Giacomo Balli profile picture
Giacomo Balli
Your Consigliere

For owners and founders facing decisions that are expensive to get wrong.
Independent counsel from someone paid only by you.

What’s on Your Mind? LinkedIn

Why are European governments and clients moving away from US software vendors?

Last updated 2026-10-07

TL;DR

European governments are moving away from US software to control where their data lives, which laws reach it, and how easily they can leave a vendor. The Netherlands, France, and Germany now run open-source workplace projects. Vendors selling to EU clients should be able to name data locations, US subprocessors, and an export path.

European governments are moving away from US software because they want to decide where their data lives, which country's courts can reach it, and how cheaply they can switch suppliers. Three national projects now show what that looks like in practice. For an owner, the shift turns into questions that EU public-sector and regulated clients already ask vendors, and that any buyer can ask too.

What are European governments building to replace US software?

European governments are building open-source workplaces they can inspect, host locally, and take apart. The Netherlands backs DAWO, France runs La Suite numérique and the Securix workstation, and Germany funds openDesk. None is a single product; each combines existing open tools such as Nextcloud and NixOS under public control.

DAWO is a community blueprint for a "digitally autonomous workplace for the Dutch government". The Ministry of the Interior and Kingdom Relations hosts its code, and supporters include the Dutch municipalities' association VNG and Tata Consultancy Services. Its operating system, DAWO-NixOS, reached version 0.1.2 on 15 August 2026, which is early. In France, the DINUM agency says La Suite numérique is used every month by more than 500,000 civil servants in 15 ministries, with documents and video hosted on SecNumCloud-certified servers in France. Germany's openDesk has been developed since January 2024 by ZenDiS, a company owned by the federal government, and on 23 September 2026 it opened a partner programme to private-sector cloud providers.

Why are European buyers moving away from US vendors?

European buyers are moving away from US vendors mainly over jurisdiction and lock-in. A US provider can be ordered by US courts to hand over data it controls wherever that data is stored. Public bodies also want to swap one component without rebuilding everything, which a single bundled suite makes expensive.

The jurisdiction point is written into US law. The Justice Department's CLOUD Act white paper says the 2018 Act confirmed that providers under US jurisdiction must answer valid US legal process "regardless of where the company stores the data." An EU data center run by a US company is still within reach. DAWO states the lock-in point on its own site: separate building blocks mean "you are not tied to one supplier."

Industrial policy sits behind both. On 24 September 2026, Tom's Hardware reported that ASML executive Frank Heemskerk said the Dutch chip-equipment maker was "selling absolutely nothing in Europe," with Europe at 0% of ASML revenue in the first half of 2026, against 5% in 2024. He asked the EU to create demand for European products. Heemskerk was talking about chip factories. The same argument, that governments should buy European on purpose, now runs through software procurement.

What did engineers on Hacker News say about it?

Engineers on Hacker News broadly welcomed the Dutch project and doubted the office suite. In a thread with more than 1,000 points and 581 comments, the most repeated caution was that replacing Windows is manageable, while replacing Microsoft 365 for staff who live in Excel, Word, and SharePoint is where these projects stall.

In the thread on DAWO, one commenter said the office suite is the hardest problem and doubted that LibreOffice or Collabora can replace Microsoft 365 without friction today. Others pointed to France's Securix, a hardened NixOS workstation built by DINUM, and its Bureautix office example, as proof that the operating system layer is already workable. Another commenter, writing as an American, read the "digital autonomy" language as a direct reaction to US politics.

What should you prepare when selling to EU clients?

Vendors selling to EU public-sector or regulated clients should prepare three written answers before the first procurement call: where customer data is stored and processed, which subprocessors are US companies, and how a customer exports everything and leaves. Buyers increasingly score these answers, and a vague reply loses to a competitor who has them ready.

The subprocessor list already has a legal basis. Under GDPR Article 28, a processor may not engage another processor without the controller's prior written authorisation, so EU clients are entitled to know who handles their data. Hosting, email delivery, error tracking, analytics, and AI model APIs all count.

Which contract clauses protect buyers on data residency?

Buyers protect themselves with five contract terms: named data locations, advance notice of subprocessor changes, a defined export format and deadline, capped exit fees, and help during migration. The EU Data Act already requires cloud providers to support switching, and it removes switching and data egress charges entirely from 12 January 2027.

ClauseWhat to ask for
Data residencyNamed countries for storage, backups, and support access
SubprocessorsCurrent list plus 30 days' notice and a right to object
ExportFull export in standard formats within a fixed number of days
Exit feesNo charge, or a stated cap, for export and data transfer
Transition helpVendor support for a set period after termination

The European Commission's Data Act explainer says the law applied from 12 September 2025 and let providers charge reduced switching costs only during a transition period that ends on 12 January 2027. Buyers outside the EU can copy the same terms into any contract.

Should your business drop US software right now?

Most businesses should not drop US software right now. The European projects are publicly funded, early in places, and aimed at government desks. The practical move is smaller: know which of your clients care about jurisdiction, document your own data flows, and keep an export path open so switching stays possible later.

If most of your revenue comes from EU ministries, municipalities, hospitals, or banks, budget for data location and a US-free option as sales requirements. If a vendor pitches you a migration to a "sovereign" stack, ask first for the plan for office documents and staff training, where the Hacker News engineers expect the trouble. An independent second opinion before a switch costs less than reversing one.

Related guides

Key takeaways

  • The Netherlands, France, and Germany are each building open-source government workplaces to reduce reliance on US vendors.
  • US law lets US courts compel US providers to produce data they control, wherever it is stored.
  • Engineers expect office documents and spreadsheets, not the operating system, to be the hardest part to replace.
  • Vendors selling to EU clients need written answers on data location, US subprocessors, and export.
  • Buyers anywhere can copy the EU Data Act's switching terms into their own software contracts.

Frequently asked questions

Does hosting data in an EU data center solve the US jurisdiction problem?

Not by itself. The US Justice Department says the CLOUD Act requires providers under US jurisdiction to answer valid US legal process regardless of where they store the data. EU hosting helps with GDPR transfer rules, but clients worried about jurisdiction also ask who owns and operates the provider.

What is DAWO?

DAWO is an open community building a digitally autonomous workplace for the Dutch government. It publishes a blueprint of replaceable parts for AI, operating system, cloud, and collaboration, including DAWO-NixOS and Nextcloud. Its code is hosted by the Ministry of the Interior and Kingdom Relations, and version 0.1.2 of the operating system shipped in August 2026.

What is a subprocessor, and why do EU clients ask for the list?

A subprocessor is any third party your software uses that handles your client's personal data, such as hosting, email delivery, analytics, or an AI model API. GDPR Article 28 requires the client's prior written authorisation before a processor engages one, so EU clients ask for the list and for notice of changes.



Published: Wed, Oct 7 2026 @ 7:00:00
Back to Blog