Two forms of lock-in nobody talks about
When it comes to digital sovereignty, a lot of attention is paid to data residency. Where do your workloads run, and which jurisdiction and legislation apply to them? Rightly so, but that is not the complete story. A platform can run entirely in the Netherlands and still be under foreign control. Not through the data, but through the technology itself.
Two forms of dependency often remain overlooked:
1. Architectural lock-in
A large part of the market talks about open source, while continuing to build on proprietary environments. Once you have migrated, you cannot simply migrate back without rebuilding parts of the environment. The standard is open, but the platform is not.
2. Jurisdictional lock-in
Support, updates and license management often run through a US-based parent company. The US CLOUD Act theoretically gives the US government access to data and systems, even when the infrastructure is physically located in the Netherlands. This is no longer a fringe issue. It is exactly the type of dependency that becomes relevant within the context of NIS2 and the upcoming Data Act.
Both forms of dependency often remain invisible until an incident, audit or geopolitical shock occurs. That is when it becomes clear how much control you actually had.