No Sovereignty Without a Foundation: Why Infrastructure Tips the Scales
Sovereignty is usually discussed in terms of applications and data. Yet both run on a layer that is frequently overlooked: the infrastructure. Everything stands and falls with who controls the underlying systems. The consequence is uncomfortable but clear: a sovereign application on non-sovereign infrastructure is a contradiction in terms. Those who do not know their foundation do not know their dependencies. That is why it is worth taking a closer look at the three dimensions that make up the foundation: location, operations and jurisdiction.
Location: Where Is the Data Physically Located?
Data never exists without a place. It sits on servers, in racks, in actual buildings – and this physical location has tangible consequences. It determines which data protection laws apply directly, which authorities can demand access and how reliable commitments on latency, availability and geo-redundancy really are.
The note "EU region" in a contract does not automatically mean that the data is kept in Europe. Replication, backups, support access or telemetry data often travel across borders without this becoming visible in day-to-day operations. Sovereignty of location therefore means verifiable, complete data residency in Germany or the EU – including all copies, metadata and operational data. Certified data centers built to standards such as ISO/IEC 27001 make this proof auditable.
Operations: Who Has Control Over the Systems?
Location is necessary but not sufficient. Just as decisive is who actually operates the infrastructure: Who administers it, who applies updates, who can access data if it comes to that? A data center somewhere in Germany is of little use if operations, support and remote maintenance are controlled from a third country.
Then there is the question of transparency. Many infrastructure offerings are black boxes: the customer sees a portal but not what happens behind it. Sovereign operations mean the opposite – comprehensible operating models, clearly regulated access, documented processes and tangible points of contact. In short: control does not come from trust alone but from traceability.
Jurisdiction: Which Law Applies and When?
The third dimension is the most invisible and at the same time the most explosive. It is not the server location alone that determines which law applies to data but also the provider's corporate structure. The US CLOUD Act, for instance, obliges US companies to hand over data to US authorities – regardless of where that data is stored. A data center in the EU therefore offers no protection if the operator is subject to a non-European jurisdiction.
For companies, this creates a twofold risk. Legally, because European requirements such as the GDPR, NIS-2 or the EU Data Act simply cannot be cleanly reconciled with extraterritorial access rights. Commercially, because customers, partners and supervisory authorities are increasingly asking precisely this question. Sovereignty in terms of jurisdiction therefore means choosing providers whose ownership structure, contract law and place of jurisdiction lie entirely in Germany or the EU.
Open Source and European Alternatives
How can such a foundation be built in concrete terms? A central building block is open source. Open source code is the opposite of a black box: auditable, vendor-independent, free of hidden data outflows and license traps. Those who rely on open standards and interfaces also secure genuine portability – the most effective remedy against vendor lock-in.
The good news: fully fledged, open alternative solutions now exist for virtually every layer of the foundation. Added to this is a growing ecosystem of European cloud and infrastructure providers operating these technologies in certified data centers. The decisive factor is the operating model: open source only unfolds its sovereignty effect once operations, support and further development are professionally secured – whether through in-house teams or through managed services from the EU. This is exactly where the circle closes back to Part 1: IT not "by features" but "by design".
Cloud Is Not Just Cloud: What Matters
So does this mean getting out of the public cloud? No. As shown in Part 1, sovereignty is a spectrum, not all-or-nothing. Hyperscalers have their place – for non-critical workloads, global scaling or standard services. Critical data, core processes and sensitive workloads, on the other hand, belong on a foundation that fulfills all three dimensions: location, operations and jurisdiction.
In practice, this leads to hybrid architectures and multi-cloud strategies with a clear division of labor. We have already named the decisive test questions: Where is my data – both verifiably and completely? Who operates the systems – and above all, from where? Which jurisdiction applies in an emergency – and can I get out again without paralyzing my business? Anyone who asks these questions quickly separates sovereignty marketing from substance.
Conclusion: The Foundation Is Half the Sovereignty
Data centers, cloud and IT infrastructure are not technical details but the basis of every sovereign digital strategy. Location, operations and jurisdiction form the triad against which every offering must be measured – open source and European alternatives provide the building blocks to fulfill it. Those who create clarity here gain control, compliance and negotiating power – and lay the ground on which everything else is built.
Part 3 of this series is about precisely this "everything else": What contribution do individual, concrete platforms and solutions make – above all in IT security? And what matters in terms of deployment as well as usage and service models, so that ambition turns into lived practice?
Digital Sovereignty with DTS
DTS answers the three foundational questions not with promises but with facts. All of its own platforms and services are provided exclusively from two of its own certified high-performance data centers in Germany – the location question is settled. Operations are handled entirely by DTS itself, transparently, traceably and with personally accessible points of contact instead of an anonymous black box – the operations question is settled. As a German company with development "Made in Germany" in line with EU standards, DTS is subject exclusively to German and European law. The US CLOUD Act plays no role here – the legal question is settled.
On this foundation, DTS combines the complete sovereignty stack as manufacturer, reseller, operator and consultant: from infrastructure and managed services through to its own security software. Wherever it is technologically sound, we integrate dedicated European and open source alternatives. Customers retain data sovereignty, transparency and controllability – and at the same time meet requirements such as NIS-2.












