<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Digital Sovereignty on Sovereign Shift</title>
    <link>https://sovereignshift.eu/tags/digital-sovereignty/</link>
    <description>Recent content in Digital Sovereignty on Sovereign Shift</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Wed, 18 Feb 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://sovereignshift.eu/tags/digital-sovereignty/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>EU vs US Vendor Exposure: A Scoring Checklist for European Organisations</title>
      <link>https://sovereignshift.eu/blog/eu-us-vendor-exposure-checklist/</link>
      <pubDate>Wed, 18 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://sovereignshift.eu/blog/eu-us-vendor-exposure-checklist/</guid>
      <description>&lt;p&gt;European organisations tend to think about US vendor exposure in binary terms: either you use US cloud providers or you do not. The reality is more layered. Two organisations can both run on Microsoft 365 and have very different levels of exposure, depending on how identity is configured, who holds the encryption keys, where backups sit, and what integrations exist.&lt;/p&gt;&#xA;&lt;p&gt;This post provides a structured checklist for scoring your organisation&amp;rsquo;s actual US vendor exposure. It is not a compliance form. It is a practical tool for understanding where your sovereignty risk concentrates and which areas you can address without a full migration.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Eight Control Points US Cloud Providers Hold Over European Businesses (and Which Ones to Fix First)</title>
      <link>https://sovereignshift.eu/blog/data-driven-decision-making/</link>
      <pubDate>Thu, 15 Jan 2026 00:00:00 +0000</pubDate>
      <guid>https://sovereignshift.eu/blog/data-driven-decision-making/</guid>
      <description>&lt;p&gt;European organisations that choose EU data centres for their Microsoft 365 or Google Workspace deployments often believe they have addressed their sovereignty exposure. The data is in the EU. The box is ticked.&lt;/p&gt;&#xA;&lt;p&gt;But data location is only one of many control points a cloud provider holds over your organisation. Even with EU-hosted data, a US provider retains administrative access, controls the encryption keys, operates the identity layer, and can push updates or policy changes without your consent. The CLOUD Act (18 U.S.C. §2713) gives US law enforcement the legal authority to compel data disclosure regardless of where the data is physically stored.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
