What's digital sovereignty and how to practice it
Digital sovereignty isn't some abstract concept. It's about deciding who gets access to your data, where it lives, and what happens if a provider vanishes.
Introduction
The term “digital sovereignty” can sound scary. You might think of conferences in Brussels, debates on the European cloud, 300-page reports that no one reads. And yes, that exists. But it’s not what directly concerns you.
What concerns you is the everyday version of the problem: who has access to your files, who can read your emails, and what happens when a service you rely on closes or decides you’re no longer welcome. This article sets the stage, jargon-free.
The Problem
What you delegate without knowing
Let’s take a concrete example. You use Gmail. It’s free, it’s convenient, it works.
Here’s what you agreed to by checking “I accept the terms”:
- Google analyzes your emails. For years, Google scanned the content of your messages to target ads. They stopped in 2017, not because they had to legally, but because they had enough data elsewhere. Your emails remain analyzed by their algorithms (spam, AI, automatic sorting), stored on their servers, and subject to American law.
- Google can close your account. For violating terms of service (real or supposed), prolonged inactivity, or an algorithmic decision. Forums are full of stories of people who lost access to 15 years of emails overnight. With only a complaint form and a bot wishing you a good day as recourse.
- Google is subject to American law. A federal court, a National Security Letter, a FISA request, and your data is accessible to the American government. Without any obligation to notify you.
- You don’t have a backup. If you don’t make one yourself, your emails exist in only one place: Google’s servers. If access is lost, everything is lost.
And Gmail is just one example. Replace it with Google Drive, Dropbox, Slack, Notion: the pattern is the same. You use a service without controlling the conditions.
Small nuance: not all providers are the same. Apple, for example, allows for end-to-end encryption of iCloud via Advanced Data Protection (which needs to be manually enabled), and its business model relies mainly on hardware and services, even if its advertising revenues are growing. It’s better than Google on privacy. But your data remains on their servers, subject to American law, and Apple can still disable your account. Better doesn’t mean truly sovereign.
Three questions to ask about each of your tools
For an independent or small business, digital sovereignty boils down to three questions:
- Who controls your data? You, or a provider who could change their terms tomorrow?
- Where are they stored? In a jurisdiction that protects your privacy, or in a country where a government can demand access without notifying you?
- What happens if the service closes or cuts off your access? Do you have a Plan B, or is it total shutdown?
If you can’t answer these three questions for each of your critical tools - email, storage, passwords, communication - then you’re not sovereign. You’re a tenant. With a lease that can be terminated without notice.
The Mechanism
Sovereignty is a spectrum
No one is 100% sovereign. It’s neither realistic nor necessary. The goal isn’t to self-host everything in a submarine: it’s to make conscious choices.
There’s a spectrum:
Level 0, all with GAFAM. Gmail, Google Drive, Chrome. You control nothing, you pay nothing in cash. In fact, your data is the product. It’s not encrypted, your provider can read it, and they can be forced to hand it over to a government without even notifying you. And it’s not just Google: Microsoft with Outlook and OneDrive, Amazon with Alexa, same pattern. Servers you don’t control, and a right to look into your digital life that you gave up with one click, because their terms were written to confuse you. As for Meta, WhatsApp encrypts your messages, but collects who you call, when, and where. The content is protected, but the rest of your digital life, much less so.
And if you’re all Apple? It’s a significant step up. Apple doesn’t live off your data and takes privacy more seriously than its competitors. Advanced Data Protection encrypts a lot of iCloud end-to-end, but not everything: Mail, Contacts, and Calendar remain accessible on the server side. And above all, your data is on servers subject to American law, and you entrust everything to a single provider. If your Apple ID gets blocked, even temporarily, it’s email, photos, passwords, and apps that become inaccessible all at once.
Level 1, privacy-first alternatives. You migrate to services that respect your privacy by design. Proton Mail instead of Gmail. Proton Drive or encrypted storage instead of Google Drive. A dedicated password manager instead of the browser’s password manager. Brave or Firefox instead of Chrome. A VPN so your ISP stops profiling your browsing. You’re still hosted, but by providers whose business model aligns with privacy and your interests, not against them.
Level 2, mastered hybrid. You keep control of what’s critical: NAS for your files, Nextcloud for collaboration, local password manager. For what requires high availability, you choose trusted third parties aligned with privacy: Proton for email, an European host for encrypted multi-site backup. You control your DNS, you have a VPN, and you know exactly where each piece of data lives.
