Digital sovereignty

The internet has become a digital occupation zone.

Martin Andree, Founder of AMP Digital Ventures, Book author and Speaker at the iab Conference Day 2026 (Podcast Internetwold Austria). BDZV-Interview mit dem Medienwissenschaftler Martin Andree
This applies not only to the internet in the sense of (social) media, but also to the IT software industry as a whole.
  • European companies and authorities are often dependent on a few US providers.
  • Changes to terms and conditions or licensing models or measures resulting from political influence can have significant economic consequences.
  • A short-term change is often hardly possible.

The examples listed below can be assigned to three categories:

  • Political influence: ICC/Microsoft, CLOUD Act.
  • Economic dependency: VMware/Broadcom, Oracle, SAP, or other proprietary platforms with high switching costs.
  • Technological dependency: Cloud platforms (Azure, AWS, Google Cloud), office software, and collaboration services.

Click on a heading to read the details and conclusions.

What does digital sovereignty mean in practice for an Austrian or European company?

Sovereignty means being able to switch at any time.

Sovereignty is not about using a particular technology, but about being able to make autonomous decisions and utilize alternatives.

Digital sovereignty means being able to switch at any time – because data is portable, standards remain open, and decisions are not forced by technical dependencies.

  • Sovereignty means freedom of choice. Those who can switch providers, software, or platforms at any time are not permanently dependent on a single solution.
  • Switching requires open standards. Data must be available in open, portable formats, interfaces must be accessible, and systems should be able to communicate with each other.
  • Your own data remains the key. Digital sovereignty means retaining control over where data is stored, who can access it, and how it is used.
  • Recognize and avoid dependencies. A convenient system can become a dependency in the long run if switching becomes too expensive, technically impossible, or organizationally too difficult.
  • Sovereignty is also a question of the distribution of power. If users, companies, or states have no realistic alternative to a provider, they lose their room for maneuver.
  • A good digital system binds users not through captivity, but through quality. People stay because the service is compelling, not because switching is made practically impossible.
Sovereignty requires a mix and does not mean isolation.

Digital sovereignty is often mistakenly equated with independence in the sense of “doing everything yourself” or isolation.

Digital sovereignty does not mean isolation, but the ability to act openly and networked – with a balanced mix of your own skills, trustworthy partners and interchangeable technologies.

  • Sovereignty arises from diversity, not isolation. A sovereign system utilizes different providers, technologies, and partners to remain flexible and adaptable.
  • A mix of solutions creates resilience. Those who are not dependent on a single technology or provider can respond better to changes, failures, or new requirements.
  • Openness is an integral part of sovereignty. Exchange, cooperation, and international standards are necessary for digital systems to remain efficient and innovative.
  • It’s not about developing everything in-house. Sovereignty means consciously deciding what you need to control yourself and where collaboration makes sense.
  • Dependencies can be managed. Complete independence is hardly realistic in a networked world. The crucial factor is understanding critical dependencies and having alternatives.
  • Sovereignty requires connectivity. A digital system that functions only in isolation loses value. True sovereignty lies in being able to interact with others without losing control over one’s own interests.
Sovereignty is a purchasing decision

Digital sovereignty doesn’t begin in operations, but rather with procurement. Every purchasing decision influences how freely an organization can operate tomorrow. Those who prioritize open standards, data portability, and fair switching options invest in long-term flexibility.

  • Every procurement decision shapes future options. Whoever purchases a solution today also determines how easy it will be to switch tomorrow.
  • Criteria such as openness, data sovereignty, and interoperability must be part of the selection process. It’s not just price, functionality, and ease of use that matter, but also long-term independence.
  • Lock-in effects often arise from purchasing decisions. Proprietary formats, closed interfaces, or data that is difficult to transfer can make switching difficult later on.
  • Sovereignty is either bought along with the product or bought away. A seemingly inexpensive solution can become costly in the long run if it creates dependencies.
  • Strategic procurement creates choices. Those who prioritize open standards, portability, and transparent contract terms early on maintain flexibility.
  • Sovereignty doesn’t mean always choosing the supposedly most independent solution. The crucial factor is to consciously weigh the options: Which dependencies are acceptable? Where do we need control? Where can we purchase with confidence?

This is how I can help you

I will guide you from the initial analysis and strategic decision-making to the implementation of the projects to reach digital sovereignity.

My plan includes the following steps: Click on each step for more details.

