Competition Implications Of Digital Sovereignty Procurement Policies .

Competition Implications of Digital Sovereignty Procurement Policies

1. Meaning

Digital sovereignty procurement policies are government purchasing policies designed to ensure that public authorities retain control over important digital infrastructure, data, software, cloud services, cybersecurity systems, AI systems, and other technological capabilities.

A government may, for example, require public bodies to prefer or purchase:

locally controlled cloud infrastructure;

domestic or regional data-hosting services;

open-source software;

sovereign cloud services;

locally developed cybersecurity products;

technology from suppliers satisfying particular data-localisation requirements;

interoperable and portable digital systems;

suppliers that guarantee governmental control over critical data.

The policy objective may be security, resilience, strategic autonomy, privacy, continuity of government services, or reduction of foreign dependency.

From a competition-law perspective, however, these policies can create an important tension:

A procurement rule designed to increase digital sovereignty can simultaneously reduce the number of suppliers capable of competing for government contracts.

Therefore, the central competition question is not whether digital sovereignty is legitimate. The question is how the procurement requirement is designed and whether it unnecessarily forecloses competition.

2. Why Digital Sovereignty and Competition Can Conflict

Traditional public procurement attempts to obtain goods and services through competition.

Digital sovereignty policies may instead prioritise:

domestic suppliers;

locally hosted infrastructure;

national ownership;

local data processing;

domestic security certification;

government-controlled infrastructure.

These requirements can reduce the pool of eligible suppliers.

Example

Suppose a government requires:

“Only cloud providers headquartered in the country may bid for government cloud contracts.”

A foreign cloud provider may be technologically capable of satisfying the government's security requirements but nevertheless be excluded.

The policy could therefore:

increase sovereignty → reduce eligible suppliers → reduce competitive pressure → potentially increase prices.

This does not automatically make the procurement rule unlawful. The legal analysis depends on the applicable procurement, competition, trade, security and public-interest rules.

3. Main Competition Implications

A. Supplier Exclusion

The most obvious concern is the exclusion of suppliers based on nationality, ownership, location or corporate structure.

A requirement may be legitimate if genuinely necessary for:

national security;

confidential government information;

critical infrastructure;

cybersecurity;

operational resilience.

But a broad nationality requirement can have greater competitive effects than a technology-neutral security requirement.

Example

Compare:

Rule A

“Supplier must be domestically owned.”

with:

Rule B

“Supplier must satisfy specified security, data-control, audit and continuity requirements.”

Rule B potentially allows more suppliers to compete while pursuing the same sovereignty objective.

4. Market Concentration

Digital sovereignty procurement can unintentionally create supplier concentration.

If only a few domestic companies satisfy the eligibility criteria, government purchasing may become concentrated among them.

This can produce:

higher prices;

weaker innovation incentives;

reduced service quality;

capacity constraints;

dependence on a small group of suppliers.

Ironically, a policy designed to reduce foreign technological dependence can therefore create domestic supplier dependence.

5. Entry Barriers

Sovereignty certification can become an entry barrier.

For example, a new cloud provider may need to satisfy:

local data-centre requirements;

domestic ownership requirements;

security certification;

local personnel requirements;

government auditing;

specialised encryption standards.

These requirements can be expensive.

Large incumbent firms may therefore possess an advantage over smaller competitors.

6. Competition Between Domestic and Foreign Suppliers

A digital sovereignty policy can alter the competitive relationship between:

domestic suppliers;

foreign suppliers;

multinational technology companies;

joint ventures;

cloud providers;

open-source providers;

systems integrators.

The competition question is whether the procurement framework creates a level playing field or gives a particular category of supplier an artificial advantage.

7. Sovereign Cloud Procurement

Cloud services are particularly important.

Governments may demand:

domestic data centres;

local administrative control;

local encryption keys;

local ownership of infrastructure;

restrictions on foreign government access;

domestic incident-response teams.

These requirements may serve legitimate sovereignty purposes.

But they can also affect competition by:

reducing the number of eligible providers;

increasing fixed costs;

preventing foreign providers from bidding;

favouring established domestic providers;

increasing switching costs;

encouraging concentration.

