Why are European governments and clients moving away from US software vendors?
Last updated 2026-10-07
European governments are moving away from US software to control where their data lives, which laws reach it, and how easily they can leave a vendor. The Netherlands, France, and Germany now run open-source workplace projects. Vendors selling to EU clients should be able to name data locations, US subprocessors, and an export path.
European governments are moving away from US software because they want to decide where their data lives, which country's courts can reach it, and how cheaply they can switch suppliers. Three national projects now show what that looks like in practice. For an owner, the shift turns into questions that EU public-sector and regulated clients already ask vendors, and that any buyer can ask too.
- Netherlands: DAWOOpen blueprint for a government workplace, built on DAWO-NixOS and Nextcloud
- France: La Suite and SecurixState-run collaboration tools plus a hardened NixOS workstation
- Germany: openDeskOpen-source office and collaboration suite from the federal ZenDiS agency
What are European governments building to replace US software?
European governments are building open-source workplaces they can inspect, host locally, and take apart. The Netherlands backs DAWO, France runs La Suite numérique and the Securix workstation, and Germany funds openDesk. None is a single product; each combines existing open tools such as Nextcloud and NixOS under public control.
DAWO is a community blueprint for a "digitally autonomous workplace for the Dutch government". The Ministry of the Interior and Kingdom Relations hosts its code, and supporters include the Dutch municipalities' association VNG and Tata Consultancy Services. Its operating system, DAWO-NixOS, reached version 0.1.2 on 15 August 2026, which is early. In France, the DINUM agency says La Suite numérique is used every month by more than 500,000 civil servants in 15 ministries, with documents and video hosted on SecNumCloud-certified servers in France. Germany's openDesk has been developed since January 2024 by ZenDiS, a company owned by the federal government, and on 23 September 2026 it opened a partner programme to private-sector cloud providers.
Why are European buyers moving away from US vendors?
European buyers are moving away from US vendors mainly over jurisdiction and lock-in. A US provider can be ordered by US courts to hand over data it controls wherever that data is stored. Public bodies also want to swap one component without rebuilding everything, which a single bundled suite makes expensive.
The jurisdiction point is written into US law. The Justice Department's CLOUD Act white paper says the 2018 Act confirmed that providers under US jurisdiction must answer valid US legal process "regardless of where the company stores the data." An EU data center run by a US company is still within reach. DAWO states the lock-in point on its own site: separate building blocks mean "you are not tied to one supplier."
Industrial policy sits behind both. On 24 September 2026, Tom's Hardware reported that ASML executive Frank Heemskerk said the Dutch chip-equipment maker was "selling absolutely nothing in Europe," with Europe at 0% of ASML revenue in the first half of 2026, against 5% in 2024. He asked the EU to create demand for European products. Heemskerk was talking about chip factories. The same argument, that governments should buy European on purpose, now runs through software procurement.
What did engineers on Hacker News say about it?
Engineers on Hacker News broadly welcomed the Dutch project and doubted the office suite. In a thread with more than 1,000 points and 581 comments, the most repeated caution was that replacing Windows is manageable, while replacing Microsoft 365 for staff who live in Excel, Word, and SharePoint is where these projects stall.
In the thread on DAWO, one commenter said the office suite is the hardest problem and doubted that LibreOffice or Collabora can replace Microsoft 365 without friction today. Others pointed to France's Securix, a hardened NixOS workstation built by DINUM, and its Bureautix office example, as proof that the operating system layer is already workable. Another commenter, writing as an American, read the "digital autonomy" language as a direct reaction to US politics.
What should you prepare when selling to EU clients?
Vendors selling to EU public-sector or regulated clients should prepare three written answers before the first procurement call: where customer data is stored and processed, which subprocessors are US companies, and how a customer exports everything and leaves. Buyers increasingly score these answers, and a vague reply loses to a competitor who has them ready.
- Data locationCountry and provider for storage, backups, logs, and support access
- Subprocessor listEvery third party that touches customer data, marked if US-owned
- Legal requestsWhat you do when a government asks for customer data, stated honestly
- Export pathFormats, time to deliver a full export, and any fee
- Open formatsDocuments and data leave in standard formats another tool can read
The subprocessor list already has a legal basis. Under GDPR Article 28, a processor may not engage another processor without the controller's prior written authorisation, so EU clients are entitled to know who handles their data. Hosting, email delivery, error tracking, analytics, and AI model APIs all count.
Which contract clauses protect buyers on data residency?
Buyers protect themselves with five contract terms: named data locations, advance notice of subprocessor changes, a defined export format and deadline, capped exit fees, and help during migration. The EU Data Act already requires cloud providers to support switching, and it removes switching and data egress charges entirely from 12 January 2027.
| Clause | What to ask for |
|---|---|
| Data residency | Named countries for storage, backups, and support access |
| Subprocessors | Current list plus 30 days' notice and a right to object |
| Export | Full export in standard formats within a fixed number of days |
| Exit fees | No charge, or a stated cap, for export and data transfer |
| Transition help | Vendor support for a set period after termination |
The European Commission's Data Act explainer says the law applied from 12 September 2025 and let providers charge reduced switching costs only during a transition period that ends on 12 January 2027. Buyers outside the EU can copy the same terms into any contract.
Should your business drop US software right now?
Most businesses should not drop US software right now. The European projects are publicly funded, early in places, and aimed at government desks. The practical move is smaller: know which of your clients care about jurisdiction, document your own data flows, and keep an export path open so switching stays possible later.
If most of your revenue comes from EU ministries, municipalities, hospitals, or banks, budget for data location and a US-free option as sales requirements. If a vendor pitches you a migration to a "sovereign" stack, ask first for the plan for office documents and staff training, where the Hacker News engineers expect the trouble. An independent second opinion before a switch costs less than reversing one.
Related guides
- The contract clauses that create the most lock-in get the least scrutiny
- What to know before signing a three-year SaaS contract
- Build custom software or buy off the shelf?
- The Second Opinion: an independent review of a technology decision
- GDPR Article 28: rules for processors and subprocessors
- European Commission: the Data Act explained
- DAWO: the Dutch government's open workplace community
Key takeaways
- The Netherlands, France, and Germany are each building open-source government workplaces to reduce reliance on US vendors.
- US law lets US courts compel US providers to produce data they control, wherever it is stored.
- Engineers expect office documents and spreadsheets, not the operating system, to be the hardest part to replace.
- Vendors selling to EU clients need written answers on data location, US subprocessors, and export.
- Buyers anywhere can copy the EU Data Act's switching terms into their own software contracts.
Frequently asked questions
Does hosting data in an EU data center solve the US jurisdiction problem?
Not by itself. The US Justice Department says the CLOUD Act requires providers under US jurisdiction to answer valid US legal process regardless of where they store the data. EU hosting helps with GDPR transfer rules, but clients worried about jurisdiction also ask who owns and operates the provider.
What is DAWO?
DAWO is an open community building a digitally autonomous workplace for the Dutch government. It publishes a blueprint of replaceable parts for AI, operating system, cloud, and collaboration, including DAWO-NixOS and Nextcloud. Its code is hosted by the Ministry of the Interior and Kingdom Relations, and version 0.1.2 of the operating system shipped in August 2026.
What is a subprocessor, and why do EU