Digital sovereignty is an increasingly important business consideration. Many organisations and public sector functions are grappling with how to achieve it. Some think that digital sovereignty requires a trade-off between the benefits of using hyper-scalers’ digital infrastructure, on the one hand, and safety, security, and regulatory compliance, on the other. This isolationist view emphasises data and digital infrastructure residency, creating unnecessary limitations that stifle innovation and global competitiveness. In reality, digital sovereignty in the modern digital ecosystem is more about realising strategic objectives through leveraging technological advances and applying sound governance.

You can promote digital sovereignty by having sound IT governance across the life cycle of your IT assets and digital infrastructure.

What is digital sovereignty in a data-driven economy?

Digital sovereignty means you actively manage your data and information and stay in control of your IT assets and operations. The test is about control: you do not need to own the entire digital stack, but you do need the ability to manage and control it. A meaningful way to achieve this control is to manage third-party relationships with the appropriate contractual protections and security controls.

Digital sovereignty is the ability to manage and control IT assets and operations.

Some important considerations are:

  •     Who owns the digital infrastructure, and what rights can we enforce?
  •     Whose law applies?
  •     Who holds the encryption keys?
  •     Who can access data?
  •     Can we audit the digital infrastructure?
  •     Can we move a strategic workload if commercial or geopolitical conditions change?
  •     Is our data portable if a provider fails or exits the market?

The responses to these questions will differ for every organisation, depending on its needs and the risk level of its operations. For one organisation, who can access its data may not be as important because it does not process or store personal, sensitive or confidential data. For another, it may be a legal requirement to restrict access. In the latter instance, a control may be keeping data in “in country” or “on-premises” because the data is sensitive and good practice or the law requires it.

Start with a risk assessment

Becoming digitally sovereign starts with a risk assessment. A well-conducted risk assessment informs decisions about what you control directly, what you govern through contract and what you access through trusted partners.

Digital sovereignty is a strategic choice that depends heavily on organisational context.

Two global factors are important to consider when conducting a risk assessment. The first is the unprecedented speed of AI-based advances, which require responsible AI governance. This is likely to impact any organisation that relies on modern digital infrastructure to process data, which is typically its lifeblood. The second is the seismic geopolitical shifts we have seen in the recent past. Together, they inform the “threat” or “situational” awareness that best practice and, in some instances, regulation demands in conducting the assessment.

Benefits of a risk assessment

Conducting a risk assessment has many benefits. For one, it helps prioritise which sovereignty controls are appropriate in your context. Think how, for most organisations, a cyberattack is far more likely and the consequences are graver than those of a foreign government seeking “lawful access” to data. This means having robust security controls or commitments in place will be a higher priority than controls that restrict lawful access requests by governments.

However, the risk landscape changes frequently, so it’s important to revisit your risk assessment periodically, or after a major internal or external event. A good example of an external event is the United States export control order, which led Anthropic to suspend access to its Fable 5 and Mythos 5 models in June 2026. While this event seemed to be targeted at Anthropic (to bend it to the Trump administration’s will) rather than a sanction on its users, one consequence was that people who had already started building in Fable 5 were locked out of their projects.  So, while an event like this is unlikely, when it does occur, you would need to reassess what it means for your organisation’s digital sovereignty.

South African law provides the necessary guidance for promoting digital sovereignty

Sound IT governance is essential to promoting digital sovereignty. It is achieved by establishing leadership structures that ensure appropriate responsibility and accountability for decisions at strategic and operational levels.  Including developing and approving policies that direct its technology investments and align its technology strategy with broader organisational goals. South Africa already has the laws and guidance you need to promote digital sovereignty, such as

  • The Constitution, which is the basis for all lawful conduct within South Africa.
  •  POPIA, which, among other things, requires a transfer impact assessment and a binding transfer mechanism when transferring personal information across borders.
  • The Companies Act, which formalises board-level fiduciary duties for IT governance.  
  • Sector-specific regulations, such as the Joint Standard on Cybersecurity and Cyber Resilience Requirements. They set out a risk-based approach built on due diligence and legally enforceable IT contracts.
  • Codes like King V require the governing body to govern data, information, and technology. King outlines practices that help sustain and optimise organisations’ IT strategies and ensure business continuity.

South Africa does not lack laws or guidance on digital sovereignty.

These existing instruments, and others, provide a basis for securing, managing, and controlling your IT assets. The pattern across these instruments is that organisations need to govern their IT processes by assessing the risks associated with their activities and implementing the necessary controls to manage and control their IT assets.

Where South African law is silent, international standards such as ISO and NIST fill those gaps.

Frequently asked questions

  1. What is digital sovereignty? Digital sovereignty is your organisation’s ability to maintain control over its data, infrastructure, and operations as it uses cloud and emerging technologies. The test is control, not ownership.
  2. Does digital sovereignty mean keeping all data in South Africa? No. Data localisation is one option, and some laws require it for certain types of data. Sovereignty is about enforceable control through law, contracts, security, and exit rights, whether your data sits locally or offshore.
  3. Which laws support digital sovereignty in South Africa? The Constitution, POPIA, the Companies Act, the King Code, and sector rules, such as the FSCA and the Prudential Authority’s guidance on cloud computing and data offshoring. ISO 27001 and the NIST Cybersecurity Framework add international best practices.
  4. How does AI affect digital sovereignty? AI embeds itself within business-critical assets, increasing reliance on third parties. Good AI governance and human oversight are essential because the organisation using the AI, not the AI developers or suppliers, usually bears the legal and reputational risk.

Mark Heyink’s thoughts on digital sovereignty

Mark has decades of experience dealing with various aspects of the digital stack, and he answers some insightful questions about digital sovereignty in the video below.

Actions to take