Cancel
Start searching
This search is based on elasticsearch and can look through several thousand pages in miliseconds.
Learn more
When I think about digital sovereignty, the first thing that often comes to mind is what I don’t want: the knee-jerk use of tools like Google Suite, which I see in many organizations. To me, this symbolizes how quickly companies allow themselves to become dependent without fully realizing the consequences.
At the same time, this highlights a common misconception: digital sovereignty is often defined in terms of renunciation or dogma. Sometimes it almost feels like “digital veganism”—many people know it would be better for society, but it seems inconvenient, you have to justify yourself, and you feel like you can’t just go along with everything anymore.
But it’s not at all about running everything strictly as open source or maintaining every DNS record yourself. For me and for us at punkt.de, digital sovereignty means something else: making conscious decisions. Understanding what data is processed and how, which data you want to protect in particular—and where it’s perfectly sufficient to rely on standards or established systems.
For small and medium-sized businesses, a lack of digital sovereignty means one thing above all else: dependence. And this often only becomes apparent when it’s already too late.

One example from our own day-to-day work is Jira and Confluence. Back in 2012, we at punkt.de decided to switch from Redmine to Atlassian products. At the time, we were thrilled by the possibilities—and we still use them extensively today. But now, Atlassian is forcing its customers into the cloud. This means significant price increases, no longer having a choice, and being required to store sensitive data in an American cloud.
The problem here isn’t just the cloud. The real issue is vendor lock-in. Switching back or to another system is possible, but only with an extremely high level of effort and at great cost. Our data sovereignty is severely restricted here.

The situation is quite different in another area: email and calendar. Here, too, we rely on Microsoft 365—but with one key difference. Our email and calendar are based on open standards that have been tried and tested over many years (IMAP, CalDAV, etc.). This means that if we ever decide that Microsoft is no longer the right fit for us, we can switch back to open-source solutions or migrate to other systems with relative ease. Our data is portable, and we retain control over it.
These two examples clearly illustrate what digital sovereignty is all about: not dogma, but the ability to act.
What sets us apart at punkt.de is the approach we take to problems. Our default approach is as follows:
This doesn’t mean that we dogmatically subject every feature or project to the principle of data sovereignty. Rather, it means that we consciously weigh the options: Which data is critical, where do we need maximum control—and where is pragmatic integration sufficient?

Our first love is still open source. Why? Because open source means independence and security. It means the freedom to understand systems, customize them, and—when the going gets tough—continue operating them ourselves. For us, this story began early on: In the 2000s, a vendor discontinued the CMS we were using at the time. We had to handle free migrations for our clients. It was a painful experience—and the start of our journey with TYPO3.
TYPO3 was an eye-opener: No matter what happens to the community, we retain access to the data. We can run, expand, and customize the system ourselves. This experience continues to shape us to this day. For us, open source is therefore not just a business model, but a conviction. Not because it’s “free” or because we “have to” do it for ideological reasons—but because it gives companies the freedom to make independent decisions.
And we’re constantly amazed by just how powerful open-source products have become. Whether it’s content management, automation, or collaboration: Today, there are open-source solutions for many problems that can easily compete with the major international players.
Reality is never black and white. Two examples from our work illustrate this:
The key point is: We weigh the options. We assess which data streams are critical, what degree of flexibility is necessary, and where pragmatism is more important than ideology.
In conversations with decision-makers, we encounter two misconceptions particularly often:
Our stance on digital sovereignty isn’t just a passing trend—it’s rooted in experience. More than 20 years ago, we learned what happens when you rely too heavily on proprietary providers.
Since then, we’ve been helping companies maintain control over their data—using open source, European solutions, and even international tools when that’s the best choice. What matters isn’t ideology, but a company’s freedom to act whenever necessary.
I am convinced that digital sovereignty will become even more relevant over the next five to ten years. Regulatory requirements will increase, markets will impose stricter standards, and—at the latest when AI is deployed—it will become clear that only those who have full control over their data can remain innovative.
For small and medium-sized businesses, this means that digital sovereignty is not a niche topic. It is a strategic priority.
Digital sovereignty is not a dogma, not a project of self-sacrifice, and not a trend. It is the ability to make informed decisions and handle data in a way that ensures we remain capable of taking action—both today and in the future.
At punkt.de, we’ve been putting this philosophy into practice for over 20 years. We think first in terms of open source, then on a European scale, and we turn to international solutions when it makes sense. Always with one goal in mind: to give our customers the freedom to maintain control over their data—and thus move confidently into the digital future.