Abstract
Data are becoming increasingly crucial to business and social digitalization, as such data have become a strategic asset that accelerates economic competitiveness and digitalization of society. In a societal context, it is important to maintain complete control over data, mainly once it is to be exchanged or shared. Another challenge is associated with who has control over data produced from digital platforms used by citizens. This ability is termed data sovereignty. Digital sovereignty refers to the concept of control, self-determination, and the ability of individuals or business entities to govern and exercise their right to utilize their data. As such, digital and data sovereignty is of paramount importance to enhance data usage and ownership policies. However, less attention has been given to exploring how digital sovereignty can be achieved by digital platforms used by citizens and what policies should be put in place to re-enforce the digital rights of citizens. Moreover, there are fewer guidelines on digital sovereignty requirements in the literature. This article employs qualitative review and comparative policy analysis of European Union (EU)–United States (US) digital initiatives to identify and aggregate policies aimed at providing a common understanding of digital and data sovereignty. This study contributes to addressing challenges faced by companies in implementing initiatives needed to ensure that the digital sovereignty of citizens is preserved when they use digital platforms. Findings from this study present key requirements (technical, legal–institutional, individual, infrastructural, and cross-cutting dimensions) and digital sovereignty initiatives that apply to citizens within the EU–US.
1. Introduction
The adoption of digital technologies has become an important part of society and the economy, but this transformation has resulted in big technological companies such as Apple, Amazon, Google, Meta, Alibaba, Tencent and Microsoft, which provide crucial infrastructure-creating oligopolies which threaten the sovereignty of citizens’ data [1,2]. Infrastructure platforms used by citizens continuously produce user data. This has led to citizens not retaining or controlling data that their devices generate [3], as most of the technological companies do not comply with European rules and values. Intrinsically, public authorities across Europe are now proposing actions to be established for their residents to gain ownership, as well as some degree of control, over “their data” within the European Union. These initiatives have given rise to the concept of “digital sovereignty” [3]. Discussion related to digital sovereignty aims to safeguard the self-determination of societies to protect citizens from surveillance and the unauthorized use of their personal data, and to enable industries to be globally competitive [1,4].
Digital sovereignty is centered on the ability of a nation to control its technological infrastructure (operational sovereignty), its data (data sovereignty), and to provide internet-reliant services (via software sovereignty) [5]. Digital sovereignty is used to underline technical solutions and infrastructures needed for protecting data assets. It relates to control and self-autonomy over data assets, and is often associated with digital, technological, and cyber sovereignty, political discourse, and legal constraints [6]. The interconnection of different platforms used by citizens provided by public service providers in urban transportation, health, education, etc., forms data ecosystems that underline the need for effective mechanisms that ensure sovereign data. This helps to ensure that the citizens still retain autonomy after the exchange of data without them losing control over their data [6]. This necessitates the study of data sovereignty, which is a part of digital sovereignty. Sovereign data exchange refers to the ability of a data owner or data producer to share its data with data consumers and data users without losing its ownership. It aims to ensure that data owners and data producers have complete control over their data assets not only before the data are shared but after data are exchanged or shared with others [6,7].
This requires that data owners can define usage restrictions such as policies that administer the use and dissemination of their data before sharing it with data consumers and data users. Data consumers and data users must accept the usage restrictions and terms of usage before they can request and use the datasets [6,8]. Data sovereignty should be employed at all stages in the life cycle of a data asset, particularly where the data are exchanged. This is because data owners and data producers often relinquish control when they exchange data [6]. Due to the significance of data sovereignty, a few initiatives have emerged in Europe with the aim of establishing standards and guidelines for sovereign data exchange within data ecosystems (e.g., the International Data Spaces Association (IDSA) (https://internationaldataspaces.org/ accessed on 6 September 2026), Gaia-X (https://gaia-x.eu/about/ accessed on 6 September 2026), FIWARE (https://www.fiware.org/about-us/ accessed on 6 September 2026), Catena-X (https://catena-x.net/about-us/ accessed on 6 September 2026), etc.) [6]. Most of these large technological companies have computational capabilities and expertise, which they at times use to leverage control and unrestricted influence over the digital environment [6]. Research in the domain of digital sovereignty is still in its infancy, positioned across several issues such as organizational matters, legal principles, philosophical considerations, and technical setbacks [3]. Research that investigates how companies can abide by data protection requirements and regulatory constraints is needed to promote the development of data sovereignty [9]. Thus, this study examined the following research questions.
- RQ1: What is the state of digital sovereignty within digital platforms adopted by citizens from the European context?
- RQ2: Which key requirements influence the digital sovereignty of citizens in the context of data exchange with digital platforms?
- RQ3: How does the implementation of digital and data sovereignty support citizens in controlling data exchange and transfer in digital platforms?
Accordingly, this paper contributes to the body of knowledge by presenting qualitative findings identified from the literature and comparative policy analysis by investigating the importance of data sovereignty from the citizen’s viewpoint. This study further explored how citizens can have sovereignty over their data, enabling trusted and reliable data sharing in digital platforms. The novelty of this work is that this article contributes to the existing literature on citizens’ autonomy and rights over the digital field by discussing key requirements needed for the application of data sovereignty in the context of digital platforms that enable citizens to govern data exchange. The remainder of this article is organized as follows. Section 2 describes the methodology employed. Key findings from the literature and comparative policy analysis are presented in Section 3. The discussions and implications are presented in Section 4. Finally, Section 5 presents the conclusion, limitations, and future work.
2. Methodology
Given the focus of this study was to explore digital and data sovereignty from digital citizens’ perspectives across platform-based ecosystems, a qualitative review and comparative policy analysis [10,11,12] was employed to explore the research questions presented in the Introduction section of this paper. These approaches offer flexible methods to comprehensively examine data sovereignty from the citizens’ context, which has not yet been clearly explored in the literature.
Qualitative review is an appropriate method for identifying prior research results into practice. It can support researchers conceptualize state-of-the-art solutions [13]. To this end, published publicly available documents—peer-reviewed articles, theses, book chapters, dissertations, and policy documents—directly related to digital sovereignty and data sovereignty were searched using Web of Science, Scopus, and the Google Scholar online database. Several sources were identified using a list of keywords created for querying Web of Science, Scopus, and Google Scholar.
The keywords comprised “digital sovereignty” OR “data sovereignty” OR “self-sovereign” and “application platformization” OR “datafication” OR “digital technologies” and “citizens” OR “companies” OR “nations.” The search was stipulated from 2000 till 2025, as publications related to digitalization of societies started several decades ago. During the literature search, publicly published documents available online were searched using Google Scholar, Scopus, and Web of Science.
Furthermore, the recommendations of the Preferred Reporting Items for Systematic Reviews and Meta-Analyses (PRISMA) [12] were employed. Some items from the standard PRISMA checklist were not addressed, and only items applicable to the study area were followed. Figure 1 depicts the PRISMA source-selection flow diagram employed for selecting relevant papers.
Figure 1.
PRISMA source-selection flow diagram.
Following the process employed by Bokolo [12] using the PRISMA flow diagram, Figure 1 shows that the search retrieved 136 sources. The 136 retrieved sources were initially screened by checking the title and the abstract of each source. After a duplicate check, 7 sources were excluded as duplicates, resulting in 129 sources. After a backward and forward search using a snowballing approach, 2 more articles were included, resulting in 131 sources. Then, Google Scholar was used to retrieve the identified sources.
The inclusion and exclusion criteria were formulated to efficiently select appropriate papers, as suggested in the literature [12]. The inclusion criteria checked the scope of the selected sources to align with the research questions being examined in this study, while the exclusion criteria excluded unnecessary studies considering domain, language (if not published in English), and related subjects.
Overall, a paper or source was included (inclusion criteria) if it discussed the thematic area of digital sovereignty or data sovereignty and related initiatives, with research evidence that provided comprehensive explanations on self-sovereignty modules and strategies, as well as if the paper identified open social, legislative, or technological problems and offered future research directions.
In addition, a paper was included if it provided evidence on the thematic dimension of digital sovereignty. The publications included peer-reviewed journal articles, conference proceedings, theses, book chapters, dissertations, technical reports, and policy documents directly related to digital sovereignty and data sovereignty. Conversely, sources were excluded (exclusion criteria) if they were not published in the English language or did not contribute to the research questions being examined. Sources such as online magazines, websites, and unpublished work were excluded. Next, after checking the inclusion and exclusion criteria, 76 sources were excluded, resulting in 55 total sources (as seen in the reference list).
