The point: According to a Bitkom study, lock-in effects prevent 59 percent of companies from switching cloud providers, which is why CTOs should approach data sovereignty as an architectural question rather than a rigid compliance requirement.
Digital sovereignty has evolved from a compliance footnote into a board-level topic – driven by NIS2, DORA and geopolitical tensions. For CTOs, the question is how to reconcile sovereignty strategies with operational flexibility and resilience without unnecessarily complicating internal processes.
Regulated industries such as finance and healthcare have always had to keep an eye on where their data is stored and under which legal frameworks it falls. With NIS2 and DORA, these questions are gaining weight, as both EU regulations govern sovereignty over data, IT architectures and supply chains. However, a recent Bitkom study shows that switching providers remains technically demanding: 59 percent of the companies surveyed cited lock-in effects such as data migration as the reason they ultimately stay with their original cloud provider. In addition, 43 percent currently see no equivalent European alternatives to the major hyperscalers for their cloud requirements.
For CTOs, this means that a complete exit from the hyperscalers’ ecosystems is usually not a realistic option in practice if agility and innovative capacity are to be preserved. The reason lies in the scope of functionality, scalability and reliability of the major providers, which are difficult to replicate. A switch would also be a multi-year, high-risk major project that most organizations can hardly manage. The decision as to which data requires which kind of control should therefore primarily be a matter of architecture – not a blanket sovereignty mandate that unnecessarily complicates operational processes.
In everyday practice, actual damage is often caused not by compliance violations but by operational incidents such as system outages or exploited security vulnerabilities. According to the EuroCloud Pulse Check 2025, companies in Germany see cybersecurity (37 percent), flexible IT infrastructure (35 percent) and IT failover resilience (34 percent) as central pillars of their resilience. For CTOs, the conclusion is not to treat sovereignty and data residency in isolation as a legal compliance exercise, but as an integral part of a broader resilience strategy that jointly addresses technical flexibility and regulatory requirements.
Source: www.it-daily.net · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.