The sovereignty stack of European governments
Assumed audience
Citizens curious about where their national government's data is sitting. Digital policy people, public sector IT staff, and anyone working on European sovereignty. No deep technical knowledge is needed.
Following my blog post about the sovereignty of Belgian municipalities, I wanted to take a higher-level look.
Now that we've seen how local governments fare (at least in Belgium), what about national ones? These are the institutions that should be pushing for sovereignty.
This is a review of the national government websites of Europe. When a citizen portal is available, I use that first. If there is none, I point the scanner at the main government website.
Contents
What I analysed
The process
Note: the process is near-identical to the one I used for the Belgian municipality scan. If you've already read about it there, feel free to skip straight to the results.
Each national government website got a digital sovereignty score assembled from a series of criteria, each weighted by its relative importance.
I ran the 32 European national government websites through my sovereignty scanner (you can try it on your own site here).
In the results, I consider a service "European" if the company operating it has its legal headquarters in Europe. That means EU member states, but also the UK, Switzerland, Norway and Iceland, who share similar data protection frameworks and legal traditions with the EU.
What really counts is jurisdiction, not where the servers are physically located. A US-headquartered vendor counts as non-European even if its data centre is in Frankfurt. This is due to laws like the CLOUD Act.
A few caveats: this is not gospel, and certainly not scientific research. A government may rely on plenty of potentially non-European tools that simply don't show up in a scan like this; like cloud storage or video conferencing. Some elements might be misidentified, others missed completely. Please read the post in that spirit.
It's also a snapshot (currently from August 17th 2026) – things change.
The criteria
Email provider 25%
Email is one of the most sensitive layers and one of the hardest to migrate once it's entrenched.
The government's email provider is detected via various means (MX, SPF, autodiscover…) and rated based on its legal jurisdiction.
Website host 25%
This detects where the government website and, by extension data, lives, legally speaking.
This is done via looking up the hosting provider's ASN (autonomous system number) and figuring out what organisation is behind it. This tells me which legal entity is operating the infrastructure, not just the physical location of the server.
A server located in Europe but operated by a US cloud provider, for example, will be considered non-European.
If a service like Cloudflare is sitting in front of the website, it counts as a point of foreign control, even if the origin host is located in Europe.
Domain registrar 15%
The registrar controls the domain itself. It's where you renew it, transfer it, or… have it seized or suspended under a foreign legal order.
This doesn't weigh as much as email and hosting because losing your registrar is disruptive, but will rarely expose citizen data etc.
This one is a control risk rather than a privacy one.
DNS (domain name system) host 10%
This checks who operates the authoritative name servers for the domain. What these do is answer "where is this government's website/email server located?" when a device looks them up.
This gets scored by jurisdiction like the rest. It's weighted lower because switching DNS providers is relatively simple compared to, say, email.
SSL certificate 5%
The SSL certificate is responsible for the encryption of a citizen's connection to a website. That's what the padlock in the browser address bar indicates.
The authority responsible for issuing these certificates is the least important of all the categories tracked here. They're easy to swap and I include them mainly for completeness.
Third-party resources 20%
Modern websites rarely stand on their own and this includes government sites.
They load all manner of things from external (third-party) servers: fonts, analytics scripts, chat widgets, social media trackers, and so much more.
Each one of those is a potential exit path for visitor data to leave Europe, regardless of where the site itself is hosted.
These resources are scanned and, for the most part, identified using a local database complemented by Ghostery's TrackerDB.
The score is then established based on the proportion of these resources that are European or not.
The results
A full table of all results is included at the bottom of this post.
Sovereignty score
The scores start at 3.9 (Malta – the worst) and go up to 100 (Austria, Germany, Hungary, Luxembourg, Latvia and Romania – all tied at the top), with an average of 63.1 out of 100.
It's far from perfect, but it's better than the average of 49.2 from the Belgian municipalities scan. National governments should have more awareness of sovereignty issues, so that does make sense.
