Competition Implications Of Digital Sovereignty Procurement Policies .
Competition Implications of Digital Sovereignty Procurement Policies
1. Meaning
Digital sovereignty procurement policies are government purchasing policies designed to ensure that public authorities retain control over important digital infrastructure, data, software, cloud services, cybersecurity systems, AI systems, and other technological capabilities.
A government may, for example, require public bodies to prefer or purchase:
locally controlled cloud infrastructure;
domestic or regional data-hosting services;
open-source software;
sovereign cloud services;
locally developed cybersecurity products;
technology from suppliers satisfying particular data-localisation requirements;
interoperable and portable digital systems;
suppliers that guarantee governmental control over critical data.
The policy objective may be security, resilience, strategic autonomy, privacy, continuity of government services, or reduction of foreign dependency.
From a competition-law perspective, however, these policies can create an important tension:
A procurement rule designed to increase digital sovereignty can simultaneously reduce the number of suppliers capable of competing for government contracts.
Therefore, the central competition question is not whether digital sovereignty is legitimate. The question is how the procurement requirement is designed and whether it unnecessarily forecloses competition.
2. Why Digital Sovereignty and Competition Can Conflict
Traditional public procurement attempts to obtain goods and services through competition.
Digital sovereignty policies may instead prioritise:
domestic suppliers;
locally hosted infrastructure;
national ownership;
local data processing;
domestic security certification;
government-controlled infrastructure.
These requirements can reduce the pool of eligible suppliers.
Example
Suppose a government requires:
“Only cloud providers headquartered in the country may bid for government cloud contracts.”
A foreign cloud provider may be technologically capable of satisfying the government's security requirements but nevertheless be excluded.
The policy could therefore:
increase sovereignty → reduce eligible suppliers → reduce competitive pressure → potentially increase prices.
This does not automatically make the procurement rule unlawful. The legal analysis depends on the applicable procurement, competition, trade, security and public-interest rules.
3. Main Competition Implications
A. Supplier Exclusion
The most obvious concern is the exclusion of suppliers based on nationality, ownership, location or corporate structure.
A requirement may be legitimate if genuinely necessary for:
national security;
confidential government information;
critical infrastructure;
cybersecurity;
operational resilience.
But a broad nationality requirement can have greater competitive effects than a technology-neutral security requirement.
Example
Compare:
Rule A
“Supplier must be domestically owned.”
with:
Rule B
“Supplier must satisfy specified security, data-control, audit and continuity requirements.”
Rule B potentially allows more suppliers to compete while pursuing the same sovereignty objective.
4. Market Concentration
Digital sovereignty procurement can unintentionally create supplier concentration.
If only a few domestic companies satisfy the eligibility criteria, government purchasing may become concentrated among them.
This can produce:
higher prices;
weaker innovation incentives;
reduced service quality;
capacity constraints;
dependence on a small group of suppliers.
Ironically, a policy designed to reduce foreign technological dependence can therefore create domestic supplier dependence.
5. Entry Barriers
Sovereignty certification can become an entry barrier.
For example, a new cloud provider may need to satisfy:
local data-centre requirements;
domestic ownership requirements;
security certification;
local personnel requirements;
government auditing;
specialised encryption standards.
These requirements can be expensive.
Large incumbent firms may therefore possess an advantage over smaller competitors.
6. Competition Between Domestic and Foreign Suppliers
A digital sovereignty policy can alter the competitive relationship between:
domestic suppliers;
foreign suppliers;
multinational technology companies;
joint ventures;
cloud providers;
open-source providers;
systems integrators.
The competition question is whether the procurement framework creates a level playing field or gives a particular category of supplier an artificial advantage.
7. Sovereign Cloud Procurement
Cloud services are particularly important.
Governments may demand:
domestic data centres;
local administrative control;
local encryption keys;
local ownership of infrastructure;
restrictions on foreign government access;
domestic incident-response teams.
These requirements may serve legitimate sovereignty purposes.
But they can also affect competition by:
reducing the number of eligible providers;
increasing fixed costs;
preventing foreign providers from bidding;
favouring established domestic providers;
increasing switching costs;
encouraging concentration.
