Valikko Sulje

Data Management as a backbone of European IT sovereignty

A multi-level view on data management capability and how it enables digital sovereignty

The sovereignty paradox

In November 2025, the member states of the European Union adopted the Declaration for European Digital Sovereignty. A few days earlier, the Commission had released its Digital Omnibus proposal, a 160-page effort to simplify what has become the densest regulatory stack for data in the world. A month before that, the Commission had published its Cloud Sovereignty Framework with eight sovereignty objectives for public procurement. Europe clearly wants to be sovereign.

And yet roughly 97 percent of Europe’s cloud infrastructure runs on non-European platforms — primarily American, with some Chinese. European data crosses the Atlantic every time someone opens a shared document or queries a business intelligence dashboard. GDPR fines have passed €5.6 billion since 2018, but they have not moved the underlying market share.

This is the paradox at the heart of European digital sovereignty. There is more data regulation than any other region on Earth. There are declarations, frameworks, directives, acts, guidelines, and strategies. What is still missing, at scale, is the operational capability to exercise sovereignty over the data we generate, collect, and analyze every day.

The gap is not a regulatory gap. It is a data management gap.

When I joined the board of DAMA International® – a global association of data professionals, I came to the role thinking about data management the way most practitioners do: as an enterprise discipline. Governance, quality, architecture, metadata — all concerned with what happens inside an organization. That view has since expanded. Data management is a multi-level system that runs from the individual all the way to the international. At each level, the capabilities required for sovereignty are different. And at each level, Europe has work to do.

What Europe has already built

Let me begin with what exists, because the regulatory architecture is substantive.

The General Data Protection Regulation, in force since 2018, extended European fundamental rights to personal data wherever it flows. The Data Governance Act of 2022 introduced regulated data intermediaries and a framework for altruistic data sharing. The Data Act, applicable from September 2025, extends sovereignty to non-personal and industrial data — including the data generated by connected devices, which had previously been captured almost entirely by manufacturers. The Digital Operational Resilience Act (DORA), effective January 2025, imposes operational sovereignty requirements on financial services and their ICT providers. The NIS2 Directive extends cybersecurity obligations across critical sectors. The AI Act will be fully applicable in August 2026. The eIDAS Regulation enables cross-border electronic identification and trust services.

Behind these core instruments sits a longer list: the Open Data Directive, the Digital Markets Act, the Digital Services Act, the sector-specific European Health Data Space which entered force in March 2025, the emerging European Data Union Strategy, and the proposed EU Cloud and AI Development Act.

The architecture is coherent enough that more than 160 countries have drawn from it in drafting their own data protection laws. That is a significant export of European regulatory thinking, and it reflects something real: Europe has decided what rules data should follow, and much of the world is following along.

Regulation sets the rules of the game – but it does not play it. No amount of auditing will produce a sovereign cloud, and no fine will conjure a functioning data space out of thin air. Interoperability between twenty-seven member states, twenty-four official languages, and thousands of legacy systems is not something you can declare into existence. What regulation cannot provide is the how: the teams who do the work, the platforms they build on, the shared taxonomies that make data meaningful across borders, and the institutional trust that holds it all together. This is where the conversation needs to move from regulation to data management and multiple levels.

Sovereignty as a multi-level capability problem

Consider the full stack of activity required for European data sovereignty to be real, not rhetorical. It runs across four levels, and each level depends on the others. Figure 1 summarizes this view.

Figure 1. Layered Global Data Capability Map

International

At the international level, sovereignty rests on standards bodies, professional associations and intergovernmental organizations — ISO, OECD, UNECE, DAMA International® — and on interoperability frameworks that allow data to move across jurisdictions without losing its meaning. Cross-border data flows depend on adequacy decisions, standard contractual clauses, and technical exchange protocols. The UNCTAD in their Digital Economy Report 2021 suggest a “Global framework to enable data flows, with development objectives in mind”.

National

At the national level, sovereignty depends on infrastructure. National data exchange platforms, authoritative base registries for persons, businesses, addresses, and properties. Digital identity. Government cloud. National data strategies and government chief data officers. The World Bank’s World Development Report 2021 found that 53 percent of high-income countries have a dedicated data governance entity, compared to 0 percent of low-income countries. This single variable is the strongest predictor of national data maturity worldwide.

Of course, legal and regulatory frameworks are critical and this is what Europe excels at. But at the same time, hyper-scales dependency and stable supply of chips is still a risk for digital sovereignty, as governments which can’t control the physical environment where data is kept cannot guarantee data autonomy.

Another important national data capability is Talent and Workforce management. It means a system of Government CDO Networks, Data Professional Certification Ecosystem, skills and competencies frameworks as well as national data literacy programs to name only a few.

Sovereignty at the national level also requires a functioning data economy. This means data marketplaces, sectoral data spaces where organizations pool data under agreed governance rules, and regulated intermediaries who solve the trust problem between data holders and users. The EU is building fourteen such data spaces across health, mobility, manufacturing, energy, and other domains. The European Commission estimates that data sharing can generate 1 to 2.5 percent of GDP from public-sector data alone. Without a deliberate approach to the data economy, a country may govern its data well but still fail to extract measurable financial sovereign value from it.

Organizational

At the organizational level, sovereignty depends on the disciplines that DAMA’s Data Management Body of Knowledge® (DMBOK®) codifies: governance, architecture, modeling, storage, security, integration, master and reference data, data warehousing, content management, metadata, and quality. These disciplines sound routine until an organization tries to identify, classify, and repatriate its own data from a foreign cloud. Then the routine becomes strategic and necessary.