The spread is wide, though. Here are the best and worst:
The countries sitting at the top all run their own email and hosting infrastructure. No Microsoft, Amazon, Google, or Cloudflare. Proof that it's perfectly feasible.
At the other end, Malta (3.9) and Iceland (5.9) are pretty much running their online infrastructure through the US. Portugal (11.8) and the UK (15.4) aren't that far behind.
Email is interesting here: 75% of national governments host their email at a European provider. A lot better than what I've seen on a local level (for example: only 12.1% in Belgium were European).
We're still nowhere near perfection, however. Microsoft 365 is the email platform of choice for 8 out of 32 governments. So, 25% of national governments' internal and citizen emails go through a US-headquartered provider.
The countries doing well mostly seem to run their infrastructure through their own government IT agencies: Bundesrechenzentrum for Austria, Statens IT for Denmark, DILA for France,… The rest is mostly a mix of self-hosted setups.
Hosting
Where hosting is concerned, the situation isn't as good: 56.3% score European.
Cloudflare sits in front of 5 out of 32 government sites. Even when the server behind it is European, Cloudflare's position in front counts as a point of foreign control where traffic is handed off in an unencrypted state. AWS, Azure and Akamai host a few more and probably some of the ones hidden behind cloudflare (see below).
These are governments that have explicitly chosen US hyperscalers for their website (or believed their "European sovereign cloud" marketing).
For the 7 sites sitting behind a proxy like Cloudflare, I tried to guess the origin host by using historical data. This is a low-confidence guess and should be taken as directional at best.
Third-party resources
Among every type of third-party resource, not just analytics, these five turn up the most. As always, Google dominates.
What's notable is the non-European resource count: 83 non-EU resources across 32 government websites. That's out of 128 total resources detected. Roughly two-thirds.
Analytics
Analytics-wise, Google dominates here as well. But self-hosted Matomo instances have a very respectable second place. Microsoft Clarity makes an appearance too.
Registrars & DNS
Registrars are the category most often unknown, with 11 of 32 governments not exposing registrar info in a way the scanner can pick up. Of those identified, 62.5% are European. The undetected ones are probably European too, national registrars seem to hide better than regular ones.
DNS tells a similar story: 81.3% European, with Cloudflare being the most common non-European provider. When Cloudflare sits in front of a site, they typically handle DNS too, merging two categories into one foreign dependency.
SSL certificates
Only 25% of certificates are European. DigiCert, an American company, dominates the ranking with 6 of 32 governments using it. Amazon Trust Services (4) and Sectigo (3) follow next.
Harica, a Greek certificate authority, is the only European player with a meaningful presence. As for municipalities, this is the lowest-weighted category because switching certificate authority is relatively trivial.
Conclusion
So, what's the take-away? With an average score of 63.1/100, European national governments are above-average. Certainly compared to municipal websites in Belgium, anyway.
Email, the heaviest category, is decent at 75% European. National governments have the institutional capacity to run their own email, and many do. This is in stark contrast to municipalities where Microsoft 365 dominates (at least in the countries I tested).
Hosting, on the other hand, is not great at 56.3% European. That's actually worse than the municipalities I tested. National governments are more likely to have adopted US hyperscalers or stuck Cloudflare in front of their sites.
Registrars and DNS are mixed bags. SSL is predictably American-dominated but it's also low-stakes.
The countries at the top of the scoreboard mostly run their own IT infrastructure through dedicated government agencies. A few buy local.
The ones at the bottom lean heavily on Microsoft and US clouds. Malta practically being a US-dependency.
Defaults are sticky, even for governments.
Conclusion? Could do better and be an example.