Furthermore, a quality assessment scheme was employed to evaluate the quality of the sources by checking citation rate (assessing the number of citations received based on Google Scholar), with a threshold rate of 3 citations since the domain of digital sovereignty is still emerging. Lastly, the accessibility and quality of findings were checked, and more than half of the selected 55 sources were indexed in Scopus and Web of Science to ensure that the selected sources were of high quality.
In the final phase, qualitative data from the selected sources were extracted and synthesized to provide discussion on the research questions being examined in the study. In this step, qualitative data from the selected 55 sources were extracted and stored on a Microsoft Excel sheet. Next, data coding was carried out using thematic analysis using descriptive analysis to qualitatively report the findings to ensure the accuracy and reliability of the secondary data. The thematization was conducted manually in Microsoft Word to present the findings seen in subsequent sections of this paper.
Using these online databases, 55 sources were finally selected, and qualitative data were extracted from these sources that provided evidence on the research questions being examined. In addition, this paper reports on a comparative policy analysis, which allows researchers to investigate and discover facts about a particular area. Comparative policy analysis helps to gain an in-depth understanding of challenges faced in real situations such as data sovereignty.
Grounded by the existing literature, this paper identifies and discusses key requirements influencing the digital and data sovereignty of citizens in the context of data exchange with digital platforms. Furthermore, this paper employs comparative policy analysis as a transdisciplinary approach to extensively investigate challenges related to digital policies related to digital sovereignty and data sovereignty in the EU and US identified from the selected sources.
3. Findings
3.1. Emergence of Digital Sovereignty in European Society
Sovereignism or sovereignty has generally been understood as the definitive governing power over a political body [14,15,16]. Bodin [17] defined sovereignty in terms of divine-fated monarchical rule for a nation. Sovereignty is a form of legitimate controlling power [18] and can be defined as the supreme authority over a polity, usually a state that holds jurisdiction over a region [19], thereby safeguarding the strategic autonomy of a nation [20]. Sovereignty entails the ability of a nation to exercise its power without interference from other entities [20]. As such, sovereignty involves independence, control, self-government, empowerment, and authority, without seeking permission [21].
From a political perspective, sovereignty is seen as a supreme, all-encompassing, non-derived, internally and externally unlimited rule over a definite territory, peculiar to the nation and its representatives [22]. From a legal perspective, sovereignty is mostly associated with the idea of a legal right to independently govern from internally (within) and non-interference from external forces (outside). As such, the current discussion on digital sovereignty involves connections with legal and political prerogatives and sociometrical strategies in sociotechnical relations in the digital transformation of society [22].
The technological focus of sovereignty started in the 1980s in topics such as data, infrastructure, digital, or cyber sovereignty [4]. Sovereignty in the digital sphere is often associated with geostrategic policies and regulation related to data circulation, digitalization [22], legitimacy, and law (de jure) to rationalize the novel exercise of power across digital spaces (de facto) [23]. In this study, several terms related to sovereignty are briefly discussed, as presented in Table 1.
Table 1.
Key terms related to sovereignty from organizational and national perspectives.
At the beginning of the 2000s, the terms described in Table 1 were used to discuss topic related to sovereignty in the digital age. The propagation of digital sovereignty started based on governments needing to attain sovereign states territorially. Since the 2010s, the need for digital sovereignty in society has increased within the political sphere. Data sovereignty has also been discussed with respect to achieving data localization and territorialization [22].
Digital sovereignty has since become more important for European Union (EU) policies, necessitating the need for control of digital infrastructure, hardware devices, standards, rules, code design, content, and data [18,24]. Digital sovereignty refers to a country’s ability to manage its digital destiny [25]. Digital sovereignty is often used to legitimize the territorial strategies employed for enforcing data flows and regulatory and/or technological standards within a geographic jurisdiction [22]. Digital sovereignty has become more than a catchphrase in the digitalization of society. It relates to several domains, such as political geography, computer science, law, and ethics [22].
In regions all over the world, such as in Europe, digital sovereignty has become essential to the EU to unlock the full potential of the data economy. The EU is now initiating more comprehensive and tighter rules over the tech sector, making Europe a leading “regulatory hub for digital sovereignty” [21]. Accordingly, the EU’s Digital Agenda 2020–2030 (https://digital-strategy.ec.europa.eu/en/policies/europes-digital-decade/ accessed on 6 September 2026) published its plans to deploy secure digital spaces and services to implement a level playing environment within digital markets with platforms that strengthen the EU’s digital sovereignty [26]. Similarly, in a report on shaping Europe’s digital future, Von der Leyen [27] defined technological sovereignty as the ability of Europe to make its own choices, grounded on its own values, respecting its own rules [27].
With this framing, the European Commission (EC) refers to technological sovereignty as a defense of European values while concurrently positioning itself to champion open, decentralized, and secure data sharing [28]. Within European digital policy, “digital sovereignty” aims to give control back to companies over infrastructures and the exertion of control over the data flows [20]. There is increasing concern that citizens are gradually losing control over their data and their ability to shape and contribute to legislation that shapes the digital landscape [29]. Therefore, across regions such as Europe, there has been growing need for newer policies and strategies designed to enhance European citizens’ strategic autonomy in the digital environment [29]. Citizens’ data-protection rights are not automatically treated as legal ownership or complete control of data. Different terms related to citizen-oriented discussion of digital sovereignty, data sovereignty, platform governance are summarized in Table 2.
Table 2.
Key terms related to citizens’ perspectives on sovereignty.
Table 2 presents the main terms related to citizen sovereignty, primarily concerning consent, control, portability, digital literacy, and self-determination, highlighting citizens’ ability to enforce restrictions after their data have been shared in digital platforms. This necessitates the need to investigate challenges faced by companies in implementing initiatives needed to ensure that digital sovereignty of citizens is preserved when they use digital platforms.
3.2. Application of Digital Sovereignty for Digital Nationalism
Government views on digital sovereignty relate to the ability of the states to reiterate their control over the internet and safeguard their citizens and businesses by stipulating regulations that govern the use of digital infrastructure within their territories as well as the data of their citizens [7]. However, with the leading position of technological companies that provide cloud services that store the data of citizens and companies, there is a need for citizens to have autonomy and control over their personal data [21]. Researchers such as Lambach and Monsees [1] mentioned that digital sovereignty is a recurrent debate about internet governance that can be traced back to the late 1990s. Digital sovereignty goes beyond a nation explicitly including the role of legal and natural people, e.g., affirming that businesses and citizens should be able to independently have control over their use of digital technology [30].
This ensures that states must protect their citizens and businesses from challenges that impact their self-determination across the digital sphere [30]. The idea of digital sovereignty originated from the traditional need of nations to exercise power and control over digital assets. As such, Floridi [31] stated that most nations struggle to govern the use of data, services, standards, software, hardware, protocols, processes, and infrastructures that underpin the digitalization of society.
In the digital era, there is a need to promote the digital rights of citizens, and this entails protecting citizens’ freedom of expression and rights to online privacy [18]. Digital sovereignty minimizes economic efficiency by promoting physical localization in computing infrastructure, inevitably fostering territoriality [19]. Digital sovereignty enhances a country’s cybersecurity and the global competitiveness of domestic businesses, thereby reducing its reliance on foreign big-tech corporations and resulting in it having more control over the digitalization of their nation. Hence, the digital transformation of societies has resulted in the need for “sovereign infrastructures and systems” [7,22].
Digital sovereignty defines forms of control, ownership, independence, and autonomy over the use of data, digital infrastructures, technologies, and digital assets [4]. It relates to technical forms of digital regulation aimed at supporting the actualization of digitally sovereign citizens, as advocated by Glasze et al. [22]. Digital sovereignty in general comprises geopolitical, economic, and social dimensions, as seen in Figure 2.
Figure 2.
Dimensions of digital sovereignty.
Economic digital sovereignty will help industries in Europe to become more globally competitive. The social dimension is supposed to safeguard European citizens’ rights, democratic systems, identities, and culture (way of life). The geopolitical dimension is focused on protecting EU values, principles, and rights against rising geopolitical threats and technological dependence in regions with narratives about rising geopolitical conflicts [1].
Findings from Basile, Borri, and Verzichelli [32]; Lambach and Monsees [1] categorize three dimensions of digital sovereignty, as illustrated in Figure 2. However, the emerging area of digital sovereignty goes beyond government control over the deployment of trusted digital infrastructure and use of data produced and stored therein. It also concerns citizens at the individual level, enabling them to regain custody, autonomy, and control over the privacy and security of their own data [21] when they use digital platforms, via usage control policies enforced to support trusted and safe data exchange [33]. For EU citizens to gain sovereign control over their digital platforms, there is a need to reevaluate policies that govern the development and execution of digital platforms [21]. European countries’ dependence on foreign cloud infrastructure and digital service providers might result in EU states complying with data requirements from other countries, and this may have different rules concerning espionage and government access to citizens’ data. This can also increase the risk of vendor lock-in, inadequate portability and interoperability of data, and applications that may threaten digital sovereignty [21].
