Digital sovereignty explained

Technology · 2026-06-20 · 7 min read

By Arjun Mehta, Engineering & product

Sovereignty is not a server location. It is the practical ability to keep operating when a supplier, or a government, changes its mind.

Digital sovereignty gets discussed as a data residency question, which is the least interesting part of it. Data can sit in a local region and still be governed by a foreign contract, a foreign legal order and an operations team that can revoke access on a Tuesday.

Three pressures drive the current interest: legal exposure when a supplier answers to another jurisdiction, concentration risk when a handful of providers underpin an entire economy, and the plain observation that outages and policy changes both arrive without warning.

In practice sovereignty looks unglamorous. Data in portable formats rather than proprietary ones. Infrastructure described as code so it can be rebuilt elsewhere. Encryption keys held by you. A written exit plan that somebody has actually rehearsed.

It costs real money. Portability means avoiding the managed service that would have saved a quarter of engineering time, and duplication means paying twice for capacity you hope never to use. That trade is legitimate, but it should be a decision rather than a slogan.

The reasonable middle for most organisations is to rank systems by how badly a forced migration would hurt, then buy portability only for the top of that list and enjoy the convenience everywhere else.

Tags: cloud, policy, infrastructure

Arjun Mehta — Arjun writes about web performance, developer tooling and applied AI for ESPYCRUX. He has spent the last decade building and maintaining production web apps, and most of his articles start from something that broke in one of them.