Level 3, complete infrastructure. Dedicated server or VPS, secure mesh network, self-hosted files and messaging, all end-to-end encrypted. Your backups are distributed across multiple geographic sites. You no longer depend on anyone to access your data, and if a data center burns down, everything is replicated elsewhere. That’s what I do. It’s excessive, perhaps, for most individuals, but desirable for an entrepreneur concerned about business continuity.
The right level is the one that corresponds to your real risk and the time you want to spend on it. For most independents, level 1 is a massive improvement. Level 2 is ideal. Level 3 is real security for business.
The concrete pillars
Email. It’s the entry point for everything. Your email is your online identity, your account recovery key, your primary communication thread. The minimum: a provider that encrypts end-to-end, based in a solid jurisdiction. Proton Mail is the obvious choice, E2EE, based in Switzerland, open source, audited by third parties. Tuta (formerly Tutanota), based in Germany and open source, is a credible alternative.
Read: Apple Mail vs Gmail vs Proton Mail, the honest comparison
VPN. Not to “become totally anonymous”, but to prevent your ISP from profiling your browsing and protect against malicious acts on public networks.
Storage. Your files must be encrypted and under your control. iCloud with Advanced Protection enabled is already end-to-end encrypted: it’s a good start if you’re in the Apple ecosystem. To go further: Proton Drive (native E2EE, Swiss jurisdiction) or your own NAS with remote backup.
Passwords. A dedicated manager. Apple’s built-in Passwords app (introduced with macOS Sequoia) is already a good starting point, encrypted, integrated, free. But if you want multi-platform or team sharing, consider 1Password, Bitwarden, or KeePassXC.
Private network (mesh network). If you work from multiple locations or have a NAS, a server, distributed machines, you need to connect them securely. A mesh network like Tailscale creates a private, encrypted network between all your devices, wherever they are.
DNS. The weak link that everyone forgets. Your DNS queries pass in plaintext by default, your ISP sees every site you visit. DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), or local DNS changes everything.
What It Changes in Practice
Where to start
If you’re starting from scratch, here’s the order that makes the most difference with the least effort:
- Lock down macOS. 15 minutes, zero tools to install. -> Privacy macOS: the settings to change immediately
- Install a VPN. One app, one click. -> Why you need a VPN and how to choose one
- Migrate your email. The biggest task, but the most impactful.
- Manage your passwords. A manager + unique passwords everywhere.
- Take back control of your files. Encrypted storage + backup.
- Connect your machines. A mesh network to access everything, everywhere, securely.
Each step is an article on MacSouverain. You progress at your own pace.
What it protects (and what it doesn’t)
Digital sovereignty doesn’t protect you from everything. It doesn’t protect against a weak password, well-targeted phishing, or human error. It doesn’t guarantee that your privacy-first providers won’t ever go bankrupt or change their terms.
What it does: it reduces your dependence on a single provider, increases your ability to react if something goes wrong, and gives you a decision-making framework for every tool you add to your stack.
The Limits
It’s not excessive
There’s a trap to avoid: sliding into total paranoia. Wanting to self-host everything, refusing all third-party services, spending weekends configuring servers to replace tools that worked perfectly well.
Digital sovereignty is a slider, not a switch. Moving it from “zero control” to “reasonable control” makes a huge difference. Moving it from “reasonable control” to “operational paranoia” has diminishing returns.
Compromises are inevitable
You’ll probably still use some cloud services. The important thing is knowing which ones, why, and having an exit plan. Using iCloud for your vacation photos is an acceptable compromise. Storing your business contracts exclusively on Google Drive without a local backup is an uncontrolled risk.
Technique isn’t everything
The best encryption in the world doesn’t protect against a collaborator sending a sensitive file on WhatsApp. Digital sovereignty includes a human dimension: raising awareness, training, defining clear rules.
In Summary
Digital sovereignty isn’t a political concept for Brussels conferences. It’s a very practical approach: knowing where your data is, who can access it, and what happens if things go wrong. It’s practiced in progressive levels, from the simplest (migrating to an encrypted email provider) to the most advanced (self-hosted infrastructure).
Your data, clients, invoices, contracts, exchanges, are the heart of your business. Leaving them in the hands of a third party without a backup or Plan B is like leaving the keys to your office in the lock when you leave at night. It’ll probably work. Until the day it doesn’t. Start at level 1: it’s already a massive improvement. The rest will come naturally.
Technical terms? Check the glossary.