The debate on Sweden’s digital sovereignty has become bogged down in geopolitics, but the issue is decided in procurement processes conducted across Sweden’s public sector.
Then, suddenly, it happens. The US Federal Trade Commission (FTC) loses the independence from the executive branch on which the EU–US Data Privacy Framework depends. The legal basis underpinning much of the public sector’s use of cloud services is thereby called into question.
The legal position is unclear. What is clear, however, is that every public authority must now assess whether continued storage is compatible with the GDPR and, where necessary, migrate to European services. The question is what that would entail, and what it would cost. If the cost proves unreasonable, however, that will not be because of an American decision, but because of Swedish ones.
Imagine that the state had not taken overall responsibility for the electricity supply, but had instead left each municipality to build its own electricity grid. It sounds unthinkable, yet that is how our digital infrastructure has developed. While the state has taken overall responsibility for other areas critical to sovereignty, in practice it has left the design of the digital infrastructure to the procurement decisions of individual public authorities.
Technology has been procured as though each purchase were an isolated transaction, with cost-effectiveness taking precedence over national freedom of action. As locally rational decision-making has been allowed to govern thousands of procurement processes, the public sector is now highly dependent on a small number of suppliers, predominantly American. And, by extension, on the states under whose jurisdiction they fall. This dependence has reduced Sweden’s freedom of action and, consequently, its sovereignty.
Systems of governance create the behaviour they reward. The outcome is hardly surprising.
The vulnerability is not theoretical. US jurisdiction can restrict European users’ access to digital services, as Microsoft’s closure of accounts linked to the International Criminal Court has demonstrated. What a corresponding measure against Swedish public administration would entail hardly needs spelling out.
The state now emphasises the importance of reducing dependence, but appears to assume that the same restrained government direction that created it will now reduce it. The new cloud policy is advisory, using “should” rather than “must”. The National Agency for Public Procurement talks about digital sovereignty, but there is no requirement to take supplier dependence into account. eSam provides support for analysing cloud services, but offers limited guidance on procurement as a strategic instrument for digital sovereignty. There is little reason to believe that advice will make nationally necessary procurement decisions locally rational.
A state that cannot adapt to changing external conditions without unreasonable costs or widespread disruption does not possess digital sovereignty. If changing suppliers, migrating data or changes in legal conditions risk paralysing critical societal functions, freedom of action has already been lost.
Conditions change rapidly. Dependence comes at a price. If the state intends to reduce that dependence, procurement must begin to be used as a strategic instrument. Otherwise, Swedish taxpayers’ money will continue to finance the very dependencies the state says it wants to reduce.
If the EU–US Data Privacy Framework falls, it will be a litmus test of Sweden’s digital sovereignty. At a time when the distinction between real and digital sovereignty is, at most, lexical, it would be desirable for the state not to wait for the result before its governance begins to reflect that insight.
This article was first published in the Swedish publication Nyhetsmagasinet Fokus, under the Sticket banner, on 7 July 2026.