1. Define vision, goals and requirements

Define vision, goals and requirements

  • What does “digital sovereignty” mean specifically for the organization?
  • Which data, applications, infrastructures, and processes require particular protection?
  • Which dependencies should be reduced?
  • What requirements exist regarding data protection, security, availability, and location?
2. Inventory of the current system landscape.

Inventory of the current system landscape.

  • Applications and IT infrastructure
  • Cloud/on-premises deployment
  • Data and data flows
  • Suppliers and service providers
  • Technologies and standards used
  • Contracts, licenses, and terms
  • Interfaces and dependencies
3. Analyze dependencies and lock-in risks.

Analyze dependencies and lock-in risks.

  • Vendor dependencies
  • Proprietary data formats
  • Proprietary interfaces/APIs
  • Lack of alternative providers
  • Cloud/hyperscaler dependencies
  • Knowledge dependencies
  • Switching or migration effort
4. Classify and prioritize risks

Classify and prioritize risks

  • Criticality of systems and data
  • Failure risks or operational risks
  • Security risks
  • Data protection risks
  • Geopolitical and legal risks
  • Supplier and supply chain risks
  • Lock-in risks
  • Dependence on specific technologies or individuals
5. Assess the degree of sovereignty

Assess the degree of sovereignty

  • How dependent are we?
  • How critical is this dependency?
  • How well can we reduce it?

This allows us to create a kind of sovereignty heatmap.

6. Develop target architecture and target vision

Develop target architecture and target vision

  • Which technologies and platforms should be used in the future?
  • Where is cloud computing the right approach, and where is on-premises the better option?
  • Which open standards should be used?
  • Which data needs to be portable?
  • Which interfaces need to be open or standardized?
  • Which systems should be consolidated or replaced?
7. Develop strategy and courses of action

Develop strategy and courses of action

  • Continue operating your existing solution
  • Switching providers
  • Open-source solution
  • European/German/Austrian alternative
  • In-house operation
  • Multi-cloud
  • Hybrid cloud
  • Building your own expertise

Digital sovereignty does not automatically mean “open source” or “on-premises”. What matters is how dependent one is and how well one can maintain one’s ability to act..

8. Evaluate cost-effectiveness and effort

Evaluate cost-effectiveness and effort

  • Investment costs
  • Operating costs
  • Migration costs
  • Personnel costs
  • Training requirements
  • Switching costs
  • Long-term total cost of ownership
  • Cost-benefit ratio to achieved sovereignty gains
9. Supplier/provider selection

Supplier/provider selection

Besides price and functionality, I would explicitly evaluate:

  • Exit Strategy
  • Data Portability
  • Open Standards
  • Interoperability
  • Contract Terms
  • Subcontractors
  • Data Processing Location
  • Legal Access Rights
  • Provider’s Financial Stability
  • Support and Expertise
  • Switching Options to Other Providers
10. Securing contracts and exit strategies

Securing contracts and exit strategies

This point is often underestimated when it comes to digital sovereignty.

For critical systems, the following should be clarified before procurement:

  • Could we easily switch providers?
  • How do we exit the solution?
  • In what format will we receive our data back?
  • Which data will be deleted and when?
  • How long does a migration take?
  • What are the costs associated with exiting?
  • What support must the provider offer?
11. Create a roadmap and prioritize

Create a roadmap and prioritize

Don’t tackle everything at the same time.

  • Priority 1: Critical systems with high dependency
  • Priority 2: High lock-in, medium criticality systems
  • Priority 3: Long-term optimization
12. Implement projects and carry out migration

Implement projects and carry out migration

  • Pilot project
  • Proof of concept
  • Migration
  • Testing
  • Operational handover
  • Documentation
  • Training
13. Establish governance and responsibilities

Establish governance and responsibilities

  • Who is responsible for digital sovereignty?
  • Who evaluates new technologies?
  • Who approves new providers/cloud services?
  • What architectural principles apply?
  • What minimum requirements must procurements meet?
14. Continuous monitoring and regular reassessment

Continuous monitoring and regular reassessment

Digital sovereignty is not a one-off project. Providers, technologies, laws, and geopolitical frameworks are constantly changing.

Therefore, check regularly:

  • Has our dependency changed?
  • Have new lock-ins emerged?
  • Are there better alternatives?
  • Are our exit strategies still realistic?
  • Have any contracts or providers changed?