Two forms of lock-in that no one mentions
When discussing digital sovereignty, there is a lot of talk about data residency. Where do your workloads run, and which jurisdiction and legislation do they fall under? This is valid, but the story is incomplete. A platform can run entirely in the Netherlands and still be under foreign control. Not through the data, but through the technology itself.
Two forms of dependency often remain underexposed:
1. Architectural lock-in
A large part of the market talks about open source while building on closed environments. Once you have migrated, you cannot simply migrate back without rebuilding parts of the environment. The standard is open, but the platform is not.
2. Jurisdictional lock-in
Support, updates, and license management often run through an American parent company. In theory, the Cloud Act gives the US government access to data and systems, even when the infrastructure is physically located in the Netherlands. This is no longer a fringe case. It is exactly the type of dependency that becomes relevant under NIS2 and the upcoming Data Act.
Both forms of dependency often remain invisible until an incident, audit, or geopolitical shock occurs. Only then does it become clear how much control you actually had.