Website icon Xpert.Digital

Europe talks about independence? 15,000 municipalities analyzed: The invisible power of Microsoft in our administrations

Europe talks about independence? 15,000 municipalities analyzed: The invisible power of Microsoft in our administrations

Europe talks about independence? 15,000 municipalities analyzed: The invisible power of Microsoft in our administrations – Creative image on the topic, with AI: Xpert.Digital

Germany surprises, Austria stumbles: Who really checks our emails at the town hall?

Explosive study reveals: Austria's municipalities are dependent on Microsoft

The myth of independence: Why digital sovereignty fails as early as the inbox

In 2026, email communication seems almost like a boring, basic technology. Yet it is precisely there, in the unassuming inboxes of our local governments, that one of the most crucial strategic questions of our time is being decided: Europe's digital sovereignty. While technological independence is being eloquently proclaimed on the political stage, a large-scale study by the MXmap project of over 15,000 municipal email infrastructures in the DACH region (Germany, Austria, and Switzerland) reveals a stark reality. The results show a blatant dependence on US corporations – above all, Microsoft.

But the picture is far from uniform: While Germany surprises with an astonishingly low US share of just 7.2 percent, Austria (67 percent) and Switzerland (53.3 percent) are heavily dependent on the tech giant. What at first glance sounds like a purely technical procurement issue actually harbors enormous economic, data protection, and geopolitical risks. Because whoever controls the digital infrastructure also controls the sensitive metadata of government agencies, citizens, and businesses. Read on to find out why an American provider isn't automatically insecure, why true sovereignty must be based on freedom of choice rather than autarky – and why the true cost of a digital monoculture isn't reflected in the license fee.

Digital sovereignty begins in the municipal mailbox: An inconspicuous infrastructure issue with political explosiveness

In 2026, email seems almost like a boring, basic technology. Precisely for this reason, its strategic importance is easily underestimated. In local government, it is not just one communication channel among many, but a connecting element between departments, citizens, businesses, political bodies, state authorities, and external service providers. Municipal mailboxes handle appointment scheduling, personnel matters, tender documents, social welfare issues, construction and business information, internal situation reports, and notifications of administrative procedures. Even if particularly sensitive data should not be sent unencrypted via email, the sender, recipient, timestamps, subject lines, attachments, and communication frequency already generate meaningful metadata.

Against this backdrop, the published results of the MXmap project have considerable economic and political relevance. According to the project, 15,331 municipal email infrastructures in Germany, Austria, and Switzerland were examined. The reported share of US providers is only 7.2 percent in Germany, 53.3 percent in Switzerland, and 67 percent in Austria. The US provider category, therefore, almost exclusively includes Microsoft. The real finding is thus not only a dependence on a non-European legal system, but also an exceptionally strong concentration on a single corporation.

The differences are so significant that they can hardly be dismissed as random fluctuations. Austria's rate is more than nine times higher than Germany's, and Switzerland's is more than seven times higher. Conversely, this means that around 92.8 percent of the German municipal infrastructure examined is not classified as being provided by US vendors, while this figure is only 46.7 percent in Switzerland and 33 percent in Austria. This distribution does not automatically make Germany digitally sovereign or Austria insecure. However, it does demonstrate that three economically intertwined countries with similar administrative tasks have arrived at fundamentally different procurement and infrastructure decisions.

This study provides something that is often lacking in the debate about digital sovereignty: an empirically visible structure. The term is frequently used in political discourse, but often remains abstract. A map of municipal email providers translates it into concrete dependencies, regional patterns, and institutional decisions. It doesn't show who gives the better speeches, but rather which providers are actually embedded in the everyday communication channels of public administration.

What the numbers actually measure

A reliable analysis must first distinguish between email domain, email routing, provider assignment, data processing, and physical storage location. The project collects municipal domains from official directories and other publicly accessible sources, identifies email addresses, checks DNS and MX records, and supplements these signals with information such as SPF data, Autodiscover information, SMTP characteristics, and assignments to autonomous networks. Subsequently, the system uses several technical indicators to deduce which provider is likely operating the email service. The methodology also includes checks of security features such as SPF, DMARC, DNSSEC, and DANE.