8. Data Localisation and Competition

Data localisation requires data to be stored or processed within a particular jurisdiction.

It may improve governmental control over sensitive information.

However, it can also create:

infrastructure duplication;

higher costs;

reduced economies of scale;

barriers to foreign cloud providers;

reduced cross-border service competition.

A competition analysis should therefore distinguish between:

necessary localisation and unnecessarily broad localisation.

9. Open-Source Procurement

Digital sovereignty policies sometimes favour open-source software because it may provide:

source-code transparency;

reduced vendor dependence;

interoperability;

customisation;

portability;

greater government control.

From a competition perspective, open-source procurement can reduce proprietary vendor lock-in.

However, an exclusive preference for a particular technological model can itself exclude innovative proprietary solutions.

The better competition question is often:

Does the procurement rule promote interoperability and contestability, or does it simply replace one preferred supplier category with another?

10. Vendor Lock-In

Digital sovereignty policies frequently attempt to reduce dependence on foreign technology vendors.

However, a poorly designed sovereign system can create domestic lock-in.

Example

Government chooses one sovereign cloud provider.

After several years:

government applications are customised to that cloud;

data is stored in proprietary formats;

employees are trained on the provider's system;

APIs are provider-specific;

migration becomes expensive.

The government may then become dependent on the supposedly sovereign supplier.

Therefore:

Sovereignty without portability can produce a different form of dependency.

11. Interoperability as a Competition Tool

Procurement authorities can reduce lock-in through:

open standards;

API interoperability;

data portability;

exit rights;

migration assistance;

common technical standards.

These requirements can make the government market more contestable.

For example, a procurement contract could require:

“The supplier must provide documented APIs and enable reasonable migration of government data to another qualified provider.”

This may preserve sovereignty while maintaining competitive pressure.

12. Procurement Bundling

Digital sovereignty procurement can involve large bundles containing:

cloud infrastructure;

cybersecurity;

AI;

data storage;

identity management;

networking;

software;

technical support.

Large bundles may favour incumbent technology companies because smaller firms cannot provide the entire package.

Competition concerns may include:

tying;

bundling;

foreclosure;

reduced SME participation;

higher entry costs.

Authorities should consider whether contracts can be divided into separate lots.

13. Framework Agreements

Government framework agreements can also affect competition.

If a framework selects only two or three suppliers for several years, those suppliers may obtain substantial advantages.

Potential consequences include:

customer foreclosure;

reduced opportunities for new entrants;

reduced competitive pressure;

increased supplier concentration.

Long framework periods can make these effects stronger.

14. Strategic Procurement and Dominant Suppliers

Suppose a government already represents a very large share of demand for a specialised technology.

If procurement rules favour only a few suppliers, those suppliers may acquire significant bargaining power.

The government can then move from:

buyer power → supplier concentration → supplier bargaining power.

Competition analysis should therefore consider the structure of both sides of the market.

15. Public Procurement and Article 101 TFEU

In the EU context, procurement can interact with Article 101 TFEU, which prohibits agreements between undertakings that restrict competition.

For example, competing technology suppliers could potentially coordinate:

bids;

prices;

territories;

tender participation;

market allocation.

A sovereignty procurement programme does not legitimise supplier collusion.

16. Article 102 TFEU

Where a technology supplier has a dominant position, its conduct may also raise Article 102 TFEU issues.

Possible concerns include:

exclusionary contracts;

discriminatory access;

tying;

refusal to provide interoperability;

margin squeeze;

loyalty-inducing arrangements.

A procurement authority should therefore avoid designing contracts that unintentionally strengthen an already dominant supplier without adequate competitive safeguards.

17. Public Procurement Principles

In the EU, public procurement generally emphasises principles including:

transparency;

equal treatment;

non-discrimination;

proportionality;

competition.

Digital sovereignty requirements therefore need careful design.

A requirement should ideally have a demonstrable relationship with the procurement objective.

18. Case Law

Case 1: Concordia Bus Finland Oy Ab v Helsingin Kaupunki

C-513/99 (2002)

Facts

The case concerned public procurement criteria used by the City of Helsinki for bus services, including environmental considerations.

