Imagine a small cultural archive choosing a service to store interviews, photographs, and donor records. The subscription price is easy to compare. Other questions are harder: where will the files be processed, who can access them, and what happens if the archive wants to move? This hypothetical decision puts a human face on a debate often conducted in the language of national strategy.

Digital sovereignty is used to discuss control over digital systems, infrastructure, and information. Its meaning depends on the speaker and the problem being addressed. A government may be concerned about its ability to enforce rules; an institution may be concerned about dependence on a supplier. The phrase alone does not tell us which concern a proposal will actually solve.

Location is one kind of control

The OECD’s work on data localisation distinguishes restrictions and requirements concerning where data is stored or processed from the wider question of governing digital activity. Its 2020 discussion also cautions that sovereignty language can serve different purposes. A claim about regulatory authority is not necessarily identical to a claim of broad state control over online life. [1]

The OECD’s 2023 study examines the forms taken by localisation measures and their potential implications. The useful distinction for readers is between requiring local storage and restricting what can happen outside a territory. A rule about keeping a local copy and a rule preventing overseas processing need not have the same effect. Policy comparisons should specify the actual obligation instead of placing every measure in one bucket. [2]

Privacy does not stop at the frontier

The European Data Protection Board’s guide illustrates a different approach to cross-border control. It explains that transfers of personal data outside the European Economic Area can use mechanisms including an adequacy decision or appropriate safeguards. It also describes limited derogations, while warning that these should generally be a last resort rather than the normal basis for transfers. [4]

The point is not that every international transfer is permissible, or that paperwork guarantees protection. It is that location and protection are distinct questions. A framework can permit information to move while placing conditions on that movement. For a particular organization, the applicable requirements depend on the facts; a general explainer is not a compliance assessment.

The tradeoff is more complicated than open or closed

The joint OECD/WTO report published in 2025 examines the economic implications of data regulation alongside concerns about privacy, security, and trust. Its framing matters: cross-border flows support social and economic activity, but the concerns prompting regulation are not imaginary. Assessing a rule means considering both the problem it addresses and the restrictions or costs it creates. [3]

For the hypothetical archive, an open connection is not enough if the organization cannot understand its contract. Local storage is not enough if nobody has considered permissions or a future move to another service. Those are examples of questions a procurement process should investigate, not claims that one type of provider is inherently trustworthy or untrustworthy. A geographical label cannot answer the whole decision.

Ask what the promise actually covers

Three questions can make a sovereignty claim more concrete. First, control over what: a physical location, the ability to operate a system, the handling of personal information, or a purchasing decision? Second, control for whom: the state, the organization buying the service, or the person whose information is held? Third, what evidence would show that the promise has been delivered?

Those questions can lead to different conclusions without making the exercise pointless. A library and a national public administration may have different responsibilities. A collection of public-domain scans presents different questions from identifiable interview material. A useful debate starts with the actual information and purpose instead of assuming that all data should be treated as one undifferentiated national resource.

The cultural stakes are easy to miss when the discussion stays focused on infrastructure. Institutions decide what can be preserved, how people can participate, and what conditions accompany access. Their technical choices deserve the same clarity of purpose as their editorial or curatorial choices. Asking who controls the data should eventually lead to a more precise question: what can the people affected understand, contest, or change?

For a public discussion, this means asking advocates to name the responsibility they want to strengthen and how their proposal would do it. A clear answer gives citizens something to examine; an undefined promise of control leaves the most consequential choices out of view.

Sources & further reading

  1. OECD: Data localisation trends and challenges — 2020
  2. OECD: The Nature, Evolution and Potential Implications of Data Localisation Measures — 2023
  3. OECD/WTO: Economic Implications of Data Regulation — 2025
  4. European Data Protection Board: International data transfers