This is significantly more informative than simply looking at a single MX record. Security gateways can obscure the underlying mail service, forwarding rules can create false impressions, and historical entries may still exist even though a service is practically no longer in use. Therefore, combining multiple indicators and validating them using bounce messages improves the reliability of the mapping. Furthermore, openly publishing the pipeline, data, and maps increases verifiability and allows for corrections.

Nevertheless, the results should not be overinterpreted. Public DNS signals primarily indicate where emails may be delivered and which systems act as legitimate senders. They do not prove in every individual case where all messages, backups, logs, and metadata are stored. Likewise, it cannot be determined solely from this information which contract type a municipality uses, whether special client encryption has been implemented, who controls the keys, or which subcontractors are involved. The term "server" can also be misleading, as a single municipality may use multiple technical endpoints, and conversely, many municipalities may be served via a shared platform.

The correct interpretation, therefore, is not that 67 percent of Austrian municipalities demonstrably store all sensitive data on physical servers in the United States. Rather, it is reliably established that a very high percentage of the Austrian municipalities surveyed have publicly identifiable email infrastructure assigned to a US provider, predominantly Microsoft. This provider- and jurisdiction-related dependency alone is economically significant, even if the data is stored in a European data center.

The overall population also deserves attention. Municipal structures change through mergers, administrative associations, and shared domains. A technical analysis can encompass multiple domains belonging to a single local authority or, conversely, assign multiple local authorities to a shared infrastructure. Therefore, percentages should always be published together with the reference date, the definition of the unit under investigation, classification rules, confidence levels, and the proportion of cases that cannot be clearly assigned. While a large sample size makes the overall pattern compelling, it does not replace transparency regarding these methodological details.

Sovereignty is the ability to vote, not digital autarky

Digital sovereignty is often mistakenly equated with complete technological self-sufficiency. Such autonomy would be neither realistic nor economically viable for individual municipalities. No town hall needs to develop its own processors, program its own operating system, and operate a data center on its own. Rather, sovereignty means being able to make critical decisions independently at reasonable costs and correct them if necessary. This includes control over data, identities, keys, interfaces, contractual terms, operational processes, and exit strategies.

The decisive factor is therefore not solely the origin of a product, but rather the combination of legal jurisdiction, technical control, economic replaceability, and operational capacity. A European provider with proprietary formats, weak security processes, and a lack of portability can also create dependency for a municipality. Conversely, a US provider can offer technically excellent services, high availability, strong defense mechanisms, and contractually limited data flows. Origin nevertheless remains relevant because ownership structure and corporate headquarters determine which extraterritorial laws and government regulations a provider may be subject to.

Sovereignty can therefore be understood as a strategic option. A municipality is more sovereign the more credibly it can switch between providers, replace individual services, fully export data, control its own keys, and continue operating despite geopolitical or legal changes. A purely theoretical choice is insufficient. If switching providers is contractually permitted but takes years technically, cannot be managed with the available personnel, or becomes prohibitively expensive due to proprietary integrations, then there is effectively no freedom of choice.

From an economic perspective, digital sovereignty is similar to insurance against rare but potentially serious events. In normal operations, redundancy appears more expensive than a unified platform. However, in a crisis, the value of alternative operating methods, portable data, and independent expertise becomes apparent. The difficulty lies in the fact that the benefits of this preparedness are not visible every year, while licensing and migration costs are immediately reflected in the budget. Procurement systems that compare only short-term prices therefore underestimate structural risks.

Why Microsoft is so economically attractive

The widespread adoption of Microsoft is not solely the result of political negligence. It follows a strong economic logic. Microsoft 365 combines email, calendar, directory services, Office applications, video conferencing, document storage, collaboration, device management, security features, and increasingly, artificial intelligence into a single integrated system. For a municipality with limited IT resources, such a bundle can be more attractive than coordinating numerous individual solutions from different vendors.