8. Data Localisation and Competition
Data localisation requires data to be stored or processed within a particular jurisdiction.
It may improve governmental control over sensitive information.
However, it can also create:
infrastructure duplication;
higher costs;
reduced economies of scale;
barriers to foreign cloud providers;
reduced cross-border service competition.
A competition analysis should therefore distinguish between:
necessary localisation and unnecessarily broad localisation.
9. Open-Source Procurement
Digital sovereignty policies sometimes favour open-source software because it may provide:
source-code transparency;
reduced vendor dependence;
interoperability;
customisation;
portability;
greater government control.
From a competition perspective, open-source procurement can reduce proprietary vendor lock-in.
However, an exclusive preference for a particular technological model can itself exclude innovative proprietary solutions.
The better competition question is often:
Does the procurement rule promote interoperability and contestability, or does it simply replace one preferred supplier category with another?
10. Vendor Lock-In
Digital sovereignty policies frequently attempt to reduce dependence on foreign technology vendors.
However, a poorly designed sovereign system can create domestic lock-in.
Example
Government chooses one sovereign cloud provider.
After several years:
government applications are customised to that cloud;
data is stored in proprietary formats;
employees are trained on the provider's system;
APIs are provider-specific;
migration becomes expensive.
The government may then become dependent on the supposedly sovereign supplier.
Therefore:
Sovereignty without portability can produce a different form of dependency.
11. Interoperability as a Competition Tool
Procurement authorities can reduce lock-in through:
open standards;
API interoperability;
data portability;
exit rights;
migration assistance;
common technical standards.
These requirements can make the government market more contestable.
For example, a procurement contract could require:
“The supplier must provide documented APIs and enable reasonable migration of government data to another qualified provider.”
This may preserve sovereignty while maintaining competitive pressure.
12. Procurement Bundling
Digital sovereignty procurement can involve large bundles containing:
cloud infrastructure;
cybersecurity;
AI;
data storage;
identity management;
networking;
software;
technical support.
Large bundles may favour incumbent technology companies because smaller firms cannot provide the entire package.
Competition concerns may include:
tying;
bundling;
foreclosure;
reduced SME participation;
higher entry costs.
Authorities should consider whether contracts can be divided into separate lots.
13. Framework Agreements
Government framework agreements can also affect competition.
If a framework selects only two or three suppliers for several years, those suppliers may obtain substantial advantages.
Potential consequences include:
customer foreclosure;
reduced opportunities for new entrants;
reduced competitive pressure;
increased supplier concentration.
Long framework periods can make these effects stronger.
14. Strategic Procurement and Dominant Suppliers
Suppose a government already represents a very large share of demand for a specialised technology.
If procurement rules favour only a few suppliers, those suppliers may acquire significant bargaining power.
The government can then move from:
buyer power → supplier concentration → supplier bargaining power.
Competition analysis should therefore consider the structure of both sides of the market.
15. Public Procurement and Article 101 TFEU
In the EU context, procurement can interact with Article 101 TFEU, which prohibits agreements between undertakings that restrict competition.
For example, competing technology suppliers could potentially coordinate:
bids;
prices;
territories;
tender participation;
market allocation.
A sovereignty procurement programme does not legitimise supplier collusion.
16. Article 102 TFEU
Where a technology supplier has a dominant position, its conduct may also raise Article 102 TFEU issues.
Possible concerns include:
exclusionary contracts;
discriminatory access;
tying;
refusal to provide interoperability;
margin squeeze;
loyalty-inducing arrangements.
A procurement authority should therefore avoid designing contracts that unintentionally strengthen an already dominant supplier without adequate competitive safeguards.
17. Public Procurement Principles
In the EU, public procurement generally emphasises principles including:
transparency;
equal treatment;
non-discrimination;
proportionality;
competition.
Digital sovereignty requirements therefore need careful design.
A requirement should ideally have a demonstrable relationship with the procurement objective.
18. Case Law
Case 1: Concordia Bus Finland Oy Ab v Helsingin Kaupunki
C-513/99 (2002)
Facts
The case concerned public procurement criteria used by the City of Helsinki for bus services, including environmental considerations.