Economic Digital Sovereignty in Europe
The digitalization of the European economy is centered on solidarity, prosperity, and sustainability, anchored in empowering its citizens and industries, ensuring the cybersecurity and resilience of its digital ecosystem [28]. This is also aligned with the European vision for 2030 (https://eur-lex.europa.eu/EN/legal-content/summary/2030-digital-decade-policy-programme.html accessed on 6 September 2026) for a digital society where no one is left behind [28]. Digital sovereignty is typically associated with economic power and the productive capabilities of nations within the digital sphere [30]. To foster economic digital sovereignty, the EU controls economic aspects of digital technologies and their underlying infrastructure. The European Economic and Social Committee (EESC) (https://www.eesc.europa.eu/en/about/ accessed on 6 September 2026) helps improve the quality of EU policies and legislation. The EESC aims to support the EU’s objective of digital sovereignty towards fostering data infrastructure, decrease reliance on non-EU businesses, and reinforce cybersecurity, supporting initiatives such as Gaia-X and the deployment of secure EU data spaces that ensure data privacy and improve the single market.
The EESC highlights competition policies, fostering data-driven innovation in strategic sectors, and ensuring that citizens benefit from digitalization while adhering to European values and human rights. As regards digital sovereignty in 2023, the EESC (https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52025SC0290/ accessed on 6 September 2026) provided a report that in its first paragraph mentioned that despite substantial efforts to improve the EU’s digital sovereignty, there is still considerable reliance on non-EU-based technological companies. These initiatives aim to meet the highest standards in line with the existing EU’s GDPR to establish privacy and data security requirements in handling data for European citizens or organizations in terms of digital sovereignty to foster innovation [21]. Another initiative is the “backbone networks for pan-European cloud federations (https://digital-strategy.ec.europa.eu/en/activities/backbone-networks-cloud-federations/ accessed on 6 September 2026),” which facilitates access to reliable infrastructures and services within Europe. This is limiting the EU’s strategic self-sufficiency in the digital sphere, limiting the EU’s economic potential and Europe’s digital sovereignty and necessitating the development of suitable European infrastructures that support the production, storage, and use of digital platforms. Accordingly, to promote digital sovereignty, the EU must reduce its dependence on external technology actors residing in the United States of America (USA) and China and strengthen its own digital infrastructure. This will increase EU control over the normative direction that digital technology is taking, as highlighted in the Parliament and Council’s Decision on the Digital Decade Policy Programme 2030 (https://eur-lex.europa.eu/EN/legal-content/summary/2030-digital-decade-policy-programme.html accessed on 6 September 2026), which in its primary objectives in Article 3 aims to promote a human-centered, fundamental rights-based, transparent, inclusive, and open digital environment. Moreover, digital infrastructure services should support interoperable and secure digital technologies and services that observe and enhance the EU’s values, principles, and rights and that are accessible to all, everywhere in the EU [30].
3.3. Digital Sovereignty in Digital Platform-Based Ecosystems
This section explores the first research question: “What is the state of digital sovereignty within digital platforms adopted by citizens from the European context?” Evidence from the literature reveals that not only governments plan to achieve digital sovereignty—this is also an aspiration of their citizens. This emphasizes the significance of individual self-determination to govern who accesses and uses their data. Thus, from the citizen’s perspective, digital sovereignty can be regarded as the ability of a citizen to take actionable decisions in a conscious, independent, and deliberate manner over the access, handling, and use of her/his data [34]. Moreover, with the widespread adoption of digital platforms across society [21], the EU seeks to promote a citizen-centric vision of the digital society and economy that empowers people in line with European values [35]. Digital platforms are used by citizen generators and collect individual data that are being collected by the platform developers by default [36].
In the EU’s opinion, in using digital platforms in society, businesses should be able to compete on equal terms and citizens should be confident that their digital rights are respected, enabling an inclusive, fair, open, and human centricity. From the EU perspective, digital sovereignty should increase trust and promote ethical use of citizens’ data on digital platforms. This aims to foster Europe’s own cloud infrastructure and data services, which are explicitly being guided by the principles of sovereignty by design that aid citizens in gaining full control over the access, processing, and storage of their data [21]. Accordingly, the use of digital platforms should benefit everyone and further improve the lives of all residents living within Europe, enabling citizens to make their own informed decisions about digital technologies and be able to choose which digital platforms they intend to use [35].
To this end, digital sovereignty is gaining increasing attention from the perspective of citizens’ control, ownership, and custody over their digital assets, exercising self-determination of their data destiny [21]. Thus, digital sovereignty is a prevalent libertarian notion that fosters self-governance and basic rights protection of individuals’ (citizens’) authority in a digitally defined ecosystem [23]. Digital sovereignty is important in the use of digital platforms, as discussions on digital sovereignty have encompassed empowering citizens, communities, and businesses to have control over their data, largely due to the rise of cloud services in society [19].
Furthermore, the importance of trust is stressed, as mentioned in the literature [2], and citizens require more digital literacy skills and digital accessibility to become more digitally self-sovereign users of digital platforms [1]. On account of the challenges to sovereignty that the use of digital platforms poses, several authoritarian initiatives are being employed to foster citizens’ self-sovereignty, such as deploying virtual borders to defend against cyber threats, data localization for the protection of citizens, and information flow control [2]. Although researchers such as Flonk et al. [37] and Roberts [2] argue that despite citizens requesting more regulations of big technological companies in terms of their digital rights, the same citizens are often apprehensive that such regulatory policies may threaten their access to free and/or appropriate services these companies offer.
As such, digital platforms cannot adequately support confidential data processing, as data analysis is usually operated by third parties who do not support transparent data access or usage even after depersonalization of citizens’ data [36]. Existing work on digital sovereignty has previously focused on exploring government and regulatory perspectives, as the government is the main authority that initiates policies that protect its citizens’ digital rights, data security, and privacy [21].
Data Sovereignty for Digital Rights of Citizens
Digitalization has made data the core of innovation across society, and this requires the sharing, exchange, and usage of data that goes beyond geopolitical, social, and economic states [31]. Thus, data are a valuable asset for digital societies and economies, as they integrally contribute to planning, policymaking, and creating novel opportunities for individuals and businesses, thereby boosting the growth of the economy [38]. Currently, big technological companies collect, harvest, and analyze data generated through the online activity of citizens that use their platforms [7,21]. At times, these “data” that are exploited by digital platforms are often sensitive and personal in nature, thus challenging the privacy and sovereignty of individuals [31,39].
In addition, the handling of sensitive and personally identifiable data can offer key insights about citizens’ digital behavior. At times, citizens’ personal data and information are often acquired and utilized by big business without the knowledge and approval of citizens who are the data owners [21]. Therefore, there is a growing need for regulations, rules, and policy direction on how data should be leveraged in a way that is beneficial to citizens [38]. With an ever-greater volume of citizens’ data collected, processed, and stored in the cloud, data sovereignty has become significant for governments around the world [40]. Data sovereignty is a subset of digital sovereignty that is grounded in the idea that the use of data should be subjected to the regulations and rules of the nation(s) where the data are generated or collected [8,40].
Data sovereignty contributes to developing a safe digital environment where data owners/data providers and data consumers/data users overcome trust issues faced while sharing data. Practically speaking, data sovereignty has primarily become important in achieving digital sovereignty, as its implementation strengthens individuals to decide on the exploitation of their data as an economic asset, thus fostering a data ecosystem wherein data owners and data providers can govern the use of their data [8,41]. Data sovereignty is based on the idea that the exchange of data is subject to the laws and governance structures of the nation where such data are collected [7,21].
Moreover, citizens’ data are usually stored in data centers and cloud solutions that are not based on where the data are collected, resulting in a data residency challenge [8], since the saved data are treated based on the jurisdiction and rules where the data center is located [40]. Also, when digital platforms are used, their content should be safe from harmful and illegal content, citizens’ privacy and personal data should be safeguarded, and diversity and multilingualism should be considered. There should be mechanisms that protect children and young people while enabling them to make safe and informed choices in the digital environment [35].
Given the prominence of handling citizens and organizational data according to sovereignty principles, policymakers in the EU are initiating policies that promote fair access to and use of data [26]. Existing legislation as part of the European Strategy for Data, such as the Data Act, Data and Governance Act, and the GDPR, stipulates the need for data protection of different stakeholders [7,8].