Furthermore, there are economies of scale. A global hyperscaler distributes investments in data centers, networks, spam filters, threat analysis, high availability, and software development across millions of customers. Smaller providers may be very efficient in individual areas, but rarely achieve the same global research and investment capacity. The job market also favors established systems: There are many administrators, consulting firms, training programs, and standardized certifications available for Microsoft products. Municipalities can more easily find staff and service providers when they use widely adopted technologies.

Another factor is bundling. If an office suite is already in use, the additional use of Exchange Online often appears cost-effective. However, the business calculation can be distorted if discounted packages eliminate competition between individual services. A seemingly inexpensive overall package can generate higher switching costs in the long run because email, identity management, documents, group policies, video conferencing, and specialized applications are becoming increasingly intertwined. The more components rely on a shared directory and proprietary interfaces, the more expensive the eventual separation will be.

Network effects amplify this dynamic. When neighboring municipalities, state authorities, consulting firms, and external partners use the same tools, coordination costs decrease. Files can be exchanged without formatting issues, meetings can be organized via familiar platforms, and existing templates remain usable. Each additional organization that joins the ecosystem increases its benefits for existing participants. At the same time, the market for alternatives shrinks, reducing their investment capacity and making them less attractive.

The decision to choose Microsoft may therefore be rational at the level of an individual municipality, while the overall result becomes problematic from a macroeconomic perspective. This distinction between individual economic benefit and collective risk is crucial. No single municipality bears sole responsibility for Europe's technological competitiveness. However, if thousands of public bodies decide according to the same short-term logic, a concentration of power emerges, the geopolitical and competitive costs of which are borne by the general public.

Austria's contradiction between demand and procurement

Austria played a key role in initiating the European Declaration on Digital Sovereignty. The initiative aimed to strengthen Europe's capacity to independently regulate digital infrastructure, data, and technologies, and to decide on their use without excessive dependence on external actors. However, the fact that 67 percent of the municipal email infrastructures examined are provided by US companies reveals a clear contradiction between political aspiration and operational reality.

This contradiction is not merely rhetorical. It points to a typical implementation problem in digital policy. Strategies are decided at the federal and European levels, while concrete IT decisions are made decentrally in municipalities, municipal associations, states, and public companies. Responsibilities, budgets, existing contracts, and personnel skills are distributed across many levels. A declaration can formulate goals, but it does not automatically change existing license agreements, technical interfaces, and established administrative processes.

The high Austrian rate could have several structural causes. Possible factors include nationwide procurement frameworks, strong regional IT service providers with a Microsoft focus, widespread adoption of the Microsoft workplace environment, standardized consulting services, and the desire of small municipalities to largely outsource operations and security. Successful recommendations also spread within regional networks. Once a platform has established itself in a federal state, it becomes the supposedly low-risk standard choice. The map with its regional clusters supports this explanation but doesn't prove which factor was decisive in any given case.

Small municipalities, in particular, face a real dilemma. Having their own mail server is no symbol of sovereignty if updates are delayed, there's a lack of qualified personnel, no 24/7 monitoring, and recovery plans exist only on paper. Switching to a professionally operated cloud service can significantly improve operational security. Therefore, any serious critique shouldn't demand that every municipality revert to running its systems in the town hall basement.

The real problem lies in the lack of diversity. If Austrian municipalities used a variety of high-performing European, national, and international solutions, dependency would be better distributed. Concentrating on Microsoft, on the other hand, creates shared sources of error, uniform attack vectors, concentrated pricing power, and significant leverage for political or legal changes. Sovereignty policy must therefore make alternatives competitive, instead of criticizing municipalities for understandable decisions.

Germany's low rate is both a strength and a warning sign

With a US share of 7.2 percent, Germany stands out significantly from the DACH region's pattern. A plausible explanation lies in the historically decentralized structure of municipal IT. Municipal data centers, special-purpose associations, regional providers, publicly funded IT service providers, and medium-sized hosting companies have built their own infrastructures in many places. German federalism, often criticized as an obstacle to digitalization, can act as a diversification mechanism in this case. Different states and regions make different decisions, meaning that no single provider automatically dominates the entire market.

