Digital sovereignty for smaller companies — more important than you think today.
In February 2025 it became public that Microsoft had suspended the email account of an ICC official — because US law required it. That episode made a question real for the German IT advisory community that we had until then treated as theoretical.
On 6 February 2025, US President Donald Trump signed Executive Order 14203. It imposed sanctions on the International Criminal Court in The Hague and its staff — in response to the arrest warrants the court had issued in November 2024 against the Israeli prime minister Benjamin Netanyahu and his then defence minister Yoav Gallant over alleged war crimes in the Gaza Strip.
Three months later, in May 2025, Microsoft suspended the email account of Karim Khan, the ICC’s British chief prosecutor. Khan had to move to the Swiss provider Proton. His British bank accounts were frozen as well. Microsoft later acknowledged the suspension — while stressing that services to the ICC as an institution had not been discontinued. Only the account of the sanctioned individual, Khan.
The legal position compels Microsoft. Executive Order 14203 prohibits any US person and any US company from supporting sanctioned individuals financially, materially or technologically — on pain of fines or imprisonment. Microsoft, as a US corporation, simply had no choice. It does not matter where the server stands, it does not matter whether the account runs in Microsoft’s European cloud or in the United States: when a US sanction applies, Microsoft suspends. Otherwise Microsoft commits an offence.
That episode set off a wave in the German IT advisory community that has not yet subsided. Suddenly a question was real that we had previously treated as theoretical: what happens when a US provider we depend on daily is compelled by US law to discontinue services — to us, to a client, or to an entire sector? The answer is: exactly what happened in May 2025. And it can hit anyone sitting on a US cloud.
I believe the answer to that question will shape the next five years of IT in German smaller companies. And I believe many people running those companies have not yet asked it — because the subject has so far been discussed in an abstract political layer, not in the concrete layer of their own tools.
What digital sovereignty concretely means
Let me clear something up, because the term is used inconsistently in the debate.
Digital sovereignty is the ability to decide about your own digital tools, data and processes independently — without external actors being able to block or influence that decision. It covers three levels.
First, the legal level: which jurisdiction applies to my data? Which authorities can demand access? Which laws affect my provider, even when it operates in Europe? The central concept here is the US CLOUD Act of 2018, which allows US authorities access to the data of US companies — including when that data is physically stored in Europe. A German company storing its data with AWS in Frankfurt is not legally protected from US access. And as the Khan case shows, this is not only about access to data: it is also about the availability of the service itself.
Second, the operational level: which services keep running undisturbed if the provider discontinues them unilaterally — politically, commercially, technically? What happens to my Microsoft 365 tenant if Microsoft suspends it on the basis of a sanctions decision? What happens to my AWS hosting if the account is terminated? Until two years ago these scenarios were purely theoretical. They no longer are.
Third, the strategic level: how much bargaining power does the provider hold over my business processes? How hard would a move be? How deep does the lock-in go? Anyone who has built a complete ERP stack on Salesforce is trapped. Anyone who has migrated an office landscape to Google Workspace, likewise. Those lock-ins are not legal, but in practice they bind just as tightly.
Sovereignty is not binary — no modern company can operate entirely free of US providers, and most should not try. But sovereignty is a scale, and on that scale one can deliberately move in one direction or the other.
Why the question is becoming urgent now
Until 2024, the debate about digital sovereignty in Germany was largely academic. There were reports from the federal information security office, recommendations from government, occasional requirements for critical infrastructure. But for an ordinary company with thirty employees it was not a priority. That is changing, and quickly.
First: the geopolitical landscape is no longer predictable. The Khan–Microsoft episode is not an isolated case but the tip of an iceberg. Trump’s second term has already produced several episodes in its first months showing that US corporations become instruments of American foreign policy whether they want to or not. There have been threats of sanctions, unilateral service restrictions for particular countries, political pressure on US cloud providers. The list is getting longer, not shorter.
Second: German and European regulation bites harder. Schrems II made EU–US data transfers legally difficult in 2020. The EU–US Data Privacy Framework of 2023 tries to smooth that over — but the legal uncertainty has not gone away, and the Khan case shows the framework reaching its limits. NIS2 has required demonstrable cyber resilience from many companies since 2024. The GDPR remains strict. Any smaller company working with personal data today should not first discover where its data sits because an authority asked.
Third: serious competition from Europe is growing. Hetzner, OVH, Scaleway, IONOS, T-Systems — on the hosting side there are now solid European offerings that did not exist five years ago. Mailbox.org and Posteo offer GDPR-compliant email alternatives. Open-source stacks such as PostgreSQL, n8n, Nextcloud or OpenProject have become enormously more professional. It is no longer the case that sovereignty means going without modern tools.
Fourth: clients and business partners increasingly ask. Anyone selling into the public sector as a supplier often has to provide evidence of sovereignty today. Anyone working with large corporations that have their own compliance requirements, likewise. The question “where is your data?” is asked explicitly in procurement. Anyone without a good answer drops out.
Three levels you should concretely examine
If you want to know how sovereign your IT is today, there are three levels I would go through pragmatically.
Level 1 — hosting and location
Question: where is my data physically? Which jurisdiction applies?
In most German smaller companies the answer today looks like this: Microsoft 365 runs on European Microsoft servers (though legally under the US CLOUD Act, because Microsoft is a US company). ERP data depends on the provider — with a German ERP vendor hosting in Germany it is safe; with an international vendor on an AWS backend it is not. The website often runs at a German host — good. Backup solutions are rarely as good as the rest, often AWS-based or with international backup providers.
What you should concretely do: a short inventory of every system holding business-critical data. For each: where the provider is based, where it hosts, which jurisdiction applies. You will be surprised how unclear the answers often are.
Level 2 — the identity and access layer
Question: which providers see my identities, my permissions, my activity data?