There is a need to further improve citizens’ digital rights when using digital platforms to protect their autonomy, privacy, and data security in sharing and reusing personal data [4]. The empowering of individuals to have complete control over their data, including autonomy on what information to share and with whom such data should be shared, is important [21]. In other words, citizens should have the right to decide the destination of their data and how the data can be used or handled on digital platforms [7,21]. Citizens should have independent control to authorize, access, or possess the ability to control the level of access, ownership, and usage of their data, alongside policies on data disclosure [8,21,39].
As mentioned by Floridi [31], digital platforms generate data that are locally stored within a particular jurisdiction and are entirely subject to the laws of the country where the data are stored. There are fundamental issues to be addressed regarding how citizens’ data are gathered, used, and reused by digital platforms [36]. Additionally, the use of digital platforms is faced with challenges of defining ownership between data subjects (e.g., data providers, data owners, data users, and data consumers), control enforcement, and compliance demands [42]. Thus, there is a need for digital platforms that provide data owners and data producers trustworthy guarantees of safe and reliable data handling within available data ecosystems [33].
In the business context, different data types, such as structured and live-streamed data, used by technological companies are faced with technical challenges such as enforcing control mechanisms and adhering to government-specified compliance [42]. These companies struggle to maintain control and define ownership, often due to expertise and resource constraints [42]. For citizens to have sovereignty over their data, there is a need for citizens to control and manage what data they share and which destinations and for which purpose their data are being used [36].
3.4. Digital Sovereignty of Citizens in Digital Platforms
The focus of this section is to examine research question 2: “Which key requirements influence the digital sovereignty of citizens in the context of data exchange with digital platforms?” Although governments and other stakeholders recognize that digital sovereignty is crucial for controlling the data of organizations and citizens, the term “data sovereignty” is often not understood by all actors [4]. For citizens, this is because of technical implementation such as initiating usage policies and setting ownership rights needed to achieve data sovereignty when sharing data [7,43]. Likewise, for organizations, finding a solution for ensuring data protection and complying with policies such as the GDPR and privacy by design (https://www.edps.europa.eu/data-protection/our-work/subjects/privacy-design_en?page=5/ accessed on 6 September 2026) in the use of citizens’ data remains a challenge [4,44,45,46]. Accordingly, this section discusses key requirements that influence the data sovereignty of citizens in the context of data exchange, as shown in Figure 3.
Figure 3.
Key requirements that influence the digital sovereignty of citizens [6,7,8,18,29,30,33,44,45,46,47,48].
Figure 3 depicts the key requirements that influence the digital sovereignty of citizens in the context of data exchange with digital platforms. Each of these requirements (technical, legal–institutional, individual, infrastructural, and cross-cutting dimensions) are derived from the literature [6,7,8,18,29,30,33,44,45,46,47,48] and further discussed below.
3.4.1. Usage Controls
Usage controls are mechanisms initiated for restricting the use of data assets after usage access has been granted. Usage control aims to define and enforce restrictions on the use of data assets by enabling citizens as data owners to apply constraints via usage policies, thereby ensuring that data are processed, aggregated, stored, and shared according to specific constraints [6]. Usage control mechanisms can grant specific rights for using data, thereby enforcing certain rules to be adhered to when citizens’ data are being processed, exploited, and shared. Such a rule could, for example, be a consent to use datasets for one month, with the obligation to delete them after the agreed time [8,33].
Usage control is an important requirement for actualizing data sovereignty for citizens, as it helps to establish and enforce restrictions needed on data exchange on digital platforms. To initiate usage control mechanisms, existing policy language such as open digital rights language (ODRL), which is a W3C-standardized policy language, can be employed for digital rights management. In so doing, ODRL can be employed to enable citizens and digital platform operators to specify and communicate data access and usage conditions in a standardized fashion [33]. Also, usage control can be achieved by enforcing single usage control standards, such as JavaScript object notation (JSON) for data format or hypertext transfer protocol secure (HTTPS) for secure communication. Also, security-by-design principles can be adopted for policy enforcement from the ground up [6].
3.4.2. Access Control
Access control is a procedure deployed to regulate which entities within a digital platform are allowed to access certain data. It is an underlying data security mechanism that decreases the risk of unauthorized data access [6]. To foster data sovereignty, there is a need to deploy access control policies or restrictions by citizens as data owners or data providers to prevent data theft, breaches, or misuse of personal data. Citizens set “access policies” as set of requirements that administers who can access their data assets [8].
To enforce access control in digital platforms, an identity management service is needed to verify the identity of specific users who access data using schemes such as multifactor authentication and privilege and credential checks, which are employed to grant permissions to users [6]. Likewise, fine-grained access control can be adopted that enables citizens as data owners to limit the actors they are willing to share their data with. However, as pointed out in the literature [33], more than “access control” is needed, as digital sovereignty would end after data flow from citizens to other entities following access being granted.
3.4.3. Legality
In enabling data exchange within digital platforms, the transfer of data should always be associated with a legal contractual agreement, especially if it involves commercial data requiring payment to be made [7]. Legal contracts equip all actors with the medium to establish credibility with one another. Such contracts regulate the data usage conditions and terms, e.g., regarding economic compensation or a penalty for actors who breach contract [33]. The legal contractual agreement can be translated into machine-readable policies that grant explicit permission on the shared dataset alongside associated obligations [8,33].
Also, there may be national and international legal requirements and legislation that may restrict the transfer of data, for example, if data are to be exchanged within the EU, the GDPR, data acts, among others, which must be observed. In addition, these legal rules need to be integrated within digital platforms so that access control and usage control procedures can be governed, enforced, and made clear to citizens. However, as each nation has its own data usage and exchange policies, citizens on the consuming side often become affected via these legal contracts [6].
3.4.4. Regulations and Standards
Regulations determine the conditions for how citizens’ data are collected, processed, saved, and shared, and are essential for the provision of digital platforms. Regulations can either be “inter-“ as national legislation and “multi-“ as international and global legislation, which at times are not always aligned or compatible. This is because national legislation regulates how digital services can function for citizens in a particular nation, while international legislation comprises cross-border regulations that are applicable to a larger geographic extent, such as the GDPR in Europe [45].
Regulations stipulate the minimal obligatory conditions and steps digital platform service providers must ensure in using citizens’ data. This also helps to regulate citizens’ access to information by ensuring data transparency [45]. Furthermore, the adoption of open standardized interfaces is of utmost importance to enable future citizen-centric platforms and further avoid vendor lock-in with respect to data accessibility, provisioning, and exchange [47].
3.4.5. Self-Determination
Self-determination, also termed self-regulation, is defined as the ability of citizens to understand the basics of location privacy settings and protection when using digital platforms. This is a requirement to perform informed and privacy-aware management as related to citizens’ personal location information [45]. Self-determination is important, as most citizens lack the skills and knowledge on how best to equip safe disable/enable location privacy protection, in particular enhanced privacy awareness. Addressing this requirement will give citizens self-sovereignty to access the information required to make informed decisions about information sharing of their personal location [45].
3.4.6. Digital Literacy
Digital literacy refers to the medium of exercising digital empowerment. Going beyond understanding how to use digital platforms is important to support citizen data sovereignty. Digital literacy is centered on establishing community spaces for collective learning to enable citizens to participate in digital political discussion on the black box of technology and data politics [18]. This is important, as citizens must have a clear understanding of what digital and data sovereignty entails, and how it affects society.
This is true for regulators at national and regional level (EU and US) that initiate digital policies, but it is also important for citizens, who should be able to express their opinion of the digital future they envisage for society. Importantly, digital literacy extends beyond digital skills, but also relates to citizens’ ability to understand possible adverse effects of digitalization on individuals and society [30].
3.4.7. Data Security
Data security is important for digital platforms used by citizens when sensitive and confidential data are exchanged [44]. Ensuring secure data exchange entails protecting data confidentiality, availability, and integrity (authenticity) [33]. As such, data security has become more difficult to achieve in digital platforms. Thus, there is a need to implement data security mechanisms such as data storage encryption and transport layer security (TLS) that can be deployed in executing data exchange [33]. Data security also comprises deploying authentication and authorization schemes that enable secure communication and certification services during data exchange.
Before exchanging data, citizens intend to know who they are exchanging data with and if they can trust the other actors [45]. Authentication and authorization schemes foster a trusted data sharing execution environment for deploying digital platforms [46]. Authentication and authorization comprise employing cryptographic mechanisms that protect data by providing in-use data security including, for instance, homomorphic encryption, hardware-assisted security, and obfuscation techniques (deidentification, pseudonymization, aggregation, differential privacy, anonymization, etc.) [6].