This decentralization can create economic resilience. Regional providers keep added value, skilled workers, tax revenues, and technical expertise within the country. They are familiar with municipal procedures, state-specific legal frameworks, and administrative processes. Short distances to data centers and contacts can be advantageous in the event of disruptions. Furthermore, a diverse provider landscape limits the market power of individual corporations.

However, a low US share is no proof of high quality. A locally operated service may rely on outdated software, be insufficiently secured, or indirectly use numerous non-European components. European providers also sometimes rely on Microsoft licenses, US security products, global content delivery networks, or cloud sub-infrastructure. Visible email delivery represents only one layer of the technical stack.

Furthermore, decentralization comes at a cost. Many small platforms can duplicate investments, use different standards, and implement security measures inconsistently. Without common minimum requirements, weak links emerge in the chain. An attack on one municipal IT service provider can simultaneously affect dozens of administrations. Thus, concentration also exists among regional service providers, albeit on a smaller geographical scale.

Germany's position is therefore strongest when the existing diversity is combined with binding safety standards, joint procurement, interoperable interfaces, and professional operating models. The lesson is not to preserve every local solution. It is to pool effective federal structures in such a way that they achieve economies of scale without creating a new central monopoly.

 

Our EU and German expertise in business development, sales and marketing

Our EU and German expertise in business development, sales and marketing - Image: Xpert.Digital

Industry focus areas: B2B, digitalization (from AI to XR), mechanical engineering, logistics, renewable energies and industry

More information here:

A thematic hub offering insights and expertise:

  • Knowledge platform covering global and regional economies, innovation and industry-specific trends
  • A collection of analyses, insights, and background information from our key areas of focus
  • A place for expertise and information on current developments in business and technology
  • A hub for companies seeking information on markets, digitalization, and industry innovations

 

Regional patterns and their significance for procurement

Switzerland between data protection tradition and platform economy

At 53.3 percent, Switzerland ranks between Germany and Austria, but is significantly closer to the Austrian model. This is remarkable because Switzerland boasts a strong data protection culture, high-performance data centers, a robust telecommunications industry, and numerous local IT providers. The figures demonstrate that an attractive domestic hosting market alone is insufficient to limit the market penetration of integrated global platforms.

Switzerland is located outside the European Union and has its own legal framework. Nevertheless, it is economically closely linked to the European data space. For Swiss municipalities, not only national data protection requirements are important, but also compatibility with companies, citizens, and authorities within the European context. Microsoft offers an established ecosystem for this cross-border collaboration.

The Swiss findings highlight that data localization and provider control must be assessed separately. A data center located in Switzerland can meet low latency and local operational requirements. However, if the critical software, identity, and administration layers are controlled by a foreign corporation, a strategic dependency remains. Conversely, a Swiss provider is not automatically sovereign if it relies entirely on a US cloud and lacks a viable exit strategy.

For Switzerland, it is therefore particularly important to consider the entire supply chain. This includes ownership, corporate headquarters, subcontractors, key management, source code access, update control, support processes, data export, and emergency operations. The "Swiss hosted" label only describes a portion of the actual control.

Where data is located and who has access to it

Public debate often reduces sovereignty to the location of the data center. This is important, but not sufficient. Microsoft has expanded its European data border, allowing customer data, pseudonymized personal data, and certain support data for core cloud services to be stored and processed within the EU and EFTA region. For public sector clients, this significantly reduces data protection and compliance risks.

However, this does not completely eliminate the core legal question. A US corporation remains fundamentally subject to US law. The CLOUD Act allows US authorities, under certain conditions, to demand the release of data from identified service providers, even if that data is stored outside the United States. Legal review and challenge options exist; this is not a blanket, unrestricted right of access. Nevertheless, the risk situation differs from that of a provider subject exclusively to European law and European control.

Equally important is the current European legal framework for transatlantic data transfers. The EU-US Data Privacy Framework allows transfers to certified US organizations based on an adequacy decision. While this creates a legal basis, it does not eliminate all political uncertainty. Previous agreements have been overturned in court, and institutional changes in the United States can trigger new reviews. Therefore, long-term public IT strategies should not rely on the current legal framework remaining unchanged throughout the entire contract period.