This is the level most often overlooked in the sovereignty debate. If you use single sign-on through Microsoft Entra ID, Microsoft sees who in your company uses which application and when — even when those applications do not run at Microsoft. If you use Google Workspace, the same goes for Google. That metadata is often more sensitive than the content itself.
What you should concretely do: identify your identity provider. If it is Microsoft or Google, consider whether a European alternative exists — Keycloak, Authentik, or a dedicated European provider. Migrating is not trivial, but it is feasible.
Level 3 — tool and process lock-in
Question: how hard would it be to move away from the current provider, operationally and financially?
This is the level that matters most strategically. Some lock-ins are deep: a complete Salesforce implementation with hundreds of custom fields and process builders is barely migratable. An ERP platform with ten years of master data, likewise. Other lock-ins are shallow: office applications can be replaced relatively easily when the data is in open formats. Web tracking can be swapped out.
What you should concretely do: rank your tools by depth of lock-in. For the deep ones, ask yourself: what does my exit look like if the provider doubles its terms tomorrow or discontinues the service? If you have no answer, that is a strategic weak point.
How we handle this at digiFORMER
We do not try to be free of US providers. That would be neither realistic nor sensible. We use Microsoft 365 where it is the best tool — above all when working with clients who use it anyway. We use Cloudflare in a few places where its performance is unbeatable. We use Anthropic’s Claude intensively in our delivery chain, because the quality of the models makes a difference.
But we have set ourselves clear rules about where sovereignty takes precedence.
For our own products — SlimCore above all — a strictly European architecture applies. Hosting exclusively in Germany, in time complemented by a second European provider. A data core in PostgreSQL, with no SaaS dependencies. Open standards, documented migration paths. SlimCore clients should know: even if we disappear tomorrow, they can get at their data. That is not a given.
In our recommendations to clients we actively look at where European alternatives hold up. We have, for instance, taken several clients from Mailchimp to European newsletter providers. We have migrated backup solutions from AWS to setups at a German host. We recommend mailbox.org and Posteo instead of Gmail where that fits technically. Where the step does not hold up — with office applications at companies deeply invested in Microsoft 365, say — we stay realistic.
In our own supply chain we look at every new tool through the sovereignty lens. Running an automation service ourselves in Germany rather than putting it on a US platform is a deliberate decision. Recommending mailbox.org over Gmail is another. Using .eu instead of .com on our own website is another. Those small decisions add up to a coherent position.
What sovereignty is not
I want to be clear about what digital sovereignty is not — because the term is sometimes stretched too far.
Sovereignty is not anti-American. It is not about boycotting US providers because they are American. It is about deciding consciously when you want to depend on a provider, and what risks come with it. Microsoft, Google and Amazon deliver excellent tools. Some of them have no equal. But they are also embedded in a political and legal space that is changing. That knowledge should feed into how tools are chosen.
Sovereignty is not free. Choosing a European alternative sometimes costs more — either directly in the licence price or indirectly in the migration effort. Those costs are real and have to be weighed against the strategic advantages. In some cases it is not worth it. In others it is.
Sovereignty is not complete. You cannot run your internet infrastructure without US components — DNS, many content delivery networks, undersea cables are in the hands of international actors. You cannot build a modern software supply chain without npm, GitHub or comparable platforms. Sovereignty at a hundred per cent is an illusion. Sovereignty on the critical layers is achievable — and that is what this is about.
Nor is sovereignty static. What is a safe European choice today can be bought by a US corporation tomorrow. What is a US solution today may acquire a European subsidiary with its own data structure tomorrow. Sovereignty calls for periodic reassessment — not every month, but every year or two.
A concrete recommendation for your next step
If you are engaging seriously with digital sovereignty for the first time today, the temptation is to launch large migration projects straight away. That is usually a mistake. The better path looks like this:
Step 1 — take stock. List every system holding business-critical data. For each: provider, hosting location, jurisdiction, depth of lock-in. That takes half a day.
Step 2 — assess the risk. For each system: what happens if this provider discontinues the service tomorrow — politically, technically, commercially? How does that affect your business? How long would you need to absorb it? Sort the list by severity of impact.
Step 3 — prioritise. Concentrate on the top three systems from that ranking. For those, look seriously: is there a European alternative? How much work would a move be? What would it cost? What would it give you?
Step 4 — rebuild step by step. Migrate one at a time, in phases, with clear documentation. Anyone attempting everything at once fails. Anyone taking on one system per quarter gets a long way in two years.
That is the unexcited version of digital sovereignty. No manifestos, no sanctity, no marketing campaign. Just quiet, methodical reduction of dependency — where it holds up, and only there.
One last observation
Looking back on ten years of IT consulting, sovereignty is the subject that has changed most dramatically. In 2016 it was a niche argument for compliance specialists. In 2026 it is a top-three question in many conversations with management. The Khan–Microsoft episode made it concrete: this is not about theories from Brussels or academic discussions of data protection. It is about your email account not working tomorrow morning because a US president signed an executive order.
In that world, the winners are those who choose tools they can keep under pressure. That is a pragmatic position, not an ideological one. It is compatible with Microsoft 365. It is compatible with cloud computing. It is compatible with modern software architecture. But it requires you to know what you are doing — and why.
If you want to know where your company stands today, let us talk. A serious inventory takes half a day to a day, it does not cost a fortune, and at the end you know where you are. That is worth more than ten glossy strategy papers.
This article is the third part of a series on digiFORMER’s position. If you want to jump to the earlier parts: the manifesto and AI honestly placed are also on this site.
Andere Notizen aus der Arbeit.
Have a case that sounds like our kind of desk?
We are glad to talk. A first call of thirty minutes, no fee, no obligation to continue. If we are not a fit, we say so.