10 August 2026

Digital Sovereignty: France, Europe, Africa, Canada — One Fight, Four Different Paths

Five years ago, talk of “digital sovereignty” was still largely confined to specialist circles. By 2026, it has become a budget line, a procurement criterion, and, at times, a diplomatic flashpoint. The US CLOUD Act, which allows American authorities to demand access to data held by any company under US jurisdiction, wherever in the world that data happens to be stored, has become the point of contention for four regions each, in their own way, seeking to loosen the grip of the GAFAM (Google, Apple, Facebook, Amazon, Microsoft). France and Europe are legislating. Africa is building fast, shortcuts and all. Canada is discovering, sometimes with a jolt, just how dependent it has become on its southern neighbour.

Here is a tour of these four trajectories and what they reveal about a shared struggle being fought at very different speeds. It is a struggle Whaller has been engaged in since its founding, as set out in our Digital Sovereignty hub on the Whaller blog.
 

France, the regulatory laboratory of sovereignty

 
France has taken a clear methodological lead. The SecNumCloud qualification issued by ANSSI, France’s cybersecurity agency, now in its 3.2 version, has established itself as the most credible French answer to the extraterritorial reach of American law, guaranteeing that a cloud service sits beyond the grasp of both the CLOUD Act and FISA. The pace has quickened noticeably in 2026: the national health data platform is now migrating directly to a SecNumCloud-qualified cloud, a Prime Ministerial circular of 5 February requires public administrations to prioritise pooled public solutions first, and the interministerial digital directorate (Dinum) has begun migrating its workstations to Linux. French public procurement of SecNumCloud-qualified cloud services rose from €20 million to €22 million between 2024 and 2026, modest in absolute terms, but a telling sign of underlying momentum, reinforced by the NIS2 directive and DORA.

One figure, however, keeps things in perspective: 80% of the software purchased by the French public sector is still American. The regulatory shift is well underway; the shift in actual usage will take years longer, a gap illustrated by our piece on Teams, Slack or a sovereign platform: the honest comparison for decision-makers, where old habits remain the biggest obstacle to genuine adoption of sovereign alternatives.

As Thomas Fauré, President of Whaller, told the French National Assembly, the Senate and the Council of State, all of which have heard his testimony on these issues — public procurement specifications are too often calibrated on GAFAM functionalities, distorting competition against French players. A year on, that warning is finally translating into concrete regulatory action. Whaller’s own answer takes shape in Whaller DONJON, the first collaborative platform qualified SecNumCloud 3.2.

Europe: a strategic wake-up call, still fragile

 
At EU level, the figures are sobering: more than 80% of the digital products, services and infrastructure used across the Union originate from the United States or Asia, at an annual cost of around €264 billion. Amazon, Microsoft and Google alone control roughly 70% of the European cloud market.

Faced with this, Brussels has finally moved. On 3 June 2026, the European Commission unveiled its technological sovereignty package: the Cloud and AI Development Act (CAIDA), a Chips Act 2.0 for semiconductors, and a support strategy for European open source. Alongside this, the EuroStack initiative, backed by a coalition formed in 2024, proposes a ten-year, €300 billion investment plan to build a complete European technology stack, from semiconductors to cloud computing. Federating projects such as EURO-3C (Telefónica and 70 partners across 13 countries) aim to pool existing national infrastructure rather than start from scratch.

Observers remain cautious, though: the 3 June package has been criticised for lacking real teeth and funding, and Europe is expected to remain 80-90% dependent on American clouds for the bulk of its workloads for years to come. Europe is legislating faster than it is building — a gap Whaller has watched closely, as reflected in our 2025 recap and vision for a sovereign digital future in 2026, where genuine European independence remains a work in progress.
 

Africa: agility as the answer to a lack of legacy infrastructure

 
This is arguably the most distinctive trajectory of the four. Africa is not starting from a dependency it must dismantle, it is starting from a blank page, and writing on it fast. The continent has more than quadrupled its installed data centre capacity in under a decade, driven in part by the Africa Data Centres Association. Morocco adopted a legal framework in January 2026 requiring foreign cloud providers to host public administration data locally. Senegal has launched its New Deal Technologique Horizon 2034 and is preparing a national cloud for the 2026 Youth Olympic Games. Smart Africa has just created an African Artificial Intelligence Council, placing cloud, data and cybersecurity on the same strategic footing as energy or defence.

