A few years ago, digital sovereignty was largely viewed as a compliance conversation. If you stored data in the right geography, met the right regulatory requirements, and satisfied a handful of audit questions, you could generally move on.
That’s no longer the case.
Today, sovereignty has become a board-level discussion. Governments are rewriting policies. Regulators are increasing scrutiny. And business leaders are starting to recognize that sovereignty isn’t just about where data resides – it’s about how organizations continue operating when geopolitical, legal, or operational assumptions suddenly change.
In the first episode of our STRIVE series on digital sovereignty, I sat down with Max Mortillaro, co-founder and Chief Research Officer at Osmium Data Group. Together, we unpack what sovereignty actually means, why the conversation has accelerated so quickly, and where organizations are most likely to get it wrong.
Watch the full episode.
Key Takeaways
- Digital sovereignty is no longer just a compliance issue – it has become a resilience and business continuity concern.
- Data location is only one piece of the puzzle. Jurisdiction, operations, technology dependencies, and governance all matter.
- Many organizations focus on technical controls before understanding the business problem they’re trying to solve.
- Geopolitical uncertainty is accelerating sovereignty initiatives, particularly across Europe.
- There is no such thing as a perfectly sovereign environment. Every organization must make informed trade-offs between risk, cost, and operational requirements.
Why Data Location Isn’t the Whole Story
One of the most common misconceptions around digital sovereignty is that it begins and ends with geography. If data is stored in a local data center, the thinking goes, the sovereignty problem has been solved.
It’s an understandable assumption. After all, many of the early conversations around sovereignty focused heavily on data residency requirements and where information could legally be stored.
But as Max points out during our discussion, that’s only one dimension of a much larger challenge. Sovereignty isn’t simply about where a data center sits. It’s also about who operates it, which laws apply to it, who has access to it, and what dependencies exist behind the scenes.
A cloud service may be physically located within a specific country, but that doesn’t necessarily mean it’s insulated from legal, operational, or technological influence originating elsewhere.
That’s where the conversation becomes significantly more complex.
The Hidden Dependencies Most Organizations Overlook
When organizations first begin exploring sovereignty, they often approach it as a technology project. They evaluate hosting locations. They assess replication strategies. They examine where workloads should run.
Those conversations are important, but they can also create a false sense of confidence.
As Max explains, modern technology environments are built on layers of dependencies that aren’t always visible. A service may appear local on the surface but it may be relying on infrastructure, management systems, telemetry services, or operational controls that exist elsewhere.
That’s why sovereignty isn’t simply a question of location. It’s a question of influence.
Who ultimately controls the service? Which legal jurisdiction applies when disputes arise? What happens if geopolitical tensions introduce new restrictions, regulations, or limitations on access?
These aren’t hypothetical questions anymore. They’re becoming part of real-world risk assessments.
Sneak Peek: Sovereignty Is More Than a Technical Problem
In this segment from the conversation, Max explains why organizations often start sovereignty discussions in the wrong place – and why understanding the legal, operational, and business objectives must come before any technology decisions.
Why Europe Is Driving the Conversation
One of the most interesting parts of our discussion focuses on why sovereignty has become such a dominant topic across Europe.
The answer isn’t just regulation; it’s dependency.
European organizations have become increasingly aware that many of the technologies they rely on every day are owned, operated, or governed outside of their direct control. For years, that reality was largely accepted as part of the global technology ecosystem.
Today, that assumption is being reevaluated.
Geopolitical tensions, evolving regulations, and increasing concern around strategic autonomy have pushed sovereignty higher on the priority list for governments and enterprises alike. What was once considered an edge case has become a mainstream business concern.
The result is a growing recognition that resilience isn’t only about recovering from technical failures. It’s also about understanding and managing external dependencies before they become business disruptions.
Sovereignty and Resilience Are the Same Conversation
One of the themes that you’ll see repeatedly surfacing throughout the discussion is how closely sovereignty and resilience are connected.
At first glance, they may seem like separate disciplines. One focuses on governance, regulation, and control. The other focuses on recovery, continuity, and operational readiness.
In practice, they’re deeply intertwined.
If a business cannot access critical systems because of a geopolitical event, regulatory restriction, or third-party dependency, the outcome isn’t very different from other disruptions organizations spend years preparing for.
The business still needs to operate. Customers still need to be served. Recovery still needs to happen.
That’s why I increasingly view sovereignty through the same lens as cyber resilience. Both are fundamentally about reducing exposure to events that could disrupt operations and preparing the organization to continue functioning when those events occur.
Start With the Business Problem
Perhaps the most practical advice Max shares is also the simplest.
Before evaluating sovereign cloud offerings, before engaging vendors, and before debating technical architectures, organizations should first understand what problem they’re trying to solve.
That means understanding:
- Which business processes are most critical.
- Which data assets matter most.
- Which regulatory requirements apply.
- Which risks are truly being mitigated.
Only after those questions are answered does it make sense to evaluate technology options.
Too often, organizations start with solutions and work backward toward the problem. Sovereignty requires the opposite approach. The strategy should come first.
The architecture follows.
Why There Is No Perfect Answer
One of the realities leaders need to accept is that there is no such thing as a perfectly sovereign environment.
Every organization operates within a network of dependencies. Every technology choice introduces trade-offs. Every risk decision involves balancing operational requirements, compliance obligations, cost considerations, and business outcomes.
The goal isn’t perfection. The goal is understanding those trade-offs well enough to make informed decisions.
Organizations that approach sovereignty as a binary yes-or-no question often find themselves frustrated. Organizations that approach it as a risk-management exercise tend to make better progress.
Why This Conversation Matters
Digital sovereignty is moving quickly from a niche compliance topic to a strategic business issue.
Boards are asking questions. Regulators are increasing scrutiny. Customers are becoming more aware of where their data lives and who controls it.
At the same time, geopolitical uncertainty continues to reshape how organizations think about risk.
That doesn’t mean every company needs a radical sovereignty transformation tomorrow.
But it does mean that the organizations that start building a clear strategy today will be in a much stronger position than those who wait until the conversation becomes unavoidable.
Sovereignty isn’t a technology decision masquerading as a business problem. It’s a business problem that requires legal, operational, and technical decisions working together.
Watch the Full Episode
In this installment, Max and I explore:
- What digital sovereignty actually means.
- Why data location alone isn’t enough.
- The legal and operational dimensions organizations often overlook.
- How geopolitical developments are influencing sovereignty strategies.
- Why sovereignty and resilience are becoming inseparable.
FAQs
Q: What is digital sovereignty?
A: Digital sovereignty refers to an organization’s ability to maintain control over its data, technology, operations, and governance within specific legal and jurisdictional boundaries.
Q: Is digital sovereignty the same as data residency?
A: No. Data residency is one component of sovereignty, but sovereignty also includes legal jurisdiction, operational control, technology dependencies, and governance.
Q: Why has digital sovereignty become more important recently?
A: Growing geopolitical uncertainty, evolving regulations, and increasing concern about technology dependencies have accelerated interest in sovereignty initiatives.
Q: What is the biggest mistake organizations make?
A: Treating sovereignty as a purely technical challenge instead of a broader business risk and resilience issue.
Q: How does sovereignty relate to cyber resilience?
A: Both disciplines focus on maintaining operational continuity in the face of disruptions, whether those disruptions are technical, legal, geopolitical, or regulatory.
Q: Where should organizations begin?
A: Start by understanding the business outcomes you’re trying to protect, the risks you’re trying to mitigate, and the data and processes that are most critical to your operations.
Alex Zinin is VP/GM of Managed Service Providers at Commvault.