What Is Digital Sovereignty? A Guide for Public-Sector… | UBDS Digital
DIGITAL SOVEREIGNTY Public Sector
Digital Sovereignty

WHAT IS DIGITAL SOVEREIGNTY? A PRACTICAL GUIDE FOR PUBLIC-SECTOR LEADERS

Matt Johnson CTO
28 September, 2026

Digital sovereignty has moved firmly onto the UK policy agenda.

During 2026, Parliament has held dedicated debates on technology and national sovereignty, with MPs and peers examining the UK’s reliance on overseas technology providers and what those dependencies could mean for resilience, security and the country’s ability to make its own digital choices.

For public-sector leaders, this brings a much bigger question into focus. As public services become increasingly dependent on cloud platforms, software providers, specialist suppliers and global technology supply chains, how much control does an organisation really retain over the digital services it relies on?

It is tempting to answer that question by looking at data. Where is it stored? Who can access it? Which laws and jurisdictions apply?

All of those questions matter. But digital sovereignty goes further.

A public-sector organisation could keep its data in the UK and meet its regulatory requirements, yet still find that a critical service is difficult to change, recover or operate differently. Its technology may be tightly coupled to a particular platform. Essential knowledge may sit with a supplier. Commercial commitments or contractual arrangements may make switching difficult. An alternative provider might exist without there being a realistic way to move the service to it.

These are the wider dependencies at the heart of digital sovereignty and reflected in UBDS Digital’s Eight Dimensions framework.

For senior public-sector leaders, digital sovereignty is therefore not simply about where data or technology sits. It is about understanding the dependencies surrounding critical digital services and retaining credible choices when circumstances change.

WHAT IS DIGITAL SOVEREIGNTY?

Digital sovereignty is an organisation’s ability to retain sufficient control, knowledge and choice over the digital services and technologies it depends on. It is not simply about where data is stored.

The House of Commons Library frames digital sovereignty around the capacity to make informed choices about the technologies and digital systems on which organisations and countries depend. That does not mean government needs to become technologically self-sufficient.

Modern public services depend on external providers for good reasons. Cloud platforms, software suppliers and specialist partners can provide scale, capability and innovation that would be difficult or inefficient to reproduce internally.

The more useful question is not whether dependency exists. It is whether that dependency is understood, whether its consequences are acceptable and whether credible alternatives remain available.

WHY DOES DIGITAL SOVEREIGNTY MATTER TO GOVERNMENT?

Digital technology increasingly underpins the delivery of public services. As a result, technology dependencies can quickly become operational and strategic dependencies.

Consider a critical service that relies heavily on a particular platform, supplier or operating model. What happens if the commercial relationship changes? What if a supplier can no longer provide the same service? What if regulation, ownership arrangements or geopolitical conditions alter? Could the organisation recover the service elsewhere, and could it do so within an acceptable timeframe?

For public-sector leaders, the significance of a digital dependency depends on the service that relies on it and the consequences if that dependency is disrupted or constrained. Where a dependency supports an essential public service, losing the ability to operate, recover or change, that service becomes more than a technology problem.

These questions are ultimately about resilience and continuity. They do not make external dependency inherently undesirable. Nor are they an argument against cloud adoption.

For leaders, the important distinction is between dependencies the organisation has deliberately accepted and those that have simply built up over time. Losing practical control over a critical digital service can constrain operational choices, increase transition costs and reduce the organisation’s ability to respond when circumstances change.

IS DIGITAL SOVEREIGNTY JUST ABOUT WHERE DATA IS STORED?

No.

Data residency remains an important consideration, particularly where government organisations handle sensitive information. But knowing the physical location of data does not, by itself, establish digital sovereignty.

The National Cyber Security Centre advises organisations to consider not only where information is stored, but also where it is processed and managed, which jurisdictions apply and who may be able to access it.

The distinction becomes even clearer when the wider service is considered. An organisation might retain ownership of its data while depending heavily on proprietary technology, provider-specific operational tooling, third-party expertise, identity or security services, licensing arrangements or contractual transition support.

Data residency: concerns where data is physically located.

Data sovereignty: considers the legal and jurisdictional conditions affecting that data.

Digital sovereignty: asks the broader question: how much meaningful control and choice does the organisation retain over the digital service and the dependencies surrounding it?

THE REAL ISSUE IS DEPENDENCY AND CHOICE.

Every modern public service has digital dependencies. Some are entirely appropriate. A managed platform might reduce operational burden. A specialist supplier may provide expertise that would be inefficient to maintain internally. A long-term commercial arrangement may provide significant value.

The purpose of digital sovereignty is not to eliminate those dependencies. It is to understand which ones matter and what they mean for future choices.

UBDS Digital assesses this broader perspective across eight dimensions: Technology, Data, Operations, Security, People, Commercial, Contracts, and Jurisdiction. Together, they help reveal where an organisation has genuine options and where those options may be constrained.

A useful distinction for leaders is between an available alternative and an executable alternative. Another provider may exist. A contract may contain an exit clause. An architecture may theoretically support migration. But could the organisation actually make the change?

Could its data be recovered and made usable elsewhere? Would it retain the necessary operational knowledge? Could security controls be recreated? Would the commercial cost be realistic? Could the transition happen quickly enough to protect service continuity?

This is where digital sovereignty stops being an abstract policy question and becomes a practical leadership issue.

CLOUD PORTABILITY IS NOT THE SAME AS SERVICE PORTABILITY.

Technology portability is one part of digital sovereignty, but it does not tell leaders whether an entire service can be moved or recovered.

An application might technically run on another cloud platform. The wider service may still depend on data structures, monitoring tools, backup processes, security services, supplier expertise or commercial arrangements that are difficult to reproduce elsewhere.

This is the difference between cloud portability and service portability. The existence of an alternative does not necessarily mean an organisation has the practical ability to exercise it.

For senior leaders, the question is not simply, “Could this workload run somewhere else?” It is, “Could we continue delivering this service if we had to operate it differently?”

FIVE QUESTIONS PUBLIC SECTOR LEADERS SHOULD ASK.

  1. Which digital services are sufficiently critical to require a sovereignty assessment?
  2. Where do their most significant technology, data, operational, supplier and jurisdictional dependencies sit?
  3. Which dependencies have been consciously accepted, and which have accumulated without an explicit decision?
  4. What realistic alternatives would remain if circumstances changed?
  5. Have we demonstrated that those alternatives could actually be exercised?

These questions move digital sovereignty away from an abstract debate and towards practical decisions about resilience, control and the ability to respond.

DIGITAL SOVEREIGNTY IS ABOUT MAINTAINING STRATEGIC CHOICE.

Digital dependencies can limit control, flexibility and strategic choice. Want to understand where those dependencies arise? Read our Eight Dimensions of Dependency blog.

Ready to assess them in your organisation? Explore our Digital Sovereignty & Service Portability service.

Matt Johnson CTO
Matt Johnson
Group Chief Technology Officer

Looking for
exceptional outcomes?

Get in touch
UBDS Digital Man with Mug | security operations centre