Individual

Data sovereignty has a human bottleneck and data literacy is a

At the individual level, sovereignty depends on data literacy — on citizens who can read a dashboard, evaluate an AI output, understand consent. The European Declaration on Digital Sovereignty states, that “focus on investments in education and research, digital skills, and digital literacy s indispensable to empower European labor force”. Finland’s Elements of AI MOOC has trained hundreds of thousands of people. The UN Data Strategy targets ten percent of the workforce in data roles.

According to the European Data Market Study 2024-2026, the data professionals’ skills gap in 2024 has increased by over 10% from 2023, reaching 500,000 units across the EU27 and is estimated to reach 631,000 by 2030. Gaps of such scale require strategic commitments from countries to invest in data skills of their citizens and success depends on availability of effective education systems, data management skill models and bodies of knowledge.

Regulation runs across all four levels, but it does not substitute for any of them. GDPR does not produce trained data stewards. The AI Act does not produce metadata management. The Data Act does not produce interoperable semantic models. Each of these is data management work, and it has to be done by someone.

AI raises the stakes

Until recently, data sovereignty was largely a storage question. Where does the data sit? Under whose laws? The rise of generative AI has changed that.

AI models do not just hold data. They learn from it. They absorb and propagate the linguistic, cultural, and analytical patterns of their training sets. A model trained primarily on English-language and U.S.-perspective data will reflect that, whether anyone intends it to or not. Which means sovereignty over AI is, at bottom, sovereignty over the data pipeline — collection, preparation, labeling, lineage, validation, and governance. These are data management concerns.

The investments being made tell their own story. Saudi Arabia has committed around 100 billion dollars to its Project Transcendence sovereign AI initiative. France has mobilized €109 billion anchored by Mistral. The EU AI Continent Action Plan targets €200 billion. India’s IndiaAI Mission has committed 1.25 billion dollars including more than ten thousand GPUs and multilingual foundation models. China’s DeepSeek-R1 demonstrated that a credible frontier model can be built for under 6 million dollars, collapsing some of the assumptions about what sovereignty in compute actually requires.

But as the Brookings Institution concluded in a 2025 analysis, full-stack AI sovereignty is structurally infeasible for almost any country. The AI stack spans critical minerals, energy, semiconductors, compute, data, models, and talent. No single nation controls all of them, and few ever will. The practical alternative is what Brookings calls managed interdependence — strategic partnerships that reduce concentration risk while preserving cross-border collaboration.

Managed interdependence only works if the data flowing between partners is well-governed. This is where the EU’s fourteen Common European Data Spaces — covering health, mobility, agriculture, manufacturing, energy, finance, and other domains — become central. They are, in effect, data management programmes at continental scale. Each data space requires agreed semantics, metadata standards, quality rules, trust frameworks, and technical exchange protocols. The roughly €100 million invested through 2026 funds exactly these capabilities, not the data itself.

If Europe gets the data spaces right, sovereign AI becomes a realistic proposition. If it gets them wrong, Europe will remain structurally dependent on models trained elsewhere, on data it could have governed itself.

Data management as sovereignty practice

European digital sovereignty is not a regulation to comply with. It is a capability to build, and rebuild, and rebuild again as technology changes around it.

The regulations have been written. The declarations have been signed. What remains is the unglamorous middle layer — the metadata standards, the quality rules, the master data hierarchies, the interoperability specifications, the literacy programmes, the certification pipelines, the stewardship roles. This is the work of data management professionals. It is the work that happens in the meeting after the minister has left the room.

My argument, for what it is worth, is that the data management community should stop describing itself as a compliance support function and start describing itself as a sovereignty function too. The first framing is narrow and defensive. The second is accurate, and it reflects where the actual capability gap in Europe now lies.

DAMA International® and its 23 European chapters, the DMBOK® framework, the CDMP® certification pipeline – these are the connective tissue and a common language, that turns regulatory intent into operational reality. They were built for individuals and organizations, but they scale upward. A national chief data officer does enterprise data governance at a national scale. A continental data space does enterprise data architecture at a continental scale. The fundamentals are the same.

The November 2025 declaration on European digital sovereignty called for economic resilience, social prosperity, competitiveness, and security. All four depend on data that is findable, accessible, interoperable, reusable — and governed. This is the oldest set of principles in our field, now carrying geopolitical weight.

Sovereign Europe will be built, if it is built at all, by people who understand data as a managed asset. The regulations have opened the door. Walking through it is now our profession’s work.

Figure captions

Figure 1. Data management as a multi-level system, from the individual to the international. Each level hosts capabilities that are essential to national data management capabilities and enabling digital sovereignty. Regulation runs across all four levels but does not substitute for the operational capabilities built at each one.

Further reading

  • European Commission, Declaration for European Digital Sovereignty (November 2025).
  • European Commission, Cloud Sovereignty Framework (October 2025).
  • European Commission, European Data Union Strategy.
  • Brookings Institution, analysis on AI sovereignty and managed interdependence (2025).
  • World Bank, World Development Report 2021: Data for Better Lives.
  • OECD, Measuring the Economic Value of Data (2022).
  • DAMA International®, DAMA-DMBOK: Data Management Body of Knowledge®, second edition.
  • European Commission, European Interoperability Framework.
  • European Data Market Study 2024-2026
  • UN Digital Economy Report 2021

Alexander Zhukov is a Board Member of DAMA International® and President of DAMA Ukraine Kyiv. He works at the intersection of data governance, AI and data technologies. He is a thought leader and community builder with over a decade of IT experience. The views expressed are his own.

Samankaltaisia artikkeleita