In addition, security risks affecting artificial intelligence (AI)-enabled digital platforms, including adversarial perturbations, data poisoning, and model-inversion attacks, need to be considered. This is because explainable AI may support the identification of such vulnerabilities and improve the transparency, robustness, and trustworthiness of machine learning-based platforms [48].
3.4.8. Data Location
Another relevant requirement relates to the location where citizens’ data are stored and where the infrastructure and servers are physically stationed or located, particularly for cross-border data exchange [6]. For digital sovereignty, citizens (in this case, data owners or data providers) should be able to know the location of servers or cloud solution where their data are stored. This will ensure that digital platform providers are complying with applicable regulations, such as the GDPR [7]. Also, citizens should have the liberty to choose which cloud solution to save their data, as long as the physical locations of the servers are transparently shared by the digital [6].
3.4.9. Trustworthiness
The EU is seeking to ensure trust and transparency in data sharing ecosystems across the EU. One of the challenges for the EU is centered on ensuring that digital products and services are trustworthy, in line with EU principles and values, and well regulated even if they are owned by foreign companies [29] to uphold digital sovereignty and ensure that data do not end at the point of data exchange, and all entities exchanging data adhere to existing policies. Digital platforms and data ecosystem need to be equipped with a means to identify each participant (e.g., citizens, businesses, etc.) and further establish a common framework for mutual trust decisions [33].
3.4.10. Data Quality
The quality of the data should be ensured to support a data-driven digital platform. Data quality mainly includes the correctness, the timeliness, and the machine-readability of the data. However, data quality criteria may differ depending on the data type [47]. In the context of this study, this relates to data collected from digital platforms used by citizens.
3.5. Findings on Comparative Policy Analysis
This section investigates research question 3: “How does the implementation of digital and data sovereignty support citizens in controlling data exchange and transfer in digital platforms?” Accordingly, this section presents comparative policy analysis exploring how the implementation of digital sovereignty in the EU and US supports citizens in controlling data exchange and transfer across digital platforms.
3.5.1. Digital Sovereignty of Citizens in the EU
Across the European sphere, much of the rationale underlying the actualization of digital sovereignty in the EU is centered on the need to preserve European principles, rights, and values. European data are largely analyzed, processed, and stored outside the EU, thus necessitating significant concerns for the loss of control over personal and sensitive identifiable data [19]. As such, over the years EU legislation has become more restraining after Edward Snowden’s revelations in 2013 (when Snowden disclosed the global measure of digital surveillance), complemented by emerging threats such as lack of responsibility for illegal content, abuse of dominant market leaders, and digital fraud [19]. Another instance concerns the EU’s critique of Chinese court rulings that prevent European corporations from protecting their intellectual property (IP) rights for technological innovations [49]. These conflicts show the intrinsic link between geopolitical and economic digital sovereignty, as they are mainly influenced by the differences in the core societal value systems [30].
This has necessitated the need to safeguard the fundamental rights of citizens to data security and privacy vis-à-vis across nations and particularly from private companies [19,22]. To promote digital sovereignty, the EC is currently considering initiating a ban that limits European organizations from developing certain sensitive technologies abroad, just as they concurrently urge EU member states to prohibit certain foreign corporations from contributing in their 5G telecom networks due to data security concerns [30]. Bradford [50] highlighted how the “Brussels effects” specified that the EU became a normative standard for data protection contained using the GDPR (https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng/ accessed on 6 September 2026) as a market power, which is now being adopted with policies that aim to develop a common data market in Europe (https://digital-strategy.ec.europa.eu/en/library/european-data-market-study-2024-2026/ accessed on 6 September 2026) to spur digital innovation [38].
The GDPR, for instance, stipulated key safeguards preventing individuals’ data trafficking [30]. However, in comparison to the GDPR, the emerging field of digital sovereignty is not merely focused on data or citizens’ protection rights but also on technological and geoeconomic developments. The need for digital sovereignty has emerged due to responses to cyber threats, emerging national tech-trade war, and an increase in reliance on foreign cloud infrastructure [19].
In addition, the European response to fostering sovereignty driven by the politics of digital control has led to the deployment of initiatives such as the Digital Europe Programme (DIGITAL), (https://digital-strategy.ec.europa.eu/en/activities/digital-programme/ accessed on 6 September 2026) which aims to reinforce Europe’s digital sovereignty by promoting the development of European digital capabilities and infrastructures. This contributes to improving the technological sovereignty of the EU to minimize its dependance on foreign digital infrastructure providers [51]. Another initiative is the European Strategy for Data, (https://digital-strategy.ec.europa.eu/en/policies/strategy-data/ accessed on 6 September 2026) which has led to programs such as the International Data Spaces Association (IDSA), FIWARE, and Gaia-X, Simpl (https://digital-strategy.ec.europa.eu/en/policies/simpl/ accessed on 6 September 2026), DSSC (https://dssc.eu/space/Partners/175472674/ accessed on 6 September 2026), etc., which emphasize data sovereignty [42].
Policies related to digital sovereignty have become crucial due to the issues related to sovereign data sharing for governing usage control among participants within data ecosystems [33,43]. This necessitates the need to revise and adapt existing economic, legal, and regulatory policies such as the GDPR, data acts, (https://digital-strategy.ec.europa.eu/en/policies/data-act/ accessed on 6 September 2026) data governance acts, (https://digital-strategy.ec.europa.eu/en/policies/data-governance-act/ accessed on 6 September 2026) AI acts, (https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai/ accessed on 6 September 2026) etc., that actively promote European values and principles within areas such as digital rights, cybersecurity, data protection, and ethically designed AI systems [29].
3.5.2. Digital Sovereignty of Citizens Within EU–US Digital Policies
The EU emphasizes digital and data sovereignty for citizens, emphasizing underlying values such as respect for human rights, democracy, human dignity, equality, freedom, and the rule of law [26,28]. The EU’s approach to digital sovereignty focuses on upholding individual rights, in contrast to the state-centered approaches adopted in other regions in the world. As such, the EU intends to be a pioneer in creating global standards and norms in the regulation and standardization of digital technologies. But presently, prevailing tension between government objectives across nations regarding control over data flows and the cross-border exchange of data echoes debates over the possibility of achieving digital sovereignty that enables the governance of the digital sphere under the aegis of countries, thereby empowering citizens to have control over their data [40]. As several United States (US) technological companies operate internationally, the US government is mostly unconcerned about the regional storage of citizens’ data, as it still could exercise control over these corporations. One of the popular cases related to digital sovereignty dates back to 2013, where Microsoft challenged the digital influence of the US government based on the Stored Communications Act (SCA) (https://www.congress.gov/crs-product/LSB10801/ accessed on 6 September 2026) to access data stored on servers located in Ireland.
In this case, Microsoft disputed that the US government had no sovereign autonomy on foreign territory (Microsoft Ireland against US) [38]. The US government contended that it possessed extraterritorial authorities in terms of the SCA and could direct any US-based digital service provider to access their data irrespective of where the data were located. In response to the legal complications of this case, the US Congress later passed the Clarifying Lawful Overseas Use of Data (CLOUD) Act (https://www.justice.gov/criminal/cloud-act-resources/ accessed on 6 September 2026). The CLOUD Act 2018 authorizes US law enforcement agencies to demand access to data held by US firms abroad.
This implies that due to the principal position of US technological companies, the US can exercise its digital sovereignty powers, such as criminal investigations, even beyond its territory [38]. Furthermore, over the years, bilateral policies in the US have resulted in multiple rounds of dialogue over EU–US cross-border data sharing or transfers. For instance, the EU–US Data Privacy Framework (EU–US DPF) (https://www.dataprivacyframework.gov/Program-Overview/ accessed on 6 September 2026) was initiated for managing data transfers between the EU and the US. The identified digital sovereignty initiatives (policies, laws, programs, infrastructures, private initiatives, and academic concepts) within the EU and US that are applicable to citizens are shown in Figure 4.
Figure 4.
Digital sovereignty initiatives that apply to citizens within the EU–US.
Although this initiative was contested by privacy activist Max Schrems at the Court of Justice of the European Union (CJEU) (https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62014CJ0362/ accessed on 6 September 2026) and successively invalidated in 2020 (Schrems II), (https://curia.europa.eu/jcms/upload/docs/application/pdf/2020-07/cp200091en.pdf/ accessed on 6 September 2026) the EU’s recent adequacy decision for the US might be opposed before the CJEU. Thus, the US government executed its sovereignty over data and digital infrastructures by initiating laws that empower US authorities to compel digital service providers to disclose either citizen or business data. From the US perspective, data sovereignty goes beyond having power over data residing within its physical borders, and extends to exercising citizens’ autonomy over data remotely hosted and stored on cloud servers in other regions if the cloud service provider is a US-based company.