Full results table
32 countries
| Website | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| Austria | https://www.oesterreich.gv.at/ | 100.0 | Bundesrechenzentrum [EU] | Bundesrechenzentrum [EU] | – | Bundeskanzleramt [EU] | Bundesrechenzentrum [EU] | Harica [EU] | 0 / 0 |
| Germany | https://verwaltung.bund.de/ | 100.0 | Bundesregierung [EU] | Myra Security [EU] | – | Unknown [non-EU] | DFN [EU] | D-TRUST [EU] | 0 / 0 |
| Hungary | https://www.magyarorszag.hu/ | 100.0 | Kopint-Datorg Zrt. [EU] | NISZ [EU] | – | Unknown [non-EU] | Hungarian Government [EU] | Microsec [EU] | 0 / 0 |
| Luxembourg | https://guichet.lu/ | 100.0 | Centre des technologies de l'information de l'Etat [EU] | Centre des technologies de l'information de l'Etat [EU] | – | EuroDNS [EU] | Centre des technologies de l'information de l'Etat [EU] | Harica [EU] | 0 / 5 |
| Latvia | https://www.latvija.lv/ | 100.0 | Latvian government [EU] | VAS Latvijas Valsts radio un televizijas centrs [EU] | – | Unknown [non-EU] | nic.lv [EU] | – | 0 / 3 |
| France | https://www.service-public.gouv.fr/ | 95.0 | DILA [EU] | Worldline [EU] | – | NameShield [EU] | DILA [EU] | Sectigo [non-EU] | 0 / 2 |
| Netherlands | https://mijn.overheid.nl/ | 95.0 | Dutch Government [EU] | baten-lastendienst Logius [EU] | – | Dutch Government [EU] | Logius [EU] | DigiCert [non-EU] | 0 / 1 |
| Poland | https://www.gov.pl/ | 90.0 | Polish Government [EU] | Centralny Osrodek Informatyki [EU] | – | NASK [EU] | NASK [EU] | Certum [EU] | 1 / 2 |
| Romania | https://gov.ro/ | 78.9 | Government of Romania [EU] | STS [EU] | – | ICI [EU] | STS [EU] | – | 4 / 4 |
| Belgium | https://www.belgium.be/ | 75.0 | Federal Government [EU] | Belnet [EU] | – | Belgian Government [EU] | Akamai [non-EU] | Harica [EU] | 3 / 4 |
| Croatia | https://gov.hr/ | 75.0 | Vlada Republike Hrvatske [EU] | HITRONet [EU] | – | CARNET [EU] | CARNET [EU] | Entrust [non-EU] | 6 / 6 |
| Norway | https://www.norge.no/ | 75.0 | Microsoft 365 [non-EU] | Sognenett [EU] | – | iteam [EU] | iteam [EU] | Buypass [EU] | 0 / 5 |
| Slovenia | https://e-uprava.gov.si/ | 75.0 | Government of the Republic of Slovenia [EU] | Ministry of Digital Transformation [EU] | – | Ministrstvo za notranje zadeve in javno upravo [EU] | Government of the Republic of Slovenia [EU] | Entrust [non-EU] | 4 / 7 |
| Slovakia | https://slovensko.sk/ | 75.0 | Slovak public authorities [EU] | National Agency for Network and Electronic Services [EU] | – | NASES [EU] | Slovak public authorities [EU] | DigiCert [non-EU] | 6 / 6 |
| Bulgaria | https://egov.bg/ | 74.5 | Bulgarian Government [EU] | ESMIS [EU] | – | Unknown [non-EU] | Bulgarian government [EU] | Let's Encrypt [non-EU] | 5 / 6 |
| Denmark | https://www.borger.dk/ | 70.6 | Statens IT [EU] | GlobalConnect [EU] | – | Unknown [non-EU] | Statens IT [EU] | Sectigo [non-EU] | 1 / 1 |
| Sweden | https://www.regeringen.se/ | 63.3 | Government Offices (Regeringskansliet) [EU] | Cloudflare [non-EU] | – | Excedo [EU] | Excedo [EU] | DigiCert [non-EU] | 2 / 8 |