Principle
The CJEU accepted that contracting authorities can consider criteria pursuing objectives beyond the lowest immediate price, provided the criteria are connected with the subject matter and comply with procurement principles.
Relevance to digital sovereignty
This provides an important analogy.
A government may potentially pursue legitimate objectives such as:
cybersecurity;
resilience;
data control;
technological continuity.
But the sovereignty criterion should be connected to the procurement objective and applied transparently.
Lesson: Public procurement can pursue broader public objectives, but procurement criteria must remain legally defensible and proportionate.
19. Case 2: EVN AG and Wienstrom GmbH
C-448/01 (2003)
Facts
The procurement authority used environmental criteria when selecting electricity suppliers.
Principle
The CJEU accepted the use of environmental considerations but stressed requirements concerning transparency, verification and connection with the subject matter of the contract.
Relevance
The case is useful by analogy for digital sovereignty.
A government cannot simply state:
“This supplier is more sovereign.”
It should identify measurable criteria such as:
data-location requirements;
access-control requirements;
encryption;
operational control;
security certification;
continuity requirements.
Lesson: Sovereignty criteria should be objectively measurable and transparent.
20. Case 3: Commission v Italy
C-3/88 (1990)
Facts
Italy imposed restrictions favouring domestic production in a way that affected the free movement of goods.
Principle
The CJEU examined national measures that disadvantaged imported products and treated broad national preferences with suspicion where they impeded the internal market.
Relevance
Although this is not a digital-sovereignty procurement case, it illustrates a fundamental issue:
A government preference for domestic suppliers can affect market access.
A digital procurement rule favouring domestic technology therefore requires careful consideration of whether the nationality criterion is actually necessary.
Lesson: Domestic preference and legitimate public-security objectives should not automatically be treated as equivalent.
21. Case 4: Telaustria and Telefonadress
C-324/98 (2000)
Facts
The case concerned the award of a public-service concession involving telecommunications-related activities.
Principle
The Court emphasised transparency and appropriate publicity in public contracting, particularly where a contract has cross-border economic interest.
Relevance
Digital sovereignty procurement can involve major markets for:
cloud services;
telecommunications;
cybersecurity;
digital infrastructure.
A procurement authority should therefore consider whether its process provides sufficient transparency and market access consistent with applicable procurement rules.
Lesson: Strategic importance does not automatically eliminate procurement transparency obligations.
22. Case 5: Pressetext Nachrichtenagentur GmbH v Republik Österreich
C-454/06 (2008)
Facts
The case concerned modifications to a public contract and whether substantial changes could amount to the award of a new contract without appropriate competitive procedures.
Principle
The CJEU developed important principles concerning when changes to an existing public contract can be sufficiently substantial to require a new procurement process.
Relevance to digital sovereignty
Digital contracts frequently evolve because technology changes.
A government might initially purchase:
cloud storage
and later add:
AI infrastructure + cybersecurity + identity services + analytics.
If changes fundamentally alter the economic scope of the contract, procurement authorities need to consider whether the modifications are legally permissible.
Lesson: Sovereign digital procurement should not become a mechanism for indefinitely expanding an incumbent's contract without competitive review.
23. Case 6: Fastweb SpA v Azienda Sanitaria Locale di Alessandria
C-19/13 (2014)
Principle
The case concerned effective judicial protection in public procurement disputes and the ability of competing tenderers to challenge procurement outcomes.
Relevance
Digital sovereignty procurement can involve enormous contracts.
If a procurement authority excludes competitors through sovereignty requirements, effective review becomes important.
Lesson: Procurement decisions affecting market access should remain subject to appropriate legal scrutiny.
24. Case 7: Meca-Medina and Majcen v Commission
C-519/04 P (2006)
Principle
The CJEU explained that rules pursuing legitimate objectives can still fall within competition-law analysis when their effects restrict competition, although their competitive effects may need to be assessed in context.
Relevance
This provides a useful conceptual framework.
A sovereignty policy may pursue:
cybersecurity;
national resilience;
strategic autonomy.
Those objectives do not automatically answer the competition question.
The analysis should consider:
the legitimate objective;
the design of the measure;
its competitive effects;
whether restrictive elements are inherent or necessary;
whether less restrictive alternatives exist.
