows U.S. authorities to access data outside the U.S.—play the most prominent role. For our customers in the DACH region, this creates considerable uncertainty, both from a legal perspective—keyword: legal certainty—and strategically with regard to their own IT sovereignty.
This growing uncertainty is exacerbated by specific incidents in which access to cloud services for individual users was blocked by order of the authorities. Particularly sensational in the spring of 2025 was the case of the Chief Prosecutor of the International Criminal Court: he used the email services of a major American cloud provider, which were temporarily blocked due to U.S. sanctions. This action was interpreted worldwide as a warning sign of a lack of digital sovereignty [2,3]
Earlier incidents also demonstrate how strongly political decisions can influence digital services: For example, a globally used code-sharing platform and a widely used communication and collaboration tool restricted access for users in countries such as Iran, Syria, and Cuba—in some cases without warning and with immediate consequences for ongoing projects [4,5]
Another driver of the IT sovereignty debate is the growing importance of data as an economic asset: training data for AI applications, research data, or technical operational data are not only sensitive but often also critical to business operations. Those who lose control over this data risk more than just a data breach—they may lose the ability to drive their own innovation.
Changes in licensing models or software pricing can also have significant implications for companies and present both economic and legislative challenges. IT sovereignty, in the form of IT system portability, makes it possible to respond flexibly to such changes—for example, by switching software providers in the event of unfavorable developments, rather than being at the mercy of a single provider.
These examples illustrate that technological dependencies often only come to light in exceptional cases but develop gradually over a long period of time—for example, through contractual obligations, proprietary standards, or inflexible licensing models. In many cases, long-term ties to specific providers lead to what is known as vendor lock-in—that is, a dependency that makes switching to other solutions difficult or economically unattractive. This is where IT sovereignty comes into play: It establishes the technical and contractual conditions necessary to consciously avoid such lock-in situations.
What IT Sovereignty Means for Different Stakeholders
When implementing IT sovereignty, different interests and perspectives come into play—which not only complicates the selection of suitable solutions but also makes communication about them more difficult. That is why it is important to understand the objectives that the various stakeholders are pursuing:
- For companies, sovereignty primarily means control over their data, legal certainty, and predictable operating models. It is crucial for them to be able to reduce digital dependencies and meet regulatory requirements.
- Cloud providers often use the term as a differentiator in the competitive cloud market. “Sovereign cloud” offerings promise greater control and data protection to retain customers—but whether these actually meet the specific needs of individual companies must be assessed on a case-by-case basis.
- Policy makers, on the other hand, think in broader terms: They view IT sovereignty as a strategic goal for strengthening economic resilience and digital self-determination at the national or European level.
These differing perspectives mean that “sovereignty” is interpreted differently depending on the context.
Challenges for IT Managers: Identifying Dependencies Across Three Areas of Action
From a corporate perspective, the discussion surrounding IT sovereignty can be broken down into three key areas of action.
Data confidentiality: Any storage of data entails potential risks from unauthorized access. This immediately gives rise to fundamental security requirements—regardless of where the data is stored. In the cloud, however, additional dimensions come into play: First, there is the possibility of government access, as regulated for U.S. hyperscalers under the CLOUD Acts or FISA. Second, under the Shared Responsibility Model, organizations are generally dependent on the cloud provider faithfully fulfilling its obligations regarding security and confidentiality.
Service Availability: The provision of digital services often depends on individual providers. If political measures, trade conflicts, changes to the licensing model, or even critical alterations to the service’s functionality as part of an update occur, key processes in the value chain can suddenly and acutely be put at risk. This risk affects not only the infrastructure but also services at the application level. An example: Following the start of Russia’s war of aggression against Ukraine, the three major hyperscalers announced in unison that they would no longer offer new products or services in Russia—a move that was interpreted as a clear signal of geopolitically driven restrictions on digital services [6].
Legal certainty: Legal requirements are constantly changing—at the European level, for example, through the GDPR, the Data Act, or DORA; at the national level, through laws such as the IT Security Act 2.0. The latter requires operators of critical infrastructure, among other things, to use intrusion detection systems and to provide evidence to the BSI [7]. For companies, this means that IT systems must not only comply with the current legal framework but also be flexibly adaptable to future changes, such as reporting requirements, control mechanisms, or security standards.