| Finland | https://www.suomi.fi/ | 62.5 | Valtori [EU] | Amazon Web Services [non-EU] | – | Valtori [EU] | Sonera [EU] | Amazon Trust Services [non-EU] | 0 / 0 |
| Ireland | https://www.gov.ie/ | 62.5 | Government of Ireland [EU] | Amazon Web Services [non-EU] | Amazon Web Services [non-EU] | Department of Public Expenditure [EU] | Government of Ireland [EU] | Amazon Trust Services [non-EU] | 0 / 0 |
| Switzerland | https://www.ch.ch/ | 60.0 | Swiss Federal Administration [EU] | Amazon Web Services [non-EU] | Amazon Web Services [non-EU] | Hostpoint [EU] | Hostpoint [EU] | Amazon Trust Services [non-EU] | 1 / 2 |
| Spain | https://administracion.gob.es/ | 58.8 | Ministerio de Transformación Digital y de la Función Pública [EU] | Ministerio de Transformacion Digital y de la Funcion Publica [EU] | – | Unknown [non-EU] | Cloudflare [non-EU] | Unknown CA [non-EU] | 4 / 4 |
| Czechia | https://portal.gov.cz/ | 53.3 | Microsoft 365 [non-EU] | Govcz - Ministerstvo Vnitra Cr [EU] | – | regZone [EU] | CZ Domain Registry [EU] | DigiCert [non-EU] | 5 / 8 |
| Estonia | https://www.eesti.ee/ | 50.0 | Estonian State Portal [EU] | Cloudflare [non-EU] | – | Zone [EU] | RcodeZero [EU] | Google Trust Services [non-EU] | 1 / 1 |
| Italy | https://www.governo.it/ | 45.0 | Microsoft 365 [non-EU] | Akamai [non-EU] | Telecom Italia [EU] | Reevo [EU] | Italian Government [EU] | DigiCert [non-EU] | 0 / 2 |
| Lithuania | https://www.epaslaugos.lt/ | 45.0 | Elektroniniai valdžios vartai [EU] | Cloudflare [non-EU] | – | Kaunas University of Technology [EU] | Cloudflare [non-EU] | PerfectSSL [EU] | 1 / 1 |
| Liechtenstein | https://www.llv.li/ | 44.0 | Self-hosted (Liechtensteinische Landesverwaltung) [EU] | Cloudflare [non-EU] | Abraxas Informatik [EU] | Swizzonic [EU] | Cloudflare [non-EU] | Google Trust Services [non-EU] | 4 / 7 |
| Greece | https://www.gov.gr/ | 41.2 | Self-hosted (Microsoft Exchange (OWA)) [EU] | Akamai [non-EU] | Microsoft Azure [non-EU] | – | Foundation for Research and Technology [EU] | Let's Encrypt [non-EU] | 7 / 8 |
| Cyprus | https://www.gov.cy/ | 17.6 | Microsoft 365 [non-EU] | Microsoft Azure [non-EU] | – | – | ClouDNS [EU] | DigiCert [non-EU] | 3 / 4 |
| United Kingdom | https://www.gov.uk/ | 15.4 | Microsoft 365 [non-EU] | Fastly [non-EU] | Amazon Web Services [non-EU] | Nominet UK [non-EU] | Nominet [EU] | GlobalSign [non-EU] | 0 / 0 |
| Portugal | https://www.gov.pt/ | 11.8 | Microsoft 365 [non-EU] | Microsoft Azure [non-EU] | – | Unknown [non-EU] | .PT [EU] | GlobalSign [non-EU] | 2 / 2 |
| Iceland | https://island.is/ | 5.9 | Microsoft 365 [non-EU] | Amazon Web Services [non-EU] | – | Unknown [non-EU] | Amazon Route 53 [non-EU] | Amazon Trust Services [non-EU] | 3 / 4 |
| Malta | https://www.servizz.gov.mt/ | 3.9 | Microsoft 365 [non-EU] | Cloudflare [non-EU] | Malta Information Technology Agency (MITA) [EU] | – | Azure DNS [non-EU] | Sectigo [non-EU] | 20 / 25 |
Data collected August 2026 with my digital sovereignty scanner.
Found an error or an outdated result for your country? Let me know.