Lesson: Legitimate objectives and competition analysis can coexist.
25. Case 8: Commission v Netherlands
C-359/01 (2003)
Facts
The case concerned restrictions involving a publicly controlled undertaking and conditions affecting market access.
Principle
The Court examined national measures that could influence competitive conditions and free movement.
Relevance
The case illustrates the broader principle that governmental intervention in markets can affect competitive neutrality.
For digital sovereignty, this matters where the government:
owns a technology provider;
subsidises a sovereign cloud;
gives preferential procurement treatment;
controls critical infrastructure.
Lesson: Government ownership and procurement preferences can affect competitive conditions and should be structured carefully.
26. Important Distinction: Sovereignty Is Not Automatically Anti-Competitive
It is important not to assume:
Digital sovereignty = competition violation.
That would be incorrect.
Governments may have legitimate reasons for protecting:
national security;
defence data;
intelligence information;
critical infrastructure;
sensitive citizen information;
continuity of government operations.
The competition question is instead:
Is the restriction necessary and proportionate to the legitimate objective, and does it unnecessarily eliminate competitive alternatives?
27. Nationality Requirement vs Security Requirement
This distinction is particularly important.
| Nationality-based requirement | Security-based requirement |
|---|---|
| “Supplier must be domestic” | “Supplier must satisfy specified security controls” |
| May exclude foreign firms automatically | Potentially allows broader competition |
| Simple to administer | Requires verification |
| May be over-inclusive | Can be more targeted |
| Can create domestic concentration | Can preserve competitive choice |
| May be justified in special security situations | Usually focuses directly on the security objective |
The legal assessment depends on the applicable jurisdiction and procurement regime.
28. Competition Risks From Sovereign Cloud Markets
A sovereign cloud programme can create five major risks:
1. Concentration
Only a few providers qualify.
2. Entry barriers
Certification and infrastructure costs discourage new entrants.
3. Lock-in
Government becomes dependent on one provider.
4. Bundling
Cloud, cybersecurity, AI and software are sold together.
5. Reduced innovation
Protected suppliers may face weaker competitive pressure.
29. Competition-Friendly Design of Digital Sovereignty Procurement
A sovereignty policy can be designed to preserve competition.
A. Technology-neutral criteria
Specify the required security or sovereignty outcome rather than a particular supplier.
B. Open standards
Require interoperability.
C. Data portability
Allow migration between qualified suppliers.
D. Multiple suppliers
Use multi-vendor procurement where technically feasible.
E. Separate lots
Divide large contracts into smaller components.
F. Transparent criteria
Publish measurable eligibility requirements.
G. Periodic review
Review whether sovereignty requirements remain necessary.
H. Proportionality
Apply stricter requirements to highly sensitive data and less restrictive requirements to ordinary public information.
30. Sovereignty Tiers
One possible procurement framework is to divide government technology into tiers.
Tier 1 — Highly sensitive
Examples:
defence;
intelligence;
critical national-security systems.
Strict sovereignty requirements may be appropriate.
Tier 2 — Sensitive public data
Examples:
health;
taxation;
identity.
Strong security and governance requirements may be necessary.
Tier 3 — Ordinary government services
Examples:
public websites;
non-sensitive productivity tools.
Competition-enhancing procurement may permit a much broader supplier pool.
This approach can reduce unnecessary exclusion.
31. SME Competition
Large sovereignty requirements may disproportionately affect SMEs.
A small company may have an innovative cybersecurity or cloud product but lack:
multiple data centres;
expensive certifications;
large local infrastructure;
government-scale support capacity.
Therefore, procurement authorities should consider:
smaller lots;
consortium participation;
proportionate certification;
cloud portability;
subcontracting opportunities.
32. Impact on Innovation
Competition is closely connected with innovation.
If government procurement becomes restricted to established sovereign suppliers:
fewer entrants → less competitive pressure → potentially weaker innovation incentives.
Conversely, sovereignty requirements that promote:
open standards;
portability;
interoperability;
modular architecture;
may stimulate innovation because new suppliers can compete for individual components.