Principle

The CJEU accepted that contracting authorities can consider criteria pursuing objectives beyond the lowest immediate price, provided the criteria are connected with the subject matter and comply with procurement principles.

Relevance to digital sovereignty

This provides an important analogy.

A government may potentially pursue legitimate objectives such as:

cybersecurity;

resilience;

data control;

technological continuity.

But the sovereignty criterion should be connected to the procurement objective and applied transparently.

Lesson: Public procurement can pursue broader public objectives, but procurement criteria must remain legally defensible and proportionate.

19. Case 2: EVN AG and Wienstrom GmbH

C-448/01 (2003)

Facts

The procurement authority used environmental criteria when selecting electricity suppliers.

Principle

The CJEU accepted the use of environmental considerations but stressed requirements concerning transparency, verification and connection with the subject matter of the contract.

Relevance

The case is useful by analogy for digital sovereignty.

A government cannot simply state:

“This supplier is more sovereign.”

It should identify measurable criteria such as:

data-location requirements;

access-control requirements;

encryption;

operational control;

security certification;

continuity requirements.

Lesson: Sovereignty criteria should be objectively measurable and transparent.

20. Case 3: Commission v Italy

C-3/88 (1990)

Facts

Italy imposed restrictions favouring domestic production in a way that affected the free movement of goods.

Principle

The CJEU examined national measures that disadvantaged imported products and treated broad national preferences with suspicion where they impeded the internal market.

Relevance

Although this is not a digital-sovereignty procurement case, it illustrates a fundamental issue:

A government preference for domestic suppliers can affect market access.

A digital procurement rule favouring domestic technology therefore requires careful consideration of whether the nationality criterion is actually necessary.

Lesson: Domestic preference and legitimate public-security objectives should not automatically be treated as equivalent.

21. Case 4: Telaustria and Telefonadress

C-324/98 (2000)

Facts

The case concerned the award of a public-service concession involving telecommunications-related activities.

Principle

The Court emphasised transparency and appropriate publicity in public contracting, particularly where a contract has cross-border economic interest.

Relevance

Digital sovereignty procurement can involve major markets for:

cloud services;

telecommunications;

cybersecurity;

digital infrastructure.

A procurement authority should therefore consider whether its process provides sufficient transparency and market access consistent with applicable procurement rules.

Lesson: Strategic importance does not automatically eliminate procurement transparency obligations.

22. Case 5: Pressetext Nachrichtenagentur GmbH v Republik Österreich

C-454/06 (2008)

Facts

The case concerned modifications to a public contract and whether substantial changes could amount to the award of a new contract without appropriate competitive procedures.

Principle

The CJEU developed important principles concerning when changes to an existing public contract can be sufficiently substantial to require a new procurement process.

Relevance to digital sovereignty

Digital contracts frequently evolve because technology changes.

A government might initially purchase:

cloud storage

and later add:

AI infrastructure + cybersecurity + identity services + analytics.

If changes fundamentally alter the economic scope of the contract, procurement authorities need to consider whether the modifications are legally permissible.

Lesson: Sovereign digital procurement should not become a mechanism for indefinitely expanding an incumbent's contract without competitive review.

23. Case 6: Fastweb SpA v Azienda Sanitaria Locale di Alessandria

C-19/13 (2014)

Principle

The case concerned effective judicial protection in public procurement disputes and the ability of competing tenderers to challenge procurement outcomes.

Relevance

Digital sovereignty procurement can involve enormous contracts.

If a procurement authority excludes competitors through sovereignty requirements, effective review becomes important.

Lesson: Procurement decisions affecting market access should remain subject to appropriate legal scrutiny.

24. Case 7: Meca-Medina and Majcen v Commission

C-519/04 P (2006)

Principle

The CJEU explained that rules pursuing legitimate objectives can still fall within competition-law analysis when their effects restrict competition, although their competitive effects may need to be assessed in context.

Relevance

This provides a useful conceptual framework.

A sovereignty policy may pursue:

cybersecurity;

national resilience;

strategic autonomy.

Those objectives do not automatically answer the competition question.