This autonomy can keep digital service providers in a position where they are in compliance or dispute due to conflict of data usage laws between different jurisdictions, and this has major implications for the sovereignty of other states and regions [38]. Figure 4 depicts relevant policies and legislations initiated to uphold digital and data sovereignty in the EU and US. The open data movement at times creates additional demands, but fails to recognize that citizens are rights holders, not mainly stakeholders, with the right to control ownership of their data as they see fit [52].
In essence, there is a need for effective digital governance policies in the EU and US that do not undermine digital sovereignty. For example, it is not sufficient for the EU and US to adopt the polices presented in Figure 4 within the digital sphere, but it is important that these policies are evidence-based, robust, and capable of steering digital and data sovereignty in a direction that aligns with human rights, the rule of law, and democracy [30].
4. Discussions and Implications
4.1. Discussion
Debate on digital and data sovereignty has seen an increase over the years due to advances in access to the internet and technological development, coupled with the digital transformation of society and economy [21,53]. Digital sovereignty refers to the ability of nations to shape the direction of digitalization in a self-determined approach regarding software, hardware, services, and skills [21]. Strengthening digital sovereignty is initiated to guarantee digital rights and to maintain control and autonomy over a state’s digital destiny [30]. As citizens adopt digital platforms, issues related to data autonomy, ownership, and privacy have become more complex. Issues have arisen, such as where citizens’ data reside, who owns them, and what rules and regulations citizen data should be subject to, etc. All these become important considerations for companies in compliance with the regulations of the nation in which their digital services are provided [21].
This has necessitated the need for the topic of digital sovereignty, which refers to the need for control and autonomy of digital infrastructure and systems [37]. Nonetheless, data should also be regulated by policies specific to the nation from which the data originates [21]. For citizens, being digitally sovereign entails making sovereign decisions about the use of digital platforms in which autonomy is desired or necessary in line with applicable jurisdiction and laws [7]. Thus, researchers such as Blancato [40] advocated that digital sovereignty can be seen as related to polity associated with high standards for data protection, which ensures compliance and interoperability with a range of protections in cloud services.
On the other hand, data sovereignty, a part of digital sovereignty, has been associated with how data owners and data producers can administer policies that support achieving ownership and control of their data and autonomy in how to use such data [7,8]. Similarly, in citizens’ use of digital platforms, data sovereignty is often intently interpreted as data owners and data providers’ ability to have full control over their shared data assets [42]. Therefore, grounded on a qualitative review and comparative policy analysis, this study investigated the importance of data sovereignty from citizens’ viewpoints by investigating how citizens can have sovereignty over their data, enabling trusted and reliable data sharing on digital platforms.
Findings from this study exploring the state of digital sovereignty within digital platforms adopted by citizens from the European context suggest that not only do governments plan to achieve digital sovereignty, but that it is also the aspiration of their citizens to have autonomy and control over how their data collected by digital platforms are being used by companies without explicit consent, and having control, portability, digital literacy, and self-determination. This result highlights the need for citizens to enforce restrictions after their data have been shared on digital platforms.
Although governments and other stakeholders recognize that digital sovereignty is crucial for controlling the data of organizations and citizens, the term “data sovereignty” is often not understood by actors. Therefore, this study investigated key requirements that influence the digital sovereignty of citizens in the context of data exchange with digital platforms. Additionally, findings from this study show how the implementation of digital and data sovereignty support citizens in controlling data exchange and transfer on digital platforms by presenting comparative policy analysis exploring how the implementation of digital sovereignty in the EU and US supports citizens in controlling data exchange and transfer across digital platforms.
This article contributes to the existing literature on citizens’ autonomy and rights over the digital field by discussing key requirements needed for the application of data sovereignty in the context of digital platforms that enable citizens to govern data exchange. Findings from this study provide evidence on the key requirements that need to be addressed for citizens to have self-sovereignty in the digital age. Furthermore, this study provides evidence from the two comparative policy analyses on the implementation of digital and data sovereignty in the EU and US to support citizens in controlling data exchange and transfer across digital platforms.
Total autonomy and control denote the ability to influence and inhibit the design, manufacturing, use, and output of digital technologies with legal obligations and legislative regulation [54]. This finding is analogous to results from Martin et al. [23], where the authors mentioned that digital sovereignty has focused not just on government power, but on the logic of correspondent jurisdiction across digital spaces [23]. Moreover, findings from this study reveal that the EU has made several efforts to promote both digital and data sovereignty by initiating regulations, laws, programs, infrastructures, and private initiatives, as seen in Figure 4.
A regularly cited regulation in promoting digital sovereignty is the European GDPR, which protects and grants privacy rights to residents located in the EU when their private data are processed and used by non-EU companies that provide goods or services to EU residents [21]. As such, within the EU digital sovereignty is beyond taking back control of data. It is part of a larger geopolitical agenda, positioning the EU as an economic rival of other predominant counties such as the United States and China, thereby obtaining power and authority in line with EU democratic values, principles, and rights [1,19].
Additionally, to promote the digital rights of citizens, there is a need to shift towards more democratic, defensive, and prudential policies, including new regulations that address the digital influence of foreign state ownership and large technological companies’ operations, towards promoting technological autonomy and thereafter digital sovereignty [29] to limit the influence of big technological companies such as Apple, Amazon, Google, Meta, Alibaba, Tencent, and Microsoft. In most regions of the world, there have been occasions where most digital platforms are banned or blocked from use in order to uphold the digital sovereignty of citizens.
Such political policies can be seen as a threat to digital sovereignty, as such policies may not be sufficient as a long-term solution that safeguards citizens and their personal data. Such policies are initiated in broader geopolitical attempts to maintain and assert international dominance and power over the internet [55]. Moreover, ensuring trust and transparency for citizens when they use digital platforms has become the hallmark of the EU policies [29]. Against this background, the EU has proposed initiatives at EU level to accelerate societal digitalization, in particular setting up a trustworthy, secure, and reliable digital environment such as the common European data spaces, (https://digital-strategy.ec.europa.eu/en/policies/data-spaces/ accessed on 6 September 2026) to achieve a single market for data towards harnessing the value of data for the benefit of European society and the economy.
4.2. Implications for Policy, Research, and Practice
Over the decades, there has been the need to manage and govern data in a way that is consistent with state legislation, rules, practices, and customs of the nation where the data are located. This has been one of the foci of the EU as citizens aim to control the collection, ownership, and application of their personal data (whether collected by state government themselves, digital platform providers, or external third-party data providers) [51]. Data sovereignty thus aims to ameliorate challenges associated with processing, analyzing, storing, and sharing data. This article explores how to support citizens paving the way for further policy development in controlling data exchange and transfer in digital platforms. More specifically, contributions from this study are threefold. First, this study makes a principal contribution to existing digital politics literature, particularly in research streams related to data sovereignty in platform-based ecosystems from digital citizens’ perspectives by examining the state of digital sovereignty within digital platforms adopted by citizens in the European context.
This study’s novelty is that key findings identify the key requirements that influence the data sovereignty of citizens in the context of data exchange with digital platforms, with key requirements that can help companies to technically implement policies in building sovereign data sharing ecosystems for digital platforms used by citizens and other stakeholders in strengthening data sovereignty in line with existing EU and US regulations. Likewise, the findings provide insights for policymakers, highlighting key requirements that influence data sovereignty, and in so doing potentially enhance usage control and access control policies.
As sovereignty in the digital landscape is receiving increased scholarly and policy attention, it is necessary to explore digital policies for sovereign data control, ownership, and compliance. These identified digital sovereignty initiatives (Figure 4) will inform researchers, practitioners, decision-makers, and governments on what to consider in their conceptualizations and drafting of digital policies related to citizens’ self-sovereignty. Findings from this study contribute to the prior literature by laying the base for further research, as well as presenting dimensions of digital sovereignty that comprise geopolitical, economic, and social dimensions. The presented digital sovereignty dimensions offer a new approach to understanding digital sovereignty’s implementation.
Furthermore, evidence from this study provides direct implications for practice, guiding and providing a mutual understanding of digital sovereignty concept for citizens and companies. This can support individuals and businesses to develop digital technologies that implement data sovereignty by design for all data life-cycle stages, in line with European values, principles, and rights. Finally, evidence from the comparative policy analysis provides a review of policies, legislation, laws, programs, infrastructures, and private initiatives (as seen in Figure 4) related to digital sovereignty in the EU and US, highlighting the future of digital policy. The comparative policy analysis also reveals that there is no “one size fits all” policy for digital sovereignty for all nations.