The European Commission's case also demonstrates that Microsoft 365 is not inherently illegal. In 2024, the European Data Protection Supervisor criticized, among other things, the insufficiently defined processing purposes and safeguards for data transfers to third countries. After contractual, technical, and organizational adjustments, the supervisory authority determined in 2025 that the identified violations had been rectified. This does not, however, constitute a carte blanche or a general prohibition. Specific configurations, contractual terms, data flows, and control measures are crucial.

For municipalities, this means: The provider's name does not replace a data protection impact assessment. Likewise, a European company headquarters cannot be considered an automatic guarantee of compliance. A documented analysis of the actual service, the categories of data processed, administrative access, telemetry, support channels, and encryption used is necessary.

The economic risk of digital monoculture

A high number of providers is not just a data protection issue, but also a problem for competition and resilience. In a digital monoculture, dependence on the pricing decisions, product changes, licensing models, and development priorities of a single company increases. Municipalities can only partially avoid cost increases if essential processes, files, identities, and interfaces are tied to the same ecosystem.

This dependency often grows gradually. Initially, only email is migrated, followed by calendars, video conferencing, document storage, device management, and security tools. Later, specialized applications are connected via the central identity, and workflows are created using proprietary automation services. Each additional integration improves convenience in the short term but increases the cumulative switching costs. Ultimately, vendor lock-in arises not primarily from a contractual clause, but from the creation of thousands of technical and organizational dependencies.

Concentration also creates systemic risks. A major disruption, faulty update, identity compromise, or administrative misconfiguration can affect many organizations simultaneously. While large platforms invest heavily in resilience, their sheer size makes them particularly attractive targets. The risk to an individual customer may decrease, while the potential societal damage from a rare platform outage increases.

Negotiating power is also shifting. A small municipality can hardly enforce individual contract terms against a global corporation. Joint framework agreements improve its position, but can simultaneously accelerate the widespread standardization to a single provider. What brings better prices in the short term can shrink the market for alternatives in the long run.

From an economic perspective, Europe loses a portion of its value creation if it remains dependent on these companies. License payments flow to non-European corporations, while strategic product development, intellectual property, and highly scalable platform profits are predominantly generated outside of Europe. Local partners continue to earn money from consulting and integration, but often remain in a subordinate role. The crucial standards and product roadmaps are set elsewhere.

Security and sovereignty must not be confused

The strongest counterargument to the criticism of sovereignty is that global cloud providers often operate more securely than small municipal IT departments. This argument should be taken seriously. Microsoft and other hyperscalers have large security teams, global telemetry, automated attack detection, redundant data centers, and rapid update processes. A poorly maintained on-premises Exchange installation can pose a significantly higher immediate risk than a professionally operated cloud service.

Security and sovereignty, however, are distinct aspects. Security encompasses confidentiality, integrity, availability, and resilience against attacks. Sovereignty encompasses control, legal jurisdiction, interchangeability, and the ability to act autonomously. A solution can be highly secure but create significant dependency. Conversely, it can be formally sovereign but technically insecure. Good public IT must fulfill both objectives simultaneously.

The threat landscape justifies stringent requirements. Public administrations are among the preferred targets of cyberattacks, and municipalities are particularly vulnerable due to limited resources. Email remains a key attack vector for phishing, malware, account takeovers, and identity fraud. Simply switching providers will not solve these problems. Essential measures include multi-factor authentication, secure administrative accounts, consistent patching processes, recovery testing, network segmentation, log analysis, employee training, and correctly configured procedures such as SPF, DKIM, and DMARC.

Equally important is the question of who can manage a security incident. Does the municipality have its own log data? Can it independently lock compromised accounts? Are backups in place outside the primary platform? Is there a tested communication channel in case email and identity services fail simultaneously? A fully integrated suite can simplify management, but it can also tie multiple functions to the same chain of trust.

Regional patterns are more important than the average

The interactive map reveals a patchwork of different systems. While this term is often used negatively in administrative discourse, it is analytically valuable. Regional clusters demonstrate that procurement decisions are not solely determined by technical specifications. State policies, municipal data centers, framework agreements, historical partnerships, consulting networks, and regional IT expertise all shape the market.

