Putting data sovereignty into practice: 6 steps for SMEs
Does your company rely on Microsoft and other international cloud platforms? You are not alone: These systems are well established, employees know how to use them, and switching during day-to-day operations often seems unrealistic.
But do you know exactly which sensitive data these systems process? Do you know the providers, subprocessors, and jurisdictions involved? And could you switch to an alternative quickly if a service failed, authorities compelled access, or political conditions changed? If you cannot answer these questions clearly, your systems are not necessarily insecure. But your company may not have full control over its data and dependencies.
Aware of the dependency – what now?
Awareness of digital dependencies is growing: According to the Bitkom Cloud Report 2026, 85% of the companies surveyed believe Germany is too dependent on U.S. cloud providers. Almost two-thirds of cloud users are reconsidering their cloud strategy because of U.S. government policy. At the same time, 59% cite lock-in effects such as difficult data exports or complex migrations as the biggest barrier to switching providers.
The initial conclusion seems clear: Companies need German and European alternatives. In practice, however, migration often appears nearly impossible during ongoing operations – too expensive and too complex. Existing systems are closely tied to business processes, employees are familiar with the applications, and there is not always an immediately equivalent alternative for every service. These demands are especially challenging for small and medium-sized businesses (SMEs).
The good news is that this does not have to bring progress to a halt. Data sovereignty begins when companies create transparency around their data and dependencies, prioritize risks, and gain tighter control over particularly critical data flows. Think of data sovereignty as a process, not as replacing every IT system – despite how often the topic is framed that way. The following six steps show how SMEs can move forward in practice.
Step 1: Map data, applications, and service providers
Anyone who wants more control over company data first needs to know where it is processed. That sounds obvious, but in organically grown IT environments the answer is often incomplete. In addition to officially introduced business systems, companies often use other services, including:
cloud storage used by individual departments,
free file-sharing services,
external project platforms,
communication and collaboration tools,
applications used by tax advisors, agencies, or IT service providers,
and software that relies on additional subprocessors and cloud components.
Then there is shadow IT: Employees use applications that are readily available and easy to operate but have never been centrally reviewed or approved. This often creates data flows that management or IT does not know about – especially when employees send large files or collaborate with external parties.
Start by recording a few basic facts for every relevant application:
What data is processed in the application?
Who uses the system?
Who is responsible for the application?
Which provider operates it?
Where is the data stored?
Which other services receive the data?
Can the data be exported in full?
Result of this step: Your company has a clear, traceable overview of its most important data sets, applications, and external service providers.
Step 2: Assess protection needs and business criticality
The level of control required depends on the type of data and how it is used. A structured prioritization is more effective than a blanket rule. Processing every data set in one specific environment? For many SMEs, that is neither necessary nor economical.
The following types of data are particularly critical:
trade secrets and intellectual property,
development and research data,
contracts and transaction documents,
financial and tax information,
HR documents,
personal customer and patient data,
board and strategy documents,
and documents whose temporary unavailability would disrupt business operations.
Two straightforward questions help with the assessment:
What harm would result if unauthorized parties accessed this data?
What harm would result if the data or the associated system were unavailable for several days?
These questions help you distinguish between confidentiality requirements and operational criticality. An internal strategy document primarily needs protection from unauthorized access. A project platform used every day can be business-critical even when the content stored there is less sensitive.
This distinction helps you define requirements in line with the actual risk. Highly sensitive data may require stricter access rights, traceable activity, and controlled sharing. For business-critical systems, availability, recovery, and alternative access paths take priority.
Result of this step: You know which data and processes to address first.
Step 3: Review the full lifecycle of sensitive files
For data sovereignty, where data is stored matters – and so does what happens while it is being used and shared. Review the full lifecycle of particularly sensitive documents:
Data at rest
Start with storage:
Where is the file stored?
Is it encrypted?
Who can view, edit, or delete it?
Are backups and a deletion policy in place?
Are older versions retained in a controlled manner?
Data in use
Next, review what happens during collaboration:
Are files sent back and forth by email, for example?
Are multiple uncontrolled versions created?
Do external users have the same permissions as internal employees?
Can access be traced later?
Are permissions revoked when a project ends?
Data in transit
Control is particularly easy to lose when data is shared externally. Typical examples include:
email attachments,
open download links or links with no expiration date,
personal file-sharing accounts,
uploads to customer or service provider platforms,
uploads to collaboration platforms such as Microsoft Teams,
and locally stored copies held by external project partners.
Once a file leaves the company, you should be able to trace who received and downloaded it, how long access remains available, and whether the recipient was clearly verified. This gives you visibility into the full journey of sensitive data – from creation and collaborative use to sharing and eventual deletion.
Result of this step: You identify the specific points where control over sensitive data is lost – or could be lost.
Step 4: Assess providers and dependencies
To evaluate a service provider reliably, you need to know who is behind the service and which other parties its delivery depends on. Your review should cover three levels.
Legal dependency
Where is the provider headquartered?
Who owns the company?
Which laws apply to the provider and its owners?