33. Strategic Autonomy vs Competitive Neutrality
There are two important policy objectives:
Strategic autonomy
Government wants to avoid excessive dependence on external technology providers.
Competitive neutrality
Government wants suppliers to compete on their merits rather than through artificial preferences.
The challenge is to design procurement rules that pursue strategic autonomy without unnecessarily eliminating competition.
34. Practical Competition Test
Before adopting a digital sovereignty procurement requirement, authorities can ask:
Step 1 — What is the legitimate objective?
Security? Resilience? Privacy? National defence?
Step 2 — What market is affected?
Cloud? AI? Cybersecurity? Data storage? Software?
Step 3 — How many suppliers remain?
Does the requirement eliminate most competitors?
Step 4 — Is nationality actually necessary?
Could the objective be achieved through security requirements instead?
Step 5 — Are there less restrictive alternatives?
Could encryption, auditing or local access controls achieve the same objective?
Step 6 — Does the policy create lock-in?
Can government migrate later?
Step 7 — Is the contract appropriately divided?
Could SMEs compete for separate components?
Step 8 — Is there periodic review?
Technology and security risks change over time.
35. Relationship With Competition Law
The principal competition concerns can be summarised as:
Digital sovereignty requirement
↓
Reduced supplier eligibility
↓
Higher concentration
↓
Higher entry barriers
↓
Reduced competitive pressure
↓
Potentially:
higher prices + lower innovation + reduced choice + vendor lock-in
But there may also be legitimate countervailing benefits:
security + resilience + privacy + strategic autonomy + continuity
Therefore, the analysis must balance the actual procurement objective against the competitive restriction.
36. Revision Table
| Issue | Competition implication |
|---|---|
| Domestic preference | May exclude foreign competitors |
| Data localisation | May increase entry costs |
| Sovereign cloud | May increase concentration |
| Security certification | Can create entry barriers |
| Open source | Can reduce vendor lock-in |
| Proprietary preference | Can restrict technological choice |
| Bundled contracts | May favour large incumbents |
| Long contracts | May foreclose future entrants |
| Interoperability | Promotes contestability |
| Data portability | Reduces switching costs |
| Multi-vendor procurement | Reduces dependency |
| SME access | Increases competitive participation |
| Periodic review | Prevents outdated restrictions |
| Transparency | Reduces arbitrary supplier exclusion |
37. Key Case-Law Principles
| Case | Core principle | Digital sovereignty relevance |
|---|---|---|
| Concordia Bus Finland | Legitimate non-price procurement criteria | Security/sovereignty criteria can be considered |
| EVN/Wienstrom | Objective and transparent award criteria | Sovereignty criteria should be measurable |
| Commission v Italy | Domestic preferences can affect market access | Nationality-based exclusion requires justification |
| Telaustria | Transparency in public contracting | Strategic procurement should remain transparent |
| Pressetext | Material contract modifications may require new procurement | Prevents indefinite expansion of incumbent contracts |
| Fastweb | Effective procurement remedies | Competitors need meaningful review mechanisms |
| Meca-Medina | Legitimate objectives do not end competition analysis | Security objectives must be assessed with competitive effects |
| Commission v Netherlands | State measures can affect competitive conditions | State-backed sovereign suppliers require competitive scrutiny |
38. Conclusion
Digital sovereignty procurement policies can pursue legitimate objectives while simultaneously creating competition risks.
The major risks are:
supplier exclusion;
market concentration;
entry barriers;
domestic supplier protection;
cloud and infrastructure lock-in;
bundling;
reduced SME participation;
reduced innovation.
The most competition-sensitive approach is generally to distinguish the sovereignty objective from the nationality of the supplier. Requirements based on measurable security, resilience, interoperability, data governance and operational control can potentially preserve more competition than blanket domestic-preference rules.
Ultra-short exam formula
Digital Sovereignty Procurement → Security/Autonomy Objective → Supplier Eligibility → Market Access → Concentration → Entry Barriers → Lock-in → Innovation/Price Effects → Proportionality + Less Restrictive Alternatives.
Key authorities: Concordia Bus Finland, EVN/Wienstrom, Commission v Italy, Telaustria, Pressetext, Fastweb, Meca-Medina, and Commission v Netherlands.

comments