A federal state or district with a conspicuously high concentration can thus be specifically investigated. What contracts are in place there? What alternatives have been examined? What migration costs have been factored in? Are there municipal service providers that jointly serve several municipalities? Have open standards and exit clauses been demanded? Such questions are more productive than a blanket national attribution of blame.

The regional level also opens up opportunities for economic policy. Several municipalities can pool demand without becoming permanently tied to a single manufacturer. They can finance shared security centers, standardized interfaces, shared administration services, and portable platforms. This creates economies of scale that small European providers could not achieve on their own.

At the same time, diversity should not be confused with arbitrariness. If every municipality uses different formats, security levels, and operational processes, integration costs and the probability of errors increase. The goal must be coordinated diversity: several interchangeable providers based on common standards, common minimum requirements, and tested switching processes.

The true price is not shown on the license invoice

Public procurement often compares visible costs: licenses, migration, operation, support, and training. This is insufficient for a sound cost-benefit analysis. A complete model must also assess exit, concentration, legal, and failure risks. These include costs for data export, format conversion, interface development, retraining, parallel operation, recovery, and the replacement of coupled services.

An asymmetrical timescale is particularly problematic. The benefits of a bundled solution appear immediately, while lock-in costs only become apparent during a later migration. However, decision-makers, budget periods, and contracts change sooner. This creates an incentive to realize savings today and shift future switching costs to successors. Therefore, an honest total cost of ownership calculation must consider the entire lifecycle, including a realistic exit scenario.

Opportunity costs must also be factored in. If tenders effectively require a specific product, innovative suppliers cannot compete. The public sector loses potential price and quality advantages. At the same time, European companies lack a reliable domestic market on which to build references and scale their operations. Sovereign procurement is therefore not just about risk mitigation, but also about industrial policy through demand.

This does not mean that European suppliers should receive a blanket price premium. Permanent protection without performance pressure would perpetuate inefficient structures. Functional tenders, open formats, standardized programming interfaces, separate lots, and measurable portability are more sensible. Competition should not be replaced by nationality, but rather restored through genuine interchangeability.

From political commitment to measurable control

Municipalities need a differentiated governance model, not a blanket ban. First, data and communication processes should be classified according to their protection requirements. General citizen information, internal personnel processes, social data, security communications, and crisis management teams have different requirements. Not every service needs the same level of sovereignty.

The dependencies across the entire technical stack must then be identified. Besides the mail provider, this includes identity services, endpoint management, encryption, key ownership, backup, archiving, spam filters, domain management, network, support, and subcontractors. A municipality that only considers the visible provider may overlook more critical dependencies in other layers.

Every major procurement should include a robust exit plan. This plan must define data formats, export duration, interfaces, deletion confirmations, costs, responsibilities, and the maximum tolerable operational downtime. Crucially, this plan must undergo practical testing. An untested exit plan is as worthless as a data backup that has never been restored.

Measurable key performance indicators (KPIs) could reflect the proportion of exportable data, the number of proprietary interfaces, the duration of an identity change, the proportion of self-controlled keys, the recovery time, the dependence on individual subcontractors, and the proportion of contracts with verified exit clauses. This would transform digital sovereignty from a buzzword into a manageable characteristic.

Common reference architectures should be developed at the state or federal level. Municipalities need tested alternatives, migration tools, model contracts, security profiles, and reliable operating models. Without such support, the choice between a convenient hyperscaler offering and an organizationally demanding in-house solution remains unfair. Sovereignty cannot be solely delegated to small administrations.

A realistic path to greater European freedom of action

The first step is transparency. Projects like MXmap should be regularly updated, methodically documented, and expanded to include additional infrastructure components. Besides email, identity services, collaboration platforms, DNS, web hosting, video conferencing, document storage, and municipal applications would be relevant. Only measurable dependencies can be politically managed.