This political agility is Africa’s real head start: the ability to treat digital sovereignty as a deliberate governance choice, unencumbered by the institutional weight that slows Europe down. But it comes with a paradox that would be dishonest to ignore. The continent still accounts for under 1% of global data centre capacity and roughly 0.5% of the global cloud market. And part of this “sovereignty” is being built on Chinese equipment (Huawei, Alibaba Cloud), whose proprietary architectures limit African states’ ability to audit their own data flows every bit as much as the US CLOUD Act does. As one expert quoted in the trade press puts it, a data centre alone does not make a digital industry: without a local software ecosystem and homegrown advanced cybersecurity expertise, sovereignty remains unfinished business well beyond the server room walls.

Africa has not, then, “solved” digital sovereignty, but it has grasped, faster than most, that this is a first-order political question rather than a purely technical option.
 

Canada: waking up to its dependency on its giant neighbour

 
Canada’s case exposes a persistent blind spot: the confusion between data residency and genuine sovereignty. A 2026 report estimates that around 92% of the digital tools used by Canadian teams remain under foreign jurisdiction, and that 80% of solutions advertising “Canadian data residency” remain CLOUD-Act-exposed once their parent company is US-controlled. The federal government itself does not mince its words on its own Digital Sovereignty policy page: as long as a cloud service provider operating in Canada remains subject to a foreign country’s laws, Canada does not have full sovereignty over its data.

Prime Minister Mark Carney launched the national “AI for All” strategy on 4 June 2026, explicitly describing current dependence on foreign-controlled cloud infrastructure as “a strategic exposure Canada cannot afford to leave in place”, with a target of 850 megawatts of genuinely sovereign, that is, Canadian-controlled; compute capacity by 2030. Sovereign cloud offerings are emerging (ThinkOn, TELUS, Bell), but bilateral negotiations with Washington over the application of the CLOUD Act have been stalled since 2022, and more than 90% of Government of Quebec domain names still rely on foreign e-mail services. Canada is following, with a time lag on Europe, a path France has been clearing for rather longer, one we explored in CSR and digital sovereignty: data, the cloud, the GDPR and SecNumCloud, on mapping and dismantling exactly this kind of structural dependency.
 

One fight, different speeds

 
The picture that emerges is a simple one: everywhere, the diagnosis converges, dependence on the GAFAM is a legal, economic and geopolitical risk, not merely a matter of technological preference. But the responses diverge according to each region’s resources and inheritance.

Region Strength Weakness
🇫🇷 France Mature regulatory framework (SecNumCloud, circulars) Slow adoption in practice (80% of public-sector software still American)
🇪🇺 Europe Ambition at scale (EuroStack, CAIDA) Funding and enforcement widely seen as insufficient
🌍 Africa Political agility and speed of execution Marginal infrastructure weight, dependency on other foreign powers
🇨🇦 Canada Recent, clear-eyed political awakening Ecosystem of local alternatives still in its infancy

Whaller: a French answer to a global challenge

 
This is precisely the space Whaller has occupied since its founding: building a credible, operational and commercially viable alternative to the GAFAM, rather than simply decrying their dominance. A French collaborative platform hosted in France, Whaller offers, with Whaller DONJON, the first collaborative solution qualified SecNumCloud 3.2, a concrete, not theoretical, answer to the extraterritorial reach of US law that France, Europe and now Canada are all seeking to contain.

Whaller’s fight is the same one being fought, each at their own scale, by French and European lawmakers, by Africa’s strategists at Smart Africa, and by the Carney government in Ottawa: proving that a sovereign, secure alternative is not a niche luxury but a strategic necessity, and that it already exists, operational, today.

Further reading on the Whaller blog: Digital sobriety: a new criterion for IT procurement, Whaller Mail: sovereign e-mail integrated into Whaller, and our full Digital Sovereignty category.

 

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Articles recommandés