The analysis should consider:

the legitimate objective;

the design of the measure;

its competitive effects;

whether restrictive elements are inherent or necessary;

whether less restrictive alternatives exist.

Lesson: Legitimate objectives and competition analysis can coexist.

25. Case 8: Commission v Netherlands

C-359/01 (2003)

Facts

The case concerned restrictions involving a publicly controlled undertaking and conditions affecting market access.

Principle

The Court examined national measures that could influence competitive conditions and free movement.

Relevance

The case illustrates the broader principle that governmental intervention in markets can affect competitive neutrality.

For digital sovereignty, this matters where the government:

owns a technology provider;

subsidises a sovereign cloud;

gives preferential procurement treatment;

controls critical infrastructure.

Lesson: Government ownership and procurement preferences can affect competitive conditions and should be structured carefully.

26. Important Distinction: Sovereignty Is Not Automatically Anti-Competitive

It is important not to assume:

Digital sovereignty = competition violation.

That would be incorrect.

Governments may have legitimate reasons for protecting:

national security;

defence data;

intelligence information;

critical infrastructure;

sensitive citizen information;

continuity of government operations.

The competition question is instead:

Is the restriction necessary and proportionate to the legitimate objective, and does it unnecessarily eliminate competitive alternatives?

27. Nationality Requirement vs Security Requirement

This distinction is particularly important.

Nationality-based requirementSecurity-based requirement
“Supplier must be domestic”“Supplier must satisfy specified security controls”
May exclude foreign firms automaticallyPotentially allows broader competition
Simple to administerRequires verification
May be over-inclusiveCan be more targeted
Can create domestic concentrationCan preserve competitive choice
May be justified in special security situationsUsually focuses directly on the security objective

The legal assessment depends on the applicable jurisdiction and procurement regime.

28. Competition Risks From Sovereign Cloud Markets

A sovereign cloud programme can create five major risks:

1. Concentration

Only a few providers qualify.

2. Entry barriers

Certification and infrastructure costs discourage new entrants.

3. Lock-in

Government becomes dependent on one provider.

4. Bundling

Cloud, cybersecurity, AI and software are sold together.

5. Reduced innovation

Protected suppliers may face weaker competitive pressure.

29. Competition-Friendly Design of Digital Sovereignty Procurement

A sovereignty policy can be designed to preserve competition.

A. Technology-neutral criteria

Specify the required security or sovereignty outcome rather than a particular supplier.

B. Open standards

Require interoperability.

C. Data portability

Allow migration between qualified suppliers.

D. Multiple suppliers

Use multi-vendor procurement where technically feasible.

E. Separate lots

Divide large contracts into smaller components.

F. Transparent criteria

Publish measurable eligibility requirements.

G. Periodic review

Review whether sovereignty requirements remain necessary.

H. Proportionality

Apply stricter requirements to highly sensitive data and less restrictive requirements to ordinary public information.

30. Sovereignty Tiers

One possible procurement framework is to divide government technology into tiers.

Tier 1 — Highly sensitive

Examples:

defence;

intelligence;

critical national-security systems.

Strict sovereignty requirements may be appropriate.

Tier 2 — Sensitive public data

Examples:

health;

taxation;

identity.

Strong security and governance requirements may be necessary.

Tier 3 — Ordinary government services

Examples:

public websites;

non-sensitive productivity tools.

Competition-enhancing procurement may permit a much broader supplier pool.

This approach can reduce unnecessary exclusion.

31. SME Competition

Large sovereignty requirements may disproportionately affect SMEs.

A small company may have an innovative cybersecurity or cloud product but lack:

multiple data centres;

expensive certifications;

large local infrastructure;

government-scale support capacity.

Therefore, procurement authorities should consider:

smaller lots;

consortium participation;

proportionate certification;

cloud portability;

subcontracting opportunities.

32. Impact on Innovation

Competition is closely connected with innovation.

If government procurement becomes restricted to established sovereign suppliers:

fewer entrants → less competitive pressure → potentially weaker innovation incentives.

Conversely, sovereignty requirements that promote:

open standards;

portability;

interoperability;

modular architecture;

may stimulate innovation because new suppliers can compete for individual components.