The second step is risk-based diversification. Particularly sensitive or system-critical processes should preferably run on infrastructures where European authorities can effectively control the legal framework, keys, and operations. For less critical services, global providers can still be economically viable. Crucially, not all functions should automatically migrate to the same ecosystem.

The third step is strengthening common European demand. Individual municipalities are too small to influence platform markets. However, the federal government, states, cantons, municipalities, and European institutions can define common requirements for interoperability, security, and portability. Long-term framework agreements should allow for multiple providers and enable switching not only legally but also technically.

The fourth step is investing in expertise. Outsourcing all architectural knowledge means losing control, even with a European provider. Public administrations need sufficient in-house staff to assess risks, manage contracts, review configurations, and make decisions in emergencies. Sovereignty doesn't come from a label of origin, but from institutional capability.

The fifth step is a European provider policy that rewards performance. Europe doesn't need a copy of every US service, but it does need competitive offerings for secure email, identity, collaboration, cloud infrastructure, and management solutions. Public procurement can create a reliable market for this by requiring open standards and allowing smaller providers access. At the same time, European providers must be able to compete with global platforms in terms of usability, scalability, integration, and security.

The key lesson from 15,331 examined infrastructures

The MXmap results refute two convenient narratives. First, the dominance of US providers is not an immutable law of nature. Germany demonstrates that a large municipal landscape with a significantly lower proportion of US providers is possible. Second, political rhetoric does not guarantee operational sovereignty. Austria's high percentage of US providers illustrates how far apart aspirations and procurement reality can be.

The figures justify neither alarmism nor complacency. A Microsoft service is not automatically insecure or illegal, nor is a German or European provider automatically sovereign and secure. Nevertheless, a 67 percent concentration on US providers, predominantly on a single corporation, is a strategic warning sign. It reduces choices, concentrates risks, and weakens European negotiating power.

The economically sound answer is not a hasty, complete withdrawal. This could increase costs, create security gaps, and overwhelm administrations. What is needed is a phased strategy based on transparency, protection requirement classes, open standards, tested portability, diversified vendors, and in-house technical expertise. Existing Microsoft environments should be configured and contractually structured to limit data flows, better control keys, and ensure that future migrations remain realistic. New procurements must not further deepen dependencies without clearly outlining their long-term costs.

Digital sovereignty, therefore, does not begin with the construction of a European hyperscaler, nor does it end with a political declaration. It begins with seemingly trivial decisions about who delivers municipal emails, manages identities, controls keys, and can export data. The mailbox at the town hall is not a technical trifle. It is a small, everyday component of governmental capacity.

The provocative stance thus remains justified: those who demand European sovereignty but fail to create a verifiable opt-out mechanism for critical administrative infrastructure are primarily engaging in symbolic politics. The claim only becomes credible when municipalities are not forced to adopt European solutions, but can choose between efficient, secure, and genuinely interchangeable options. The real measure is not the nationality of the logo, but the freedom to remain capable of acting under changing economic, legal, or geopolitical conditions.

 

🎯🎯🎯 Data-driven B2B industry hub as a quasi-in-house solution

The quasi-in-house solution: How Xpert.Digital closes operational gaps in B2B marketing and sales – Smart Content-Driven Business - Image: Xpert.Digital

Xpert.Digital is a data-driven B2B industry hub led by Konrad Wolfenstein . The company acts as an external, quasi-in-house solution for industrial partners, closing operational gaps in marketing, content, and sales – without requiring additional resources on the client side.

More information here:

 

Your global marketing and business development partner

☑️ Our business language is English or German

☑️ NEW: Correspondence in your native language!

 

Konrad Wolfenstein

I and my team are happy to be available to you as your personal advisor.

You can contact me by filling out the contact form here wolfenstein@xpert.digital:or simply call me at +49 7348 4088 965. My email address is

I'm looking forward to our joint project.

 

 

☑️ SME support in strategy, consulting, planning and implementation

☑️ Creation or realignment of the digital strategy and digitization

☑️ Expansion and optimization of international sales processes

☑️ Global & Digital B2B trading platforms

☑️ Pioneer Business Development / Marketing / PR / Trade Fairs

Leave the mobile version