What is Digital Sovereignty?

Most definitions of digital sovereignty are captured by vendors or governments to fit their purpose, and lack accountability.

This definition was built to fix that.

Explore the Duology

Diagnosis, exposure, and the instruments to reclaim control.

Meet the Author

Thirty years inside the machine. Now naming what it does.

Lookup Glossary Terms

Review the full Digital Sovereignty Glossary

Every digital sovereignty definition in circulation has been captured. Cloud vendors sell 'sovereign cloud' that collapses the moment the US CLOUD Act, China's National Intelligence Law, or any extraterritorial jurisdiction compels access, while consultancies sell digital sovereignty frameworks and maturity assessments designed to be passed without breaking vendor lock-in. Governments invoke data sovereignty to justify surveillance, and standards bodies certify data governance processes that never test whether technology sovereignty, cloud sovereignty, or operational control survive when permission is withdrawn. The field has been gutted, and what remains are product categories dressed as enforceable conditions.

This digital sovereignty definition exists because none of the others survive contact with power. None require that disputes be compelled in the sovereign's own courts, none test whether digital infrastructure survives when a vendor, platform, or jurisdiction withdraws, overrides, or blocks execution, and none address foreign arbitration, covert observation, or the licensing conditions that make exit non-viable. Not one of them even defines what failure looks like. This definition was built to be enforceable, auditable, and independently verifiable, because the field needed a definition that cannot be sold, only measured.

This digital sovereignty definition is just one of the many terms in the full glossary of digital sovereignty terms.

Definition of Digital Sovereignty

The ultimate enforceable authority, and the practical control to carry that authority into effect, of nations, organisations, communities, and individuals (collectively, the sovereign) over the data and operational survivability, execution, governance, and recovery of digital systems.

This authority and control must be visible, auditable, independently verifiable, structurally secured, operationally demonstrable, and enforceable by the sovereign, with capacity proportionate to the sovereign's scale and the criticality of the system. This capacity includes the skills, expertise, and operational knowledge required to exercise sovereign authority, which must be retained, directed, and substitutable under the sovereign's own control.

It is a strategic capacity that must be exercised without external permission, not contingent on external authority, and carried into effect through the ability to build, operate, permit, constrain, deny, restore, migrate, substitute, or exit execution.

This capacity is compatible with voluntary participation in shared systems, markets, treaties, or standards only where entry, exit, enforcement, and remedy remain under the sovereign's own control within a defined operational boundary and where such participation does not degrade or subordinate sovereign authority during operation. Such participation cannot be unilaterally altered, revoked, or weaponised by an external actor.

It must be enforceable under the sovereign's own legal jurisdiction, such that disputes, interventions, audit rights, and remedies can be compelled in the sovereign's own courts and enforcement systems, within the sovereign's own time tolerance, and without reliance on foreign arbitration, extraterritorial law, or external discretionary authority that can prevent or indefinitely delay enforcement. Self-determination must be preserved without any form of externally imposed observation, whether overt or covert, embedded as a condition of access, operation, compliance, recovery, or continued use.

Digital sovereignty exists only where that authority and control remain effective without critical reliance on, or exposure to, any external actor, platform, vendor, jurisdiction, infrastructure, contractual condition, economic mechanism, or control path through which execution, continuity, recovery, substitution, migration, or exit can be constrained, degraded, or denied.

It fails wherever any external actor retains the capacity to withdraw, override, delay, compel, surveil, or block sovereign operation, or to impose economic, contractual, or licensing conditions that render execution, continuity, recovery, substitution, migration, or exit non-viable, by any means and through any mechanism, whether technical, legal, commercial, or operational.