IT sovereignty forms the structural foundation for these three areas of action. It creates the flexibility to not only manage regulatory and technological change but also to proactively integrate it—into IT architecture decisions, software strategies, and the selection of external service providers.
IT sovereignty is not an all-or-nothing proposition
In public discourse, IT sovereignty is often equated with complete technological independence. In the reality of business operations, however, the issue is more nuanced: Which dependencies are tolerable, which are critical—and which can be reduced at a reasonable cost?
Not every technological dependency is a disadvantage in and of itself—on the contrary: For example, the strategic use of cloud services from large hyperscalers can, of course, also bring companies significant benefits. These solutions are often technologically mature, highly scalable, and enable the rapid implementation of innovative ideas. They provide access to cutting-edge technologies such as AI, data analytics, or global infrastructure without requiring companies to build and operate them themselves. In this context, the immediate business benefits can outweigh the potential risks of dependency—especially when this dependency is consciously accepted and strategically managed. In this context, IT sovereignty does not necessarily mean complete self-reliance, but rather the ability to make informed and autonomous technological decisions—even if this involves the use of external services.
The key is to consciously manage technological dependencies—not to avoid them across the board. Those who manage data with autonomy and remain independent in their technological decisions lay the foundation for innovation, adaptability, and sustainable digital value creation.
In this way, data is not only protected but also made purposefully usable—for example, for AI-powered business models, personalized services, or integration into digital ecosystems. This gives companies the freedom to independently shape their digital strategy—and to adapt flexibly to changing market conditions.
Those who strategically manage data, processes, and systems—while carefully weighing where a technology partnership brings real added value and where it leads to critical dependence—secure clear advantages: faster development cycles, greater adaptability, stronger customer loyalty, and more independence in value creation. IT sovereignty thus becomes a driver of innovation and differentiation—far beyond mere security concerns.
Architectural Decisions: The Technical Lever to Autonomy
The foundation for digital independence lies in architectural decisions. Even during the planning phase of a solution—whether for data processing, user management, or system integration—it is determined to what extent a company will depend on external components.
Technical sovereignty arises when companies retain control over key components: data storage, the operating environment, and software development. This does not necessarily mean operating everything in-house. What matters is what options are available when conditions change.
These include, on the one hand, the ability to switch providers without requiring fundamental software customization or data format changes during migration (e.g., through the use of standardized interfaces and portable technologies) and, on the other hand, clear contractual and technical provisions governing operational and data responsibility. These principles not only enable autonomy but also improve resilience against external disruptions.
Implementing a customized, sovereign architecture presents several challenges. Companies must clarify numerous questions in advance: Which data and systems are actually business-critical? Where do dependencies already exist today? What regulatory requirements apply in the respective business area, and what ones are expected in the future? Do proprietary solutions offer significant added value that justifies entering into dependencies in specific cases?
Only after conducting this analysis can a decision be made regarding which architecture is sustainable in the long term and strategically sound.
Three Key Questions for Greater Transparency
Whether a solution offers IT sovereignty can be assessed based on three key questions—these help systematically analyze existing dependencies and identify areas for action and scope for maneuver:
- Data Control:
Who has control over business-critical data and can actively manage its use, storage, and disclosure? Auditability is also crucial here—that is, the extent to which access can be controlled and tracked by the company. - Operational Responsibility:
Who operates the underlying infrastructure, and under what legal framework? This question concerns not only technical responsibilities but also legal control by third parties. - Software control:
Who determines how the software in use will evolve, and who decides on licenses, costs, updates, interfaces, or the discontinuation of features? A lack of control can lead to functional or security-related limitations in the long term.
These key questions lay the foundation for sound decisions at the technical, contractual, and organizational levels and clarify where control lies within the company—and where it does not.