Each state has its own unique geopolitical, economic, and social factors, as well as technological capabilities that consequently shape its national priorities and digital foreign policies. At the same time, some nations may not have clear approaches to fostering digital sovereignty. As such, the findings from this study can serve as a guideline for these nations to operationalize self-sovereign policies related to regional and cross-border data exchange. This provides policy recommendations for developing nations to navigate the differences among developed countries while respecting the individual sovereignty of each country.
5. Conclusions
Digital sovereignty is an important theme in the debate on governing the fast-changing digital technologies. Digital sovereignty has become a profound political question regarding government legitimacy in balancing power among stakeholders. This growing influence of digitalization and digital platforms has increased the intricacy of dependence for nations and contributed to the emergence and need for digital and data sovereignty. Therefore, this article explores how digital sovereignty can be achieved by digital platforms provided by public authorities and what policies should be put in place to re-enforce the digital rights of citizens.
This study explored the state of digital sovereignty within digital platforms adopted by citizens from the European context, and identifies key requirements influence digital sovereignty of citizens in the context of data exchange with digital platforms. Also, this study explored how the implementation of digital and data sovereignty supports citizens in controlling data exchange and transfer in digital platforms. More importantly, findings from this study provide guidelines on data sovereignty requirements grounded on data from literature reviews and comparative policy analysis of EU–US digital initiatives to identify and aggregate policies aimed at providing a common understanding of digital and data sovereignty. This article discusses the emergence of digital sovereignty in European society, application of digital sovereignty for digital nationalism, digital sovereignty in digital platform-based ecosystems, data sovereignty for digital rights of citizens, and key requirements that influence the data sovereignty of citizens.
Limitations and Future Work
These findings derive mainly from heterogeneous secondary sources. As such, this may not provide sufficient evidence on the implementation of digital and data sovereignty. Also, there is possible selection bias and limited citizen-level evidence. Most of the findings are mostly EU-centric. There are some imbalances in the comparative policy analysis due to the rapidly changing regulatory environment. Findings from this study are mostly qualitative in nature and grounded in secondary data.
Future studies will employ quantitative approaches to obtain further insights and evidence on how data sovereignty can be achieved across platform-based ecosystems from digital citizens’ perspectives. Also, future research can also examine how digital and data sovereignty is being underpinned by geopolitical, economic, and social dimensions. Additionally, future research can explore to what extent digital literacy shifts some responsibility toward the citizen. This will contribute to examining whether citizens understand how digital platforms collect, process, transfer, and monetize their data in relation to data access, portability, usage restrictions, decision rights, jurisdiction, ownership, and consent, and their formal rights and capacity to exercise those rights when it comes to how their information is being used.
Funding
This research received no external funding.
Institutional Review Board Statement
Not applicable.
Informed Consent Statement
Not applicable.
Data Availability Statement
No new data were created or analyzed in this study. Data sharing is not applicable to this article.
Acknowledgments
The author is thankful to the Institute for Energy Technology, Halden, Norway, for providing the resources needed to draft this manuscript.
Conflicts of Interest
The author declares no conflicts of interest.
References
- Lambach, D.; Monsees, L. Beyond sovereignty as authority: The multiplicity of European approaches to digital sovereignty. Glob. Political Econ. 2024, 4, 71–88. [Google Scholar] [CrossRef] [Scilit]
- Roberts, H. Digital Sovereignty: A Normative Approach. 2024. Available online: https://papers.ssrn.com/sol3/papers.cfm?Abstract_id=4699167 (accessed on 6 September 2026).
- Paulsson, A.; Fred, M. Making apps, owning data: Digital sovereignty and public authorities’ arrangements to “byte” back. Organization 2024, 32, 1103–1121. [Google Scholar] [CrossRef] [Scilit]
- von Scherenberg, F.; Hellmeier, M.; Otto, B. Data sovereignty in information systems. Electron. Mark. 2024, 34, 15. [Google Scholar] [CrossRef] [Scilit]
- Ganz, A.; Camellini, M.; Hine, E.; Novelli, C.; Roberts, H.; Floridi, L. Submarine cables and the risks to digital sovereignty. Minds Mach. 2024, 34, 31. [Google Scholar] [CrossRef] [Scilit]
- Biehs, S.; Stilling, J. Identification of Key Requirements for the Application of Data Sovereignty in the Context of Data Exchange. In Proceedings of the Hawaii International Conference on System Sciences 2024 (HICSS-57), Honolulu, HI, USA, 3–6 January 2024; Volume 3. Available online: https://aisel.aisnet.org/hicss-57/in/data_ecosystems/3 (accessed on 6 September 2026).
- Bokolo, A.J. Implementing Digital Sovereignty to Accelerate Smarter Mobility Solutions in Local Communities. Smart Cities 2025, 8, 106. [Google Scholar] [CrossRef] [Scilit]
- Bokolo, A.J.; Sarshar, S. Enhancing data sovereignty to improve intelligent mobility services in smart cities. Urban Gov. 2025, 5, 20–31. [Google Scholar] [CrossRef] [Scilit]
- Kokas, A. Trafficking Data: How China Is Winning the Battle for Digital Sovereignty; Oxford University Press: New York, NY, USA, 2022; p. 288. ISBN 9780197620502. [Google Scholar]
- Dixon-Woods, M.; Bonas, S.; Booth, A.; Jones, D.R.; Miller, T.; Sutton, A.J.; Shaw, R.L.; Smith, J.A.; Young, B. How can systematic reviews incorporate qualitative research? A critical perspective. Qual. Res. 2006, 6, 27–44. [Google Scholar] [CrossRef] [Scilit]
- Barnett-Page, E.; Thomas, J. Methods for the synthesis of qualitative research: A critical review. BMC Med. Res. Methodol. 2009, 9, 59. [Google Scholar] [CrossRef] [Scilit]
- Bokolo, A.J. Implications of telehealth and digital care solutions during COVID-19 pandemic: A qualitative literature review. Inform. Health Soc. Care 2021, 46, 68–83. [Google Scholar] [CrossRef] [Scilit]
- Pan, M.L. Preparing Literature Reviews: Qualitative and Quantitative Approaches; Routledge: London, UK, 2016. [Google Scholar]
- Lehuedé, S. An alternative planetary future? Digital sovereignty frameworks and the decolonial option. Big Data Soc. 2024, 11, 20539517231221778. [Google Scholar] [CrossRef] [Scilit]
- Timmers, P. Sovereignty in the Digital Age; Werthner, H., Ghezzi, C., Kramer, J., Nida-Rümelin, J., Nuseibeh, B., Prem, E.M., Eds.; Springer: Cham, Switzerland, 2024; p. 571. [Google Scholar]
- Hinsley, F.H. Sovereignty, 2nd ed.; Cambridge University Press: Cambridge, UK, 1986. [Google Scholar]
- Bodin, J.; Frémont, C.; Couzinet, M.D.; Rochais, H. The Six Books of the Republic; Chez Iacques du Puys: Paris, France, 1986; Volume 6. [Google Scholar]
- Pierri, P.; Calderón Lüning, E. A Democratic Approach to Digital Rights: Comparing perspectives on digital sovereignty on city level. Int. J. Commun. 2023, 17, 3600–3618. [Google Scholar]
- Adler-Nissen, R.; Eggeling, K.A. The Discursive Struggle for Digital Sovereignty: Security, Economy Rights and the Cloud Project Gaia-X. JCMS J. Common Mark. Stud. 2024, 62, 993–1011. [Google Scholar] [CrossRef] [Scilit]
- Gordon, G. Digital sovereignty, digital infrastructures, and quantum horizons. AI Soc. 2024, 39, 125–137. [Google Scholar] [CrossRef] [Scilit]
- Tan, K.L.; Chi, C.H.; Lam, K.Y. Survey on digital sovereignty and identity: From digitization to digitalization. ACM Comput. Surv. 2023, 56, 1–36. [Google Scholar] [CrossRef] [Scilit]
- Glasze, G.; Cattaruzza, A.; Douzet, F.; Dammann, F.; Bertran, M.G.; Bômont, C.; Braun, M.; Danet, D.; Desforges, A.; Géry, A.; et al. Contested spatialities of digital sovereignty. Geopolitics 2023, 28, 919–958. [Google Scholar] [CrossRef] [Scilit]
- Martin, A.; Sharma, G.; Peter de Souza, S.; Taylor, L.; van Eerd, B.; McDonald, S.M.; Marelli, M.; Cheesman, M.; Scheel, S.; Dijstelbloem, H. Digitisation and sovereignty in humanitarian space: Technologies, territories and tensions. Geopolitics 2023, 28, 1362–1397. [Google Scholar] [CrossRef] [Scilit]
- Mügge, D. EU AI sovereignty: For whom, to what end, and to whose benefit? J. Eur. Public Policy 2024, 31, 2200–2225. [Google Scholar] [CrossRef] [Scilit]
- Larsen, B.C. The Geopolitics of AI and the Rise of Digital Sovereignty. 2022. Available online: https://policycommons.net/artifacts/4140902/the-geopolitics-of-ai-and-the-rise-of-digital-sovereignty/4949615/ (accessed on 6 September 2026).