In which countries is the data processed?
What forms of government access could apply?
Technical dependency
Which cloud infrastructure and subprocessors are used?
Can the provider technically access customer data?
How is data transferred and stored?
Which authentication and permission controls are available?
How are security incidents detected and communicated?
Operational dependency
Can data be exported in full and in a usable format?
How much effort would switching providers require?
Which functions, metadata, or logs would be lost?
What happens to remaining data after the contract ends?
Is an alternative available during an extended outage?
Bitkom also recommends a risk-based approach: Companies should understand their critical systems, data, and processes, assess dependencies consciously, and derive measures for architecture, governance, and procurement. Data sovereignty comes from informed decisions and genuine options rather than blanket avoidance of technology.
Result of this step: You assess providers based on the actual level of control and ability to switch – not just features and price.
Step 5: Bring the most critical data flows under control first
Once you have completed the inventory, it usually makes sense to address the most sensitive processes first. Suitable starting points include:
sending confidential or particularly large files,
collaborating with external advisors and project partners,
providing documents for audits,
exchanging contracts and financial documents,
communications involving executive management and boards,
preparing corporate transactions,
and securely storing intellectual property.
These processes can often be moved out of insecure email, cloud, or file-sharing structures without replacing core ERP, CRM, or office systems at the same time. This delivers measurable progress quickly:
sensitive files are stored in a controlled environment,
access is assigned selectively,
external users receive only the permissions they need,
activities remain traceable,
and data is no longer distributed through multiple uncontrolled channels.
This prioritization follows a risk-based approach: The greater the potential harm, the higher the requirements for sovereignty and control.
Result of this step: You achieve a concrete improvement in security and sovereignty without rebuilding the entire IT environment at once.
Step 6: Establish ownership and regular reviews
A core part of data sovereignty is reviewing progress regularly. Providers, ownership structures, technical components, and especially legal frameworks change. New applications and data flows are added all the time.
Assign clear organizational responsibility for the topic. At minimum, a designated person or role should:
maintain an overview of critical data and systems,
review new applications before introduction,
reassess providers and contracts regularly,
review access rights,
document security evidence and attestations,
prepare exit and emergency scenarios,
and ensure employees understand and use approved data channels.
In an SME, this responsibility can sit with IT, data privacy, information security, or executive management, with support from an external service provider. What matters is that ownership is clear and the work does not get lost in day-to-day operations.
A practical review schedule could include:
reviewing access rights immediately after personnel or organizational changes,
reassessing critical providers and contracts at least once a year,
approving new applications before use,
and regularly testing export and emergency procedures in practice.
Result of this step: Data sovereignty becomes part of your organizational processes rather than depending on one-time measures.
Quick check: Where is action most urgent?
Take the quick check: The more often you have to answer “No” to the following questions, the more urgent your need for action:
Do you know where your most sensitive data is stored?
Do you know every cloud and file-sharing service your employees use?
Do you know which companies own and control these services?
Can you trace who viewed or downloaded confidential files?
Can you export data in full from your most important cloud systems?
Is an alternative available if a business-critical service fails?
Are responsibilities for providers, access rights, and data flows clearly assigned?
Are external permissions reliably revoked when a project ends?
Important: This quick check does not replace a full assessment. For further guidance and information, Bitkom provides a practical guide (only available in German).
How netfiles strengthens control over critical data flows
netfiles helps companies manage particularly sensitive document processes in a controlled environment without replacing their entire existing IT infrastructure. netfiles data rooms enable confidential files to be stored centrally, shared with internal and external participants, and controlled through clearly defined roles and permissions. Activities remain traceable, while documents no longer need to be distributed through unstructured email attachments or open cloud folders.
netfiles Send is designed for the simple and secure transfer of large and confidential files. Files and folders of up to 150 GB can be provided through protected download links. Options such as expiration dates, receipt confirmation, password protection, and email verification provide greater control at external transfer points.
netfiles is headquartered, developed, and hosted in Germany. netfiles is certified to ISO/IEC 27001 and ISO 22301 and holds independent BSI C5 and SOC 2 attestations.
netfiles is especially suitable for processes that require sensitive data to be stored securely, used collaboratively, or shared externally. SMEs gain a sovereign alternative for the data flows where control, confidentiality, and traceability matter most – without replacing every existing business application.
Conclusion: Data sovereignty starts with one step
The most important point about data sovereignty in one sentence? Do not wait until a “complete” cloud or IT strategy has been agreed – either within your company or by policymakers. Your first, straightforward step is to make your data, systems, and dependencies visible. From there, you can prioritize risks and bring the most critical data flows under greater control.
Data sovereignty develops step by step rather than through a one-time IT overhaul – through transparency and clear priorities, targeted solutions, and the ability to remain operational when conditions change.
Learn more – netfiles is your sovereign data partner
European cloud solutions are not a fallback option – they are the strategic choice for companies that want to retain control over their data.
See for yourself – try netfiles free for 14 days. No U.S. dependency, full functionality. Start your free trial →
Questions about cloud sovereignty? Talk to our team →