33. Strategic Autonomy vs Competitive Neutrality

There are two important policy objectives:

Strategic autonomy

Government wants to avoid excessive dependence on external technology providers.

Competitive neutrality

Government wants suppliers to compete on their merits rather than through artificial preferences.

The challenge is to design procurement rules that pursue strategic autonomy without unnecessarily eliminating competition.

34. Practical Competition Test

Before adopting a digital sovereignty procurement requirement, authorities can ask:

Step 1 — What is the legitimate objective?

Security? Resilience? Privacy? National defence?

Step 2 — What market is affected?

Cloud? AI? Cybersecurity? Data storage? Software?

Step 3 — How many suppliers remain?

Does the requirement eliminate most competitors?

Step 4 — Is nationality actually necessary?

Could the objective be achieved through security requirements instead?

Step 5 — Are there less restrictive alternatives?

Could encryption, auditing or local access controls achieve the same objective?

Step 6 — Does the policy create lock-in?

Can government migrate later?

Step 7 — Is the contract appropriately divided?

Could SMEs compete for separate components?

Step 8 — Is there periodic review?

Technology and security risks change over time.

35. Relationship With Competition Law

The principal competition concerns can be summarised as:

Digital sovereignty requirement

↓

Reduced supplier eligibility

↓

Higher concentration

↓

Higher entry barriers

↓

Reduced competitive pressure

↓

Potentially:

higher prices + lower innovation + reduced choice + vendor lock-in

But there may also be legitimate countervailing benefits:

security + resilience + privacy + strategic autonomy + continuity

Therefore, the analysis must balance the actual procurement objective against the competitive restriction.

36. Revision Table

IssueCompetition implication
Domestic preferenceMay exclude foreign competitors
Data localisationMay increase entry costs
Sovereign cloudMay increase concentration
Security certificationCan create entry barriers
Open sourceCan reduce vendor lock-in
Proprietary preferenceCan restrict technological choice
Bundled contractsMay favour large incumbents
Long contractsMay foreclose future entrants
InteroperabilityPromotes contestability
Data portabilityReduces switching costs
Multi-vendor procurementReduces dependency
SME accessIncreases competitive participation
Periodic reviewPrevents outdated restrictions
TransparencyReduces arbitrary supplier exclusion

37. Key Case-Law Principles

CaseCore principleDigital sovereignty relevance
Concordia Bus FinlandLegitimate non-price procurement criteriaSecurity/sovereignty criteria can be considered
EVN/WienstromObjective and transparent award criteriaSovereignty criteria should be measurable
Commission v ItalyDomestic preferences can affect market accessNationality-based exclusion requires justification
TelaustriaTransparency in public contractingStrategic procurement should remain transparent
PressetextMaterial contract modifications may require new procurementPrevents indefinite expansion of incumbent contracts
FastwebEffective procurement remediesCompetitors need meaningful review mechanisms
Meca-MedinaLegitimate objectives do not end competition analysisSecurity objectives must be assessed with competitive effects
Commission v NetherlandsState measures can affect competitive conditionsState-backed sovereign suppliers require competitive scrutiny

38. Conclusion

Digital sovereignty procurement policies can pursue legitimate objectives while simultaneously creating competition risks.

The major risks are:

supplier exclusion;

market concentration;

entry barriers;

domestic supplier protection;

cloud and infrastructure lock-in;

bundling;

reduced SME participation;

reduced innovation.

The most competition-sensitive approach is generally to distinguish the sovereignty objective from the nationality of the supplier. Requirements based on measurable security, resilience, interoperability, data governance and operational control can potentially preserve more competition than blanket domestic-preference rules.

Ultra-short exam formula

Digital Sovereignty Procurement → Security/Autonomy Objective → Supplier Eligibility → Market Access → Concentration → Entry Barriers → Lock-in → Innovation/Price Effects → Proportionality + Less Restrictive Alternatives.

Key authorities: Concordia Bus Finland, EVN/Wienstrom, Commission v Italy, Telaustria, Pressetext, Fastweb, Meca-Medina, and Commission v Netherlands.

LEAVE A COMMENT