- European Commission. Proposal for a Regulation of the European Parliament and of the Council on Harmonised Rules on Fair Access to and Use of Data (Data Act) (COM/2022/68 Final). 2022. Available online: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52022PC0068 (accessed on 12 December 2023).
- Von der Leyen, U. (Ed.) Shaping Europe’s Digital Future; European Commission: Luxembourg, 2020; Available online: https://ec.europa.eu/commission/presscorner/detail/en/ac_20_260 (accessed on 6 September 2026).
- European Commission. 2030 Digital Compass: The European Way for the Digital Decade. In COM(2021) 118 Final, Brussels. 2021. Available online: https://eur-lex.europa.eu/legal-content/en/TXT/?uri=CELEX%3A52021DC0118 (accessed on 6 September 2026).
- Madiega, T. Digital Sovereignty for Europe--European Parliament-BRIEFING EPRS Ideas Paper Towards a More Resilient EU. 2020. Available online: https://www.europarl.europa.eu/RegData/etudes/BRIE/2020/651992/EPRS_BRI(2020)651992_EN.pdf (accessed on 6 September 2026).
- Smuha, N.A. Digital sovereignty in the european union: Five challenges from a normative perspective. In European Sovereignty: The Legal Dimension—A Union in Control of Its Own Destiny; Springer Nature: Cham, Switzerland, 2022; pp. 127–149. [Google Scholar]
- Floridi, L. The fight for digital sovereignty: What it is, and why it matters, especially for the EU. Philos. Technol. 2020, 33, 369–378. [Google Scholar] [CrossRef] [Scilit]
- Basile, L.; Borri, R.; Verzichelli, L. ‘For whom the sovereignist Bell Tolls?’ Individual determinants of support for sovereignism in ten European countries. In Sovereignism and Populism; Routledge: London, UK, 2021; pp. 85–107. [Google Scholar]
- Lohmöller, J.; Pennekamp, J.; Matzutt, R.; Schneider, C.V.; Vlad, E.; Trautwein, C.; Wehrle, K. The unresolved need for dependable guarantees on security, sovereignty, and trust in data ecosystems. Data Knowl. Eng. 2024, 151, 102301. [Google Scholar] [CrossRef] [Scilit]
- Pohle, J.; Thiel, T. Digital sovereignty. Pract. Sovereignty Digit. Involv. Times Cris. 2021, 13, 47–67. [Google Scholar] [CrossRef] [Scilit]
- Maria, N. The Global Reach of the EU’s Approach to Digital Transformation. 2024. Available online: https://policycommons.net/artifacts/11321611/the-global-reach-of-the-eus-approach-to-digital-transformation/12207758/ (accessed on 6 September 2026).
- Gilbert, S.; Baca-Motes, K.; Quer, G.; Wiedermann, M.; Brockmann, D. Citizen data sovereignty is key to wearables and wellness data reuse for the common good. npj Digit. Med. 2024, 7, 27. [Google Scholar] [CrossRef] [Scilit]
- Flonk, D.; Jachtenfuchs, M.; Obendiek, A. Controlling internet content in the EU: Towards digital sovereignty. J. Eur. Public Policy 2024, 31, 2316–2342. [Google Scholar] [CrossRef] [Scilit]
- Musoni, M.; Karkare, P.; Teevan, C.; Domingo, E. Global Approaches to Digital Sovereignty: Competing Definitions and Contrasting Policy. 2023. Available online: https://ecdpm.org/application/files/7816/8485/0476/Global-approaches-digital-sovereignty-competing-definitions-contrasting-policy-ECDPM-Discussion-Paper-344-2023.pdf (accessed on 6 September 2026).
- Chapdelaine, P.; McLeod Rogers, J. Contested sovereignties: States, media platforms, peoples, and the regulation of media content and big data in the networked society. Laws 2021, 10, 66. [Google Scholar] [CrossRef] [Scilit]
- Blancato, F.G. The cloud sovereignty nexus: How the European Union seeks to reverse strategic dependencies in its digital ecosystem. Policy Internet 2024, 16, 12–32. [Google Scholar] [CrossRef] [Scilit]
- Vayadande, K.; Singh, V.; Sultanpure, K.; Deshpande, D.; Patil, H.; Patil, A.; Pathak, A.; Pareek, S.; Patil, D. Empowering Data Sovereignty: Decentralized Image Sharing through Blockchain and Interplanetary File System. Int. J. Intell. Syst. Appl. Eng. (IJISAE) 2024, 12, 223–235. [Google Scholar]
- Abbas, A.E.; van Velzen, T.; Ofe, H.; van de Kaa, G.; Zuiderwijk, A.; de Reuver, M. Beyond control over data: Conceptualizing data sovereignty from a social contract perspective. Electron. Mark. 2024, 34, 20. [Google Scholar] [CrossRef] [Scilit]
- Heidebrecht, S. From market liberalism to public intervention: Digital sovereignty and changing European union digital single market governance. JCMS J. Common Mark. Stud. 2024, 62, 205–223. [Google Scholar] [CrossRef] [Scilit]
- Duisberg, A. Legal Aspects of IDS: Data Sovereignty—What Does It Imply? In Designing Data Spaces; Otto, B., ten Hompel, M., Wrobel, S., Eds.; Springer: Cham, Switzerland, 2022. [Google Scholar] [CrossRef] [Scilit]
- Özdal Oktay, S.; Heitmann, S.; Kray, C. Linking location privacy, digital sovereignty and location-based services: A meta review. J. Locat. Based Serv. 2024, 18, 1–52. [Google Scholar] [CrossRef] [Scilit]
- Ishmaev, G. Sovereignty, privacy, and ethics in blockchain-based identity management systems. Ethics Inf. Technol. 2021, 23, 239–252. [Google Scholar] [CrossRef] [Scilit]
- Cuno, S.; Bruns, L.; Tcholtchev, N.; Lämmel, P.; Schieferdecker, I. Data governance and sovereignty in urban data spaces based on standardized ICT reference architectures. Data 2019, 4, 16. [Google Scholar] [CrossRef] [Scilit]
- ForouzeshNejad, A.A.; Arabikhan, F.; Taheri, R. The Role of Explainable AI (XAI) in Enhancing the Security of Machine Learning Systems Against Adversarial Attacks. In Adversarial Example Detection and Mitigation Using Machine Learning; Springer Nature: Cham, Switzerland, 2026; pp. 153–170. [Google Scholar]
- European Commission. ‘EU Challenges China at the WTO to Defend High-Tech Sector’. PRESS RELEASE 18 February 2022 Brussels, 2022. Available online: https://ec.europa.eu/commission/presscorner/detail/en/ip_22_1103 (accessed on 6 September 2026).
- Bradford, A. The Brussels Effect: How the European Union Rules the World; Oxford University Press: New York, NY, USA, 2020. [Google Scholar]
- Bıçakçı, A.S. Digital Europe Program: Nurturing Technological Sovereignty for a Resilient European Digital Ecosphere. Ank. Avrupa Çalışmaları Derg. 2024, 23, 135–174. [Google Scholar] [CrossRef] [Scilit]
- Cannon, S.E.; Moore, J.W.; Adams, M.S.; Degai, T.; Griggs, E.; Griggs, J.; Marsden, T.; Reid, A.J.; Sainsbury, N.; Stirling, K.M.; et al. Taking care of knowledge, taking care of salmon: Towards Indigenous data sovereignty in an era of climate change and cumulative effects. FACETS 2024, 9, 1–21. [Google Scholar] [CrossRef] [Scilit]
- Saeedikiya, M.; Salunke, S.; Kowalkiewicz, M. The nexus of digital transformation and innovation: A multilevel framework and research agenda. J. Innov. Knowl. 2025, 10, 100640. [Google Scholar] [CrossRef] [Scilit]
- Donnelly, S.; Ríos Camacho, E.; Heidebrecht, S. Digital sovereignty as control: The regulation of digital finance in the European union. J. Eur. Public Policy 2024, 31, 2226–2249. [Google Scholar] [CrossRef] [Scilit]
- Bernot, A.; Cooney-O’Donoghue, D.; Mann, M. Governing Chinese technologies: TikTok, foreign interference, and technological sovereignty. Internet Policy Rev. 2024, 13, 1–26. [Google Scholar] [CrossRef] [Scilit]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.