Options and How to Weigh Them: A Comparison of Three Infrastructure Strategies
IT sovereignty can be implemented in various ways—depending on the industry, risk tolerance, and technical complexity. For our project business, we see three approaches to implementing IT infrastructures that meet heightened IT sovereignty requirements:
- In-house infrastructure (on-premises):
Maximum control over data and systems. Requires significant investment in infrastructure and internal expertise. Particularly suitable for security-critical areas or sensitive data sets. - European cloud providers:
Easy compliance with European data protection standards and legal certainty (e.g., IONOS or STACKIT). Often offer greater transparency but frequently have less functionality than U.S. hyperscalers. - Sovereign cloud offerings from international hyperscalers:
Technically isolated environments (e.g., Microsoft Sovereign Cloud or AWS European Sovereign Cloud). Improved compliance thanks to the broad service portfolio of U.S. hyperscalers. Legal risks, however, remain: Since U.S. corporations continue to be subject to U.S. law, access to the data may still be granted in the context of criminal investigations or intelligence activities
In many cases, a hybrid solution makes sense—for example, with critical systems hosted on European infrastructure and complementary cloud services from U.S. hyperscalers for scalable processing or AI-powered analytics.
Software design also has a significant impact on IT sovereignty
A well-thought-out software design that takes into account aspects such as data localization, encryption, modularity, and interoperability can reduce dependence on external providers and thereby increase control over critical data and processes. The use of open-source software can help increase transparency and flexibility, as it enables companies to review, customize, and further develop the source code without being dependent on proprietary solutions. By implementing open standards and avoiding vendor lock-in situations, companies can strengthen their flexibility and independence. When a company designs its software to be flexible, transparent, and independent, it can more easily ensure compliance with all relevant regulations and laws. This reduces the risk of compliance violations and strengthens the company’s autonomy regarding its IT infrastructure and data management.
Innovation-driven companies, in particular, can benefit from a software design that enables data portability, openness, and interoperability—because this is the only way they can flexibly integrate new technologies, develop their own digital services, or scale data-driven business models. Here, it is particularly important to carefully assess which IT dependencies to embrace in order to accelerate the company’s own pace of innovation: Those who rely on closed platforms may run the risk of limiting their ability to innovate in the medium term and of having to adapt to market dynamics rather than helping to shape them. On the other hand, maintaining competitive open systems can also involve a disproportionate amount of effort. The most prominent example of this today is undoubtedly the commercial offering of powerful large language models, which—depending on the application—cannot really be replaced by an open alternative.
IT sovereignty is a strategic decision
For companies, IT sovereignty does not mean making a radical break with existing structures. Rather, it involves the structured evolution of the organization and the IT systems it uses. Companies are not faced with the question of “cloud or no cloud,” but rather with the task of structuring control over their data and systems in such a way that they can operate flexibly, in compliance with regulations, and cost-effectively over the long term. Although the initial architectural decision plays a pivotal role in IT sovereignty, the implementation of an IT sovereignty strategy is not a one-time project but an ongoing process of shaping the organization. Organizations that continually address their dependencies and define their own courses of action lay the foundation for technological decisions that remain viable even under changing regulatory, political, or economic conditions. They not only strengthen their resilience—they also lay the groundwork for future projects, for digital independence, and for the ability to actively shape their own role in the market. IT sovereignty is thus also an expression of entrepreneurial autonomy: the freedom to decide how to handle data, technology, and innovation—rather than merely having to react.
Only those who develop a solid IT sovereignty strategy and regularly review it can make informed decisions regarding their digital infrastructure and IT sovereignty as part of their entrepreneurial freedom.
We’ll explore how the principles of IT sovereignty specifically impact data analytics architectures in our follow-up article, “Digital Sovereignty for AI and Analytics Platforms—From Principles to Concrete Solutions.”
Sources:
[1] BARC (Accessed July 8, 2025): Securing Data Sovereignty—Recommendations for Action for Companies.
[2] Heise (2025): International Criminal Court: Microsoft’s Email Block as a Wake-up Call for Digital Sovereignty.
[3] Golem (2025): Microsoft Blocks Email Account—U.S. Sanctions Hinder the Work of the ICC.
[4] The Verge (July 29, 2019): GitHub restricts developers in Iran, Syria, and other sanctioned nations.
[5] BBC (December 21, 2018): GitHub code-sharing site hit by takedown over anti-censorship tool.
[6] TechCrunch (March 10, 2022): Amazon, Microsoft, and Google suspend cloud sales in Russia.
[7] BSI (Retrieved July 10, 2025): IT Security Act 2.0 – Act to Increase the Security of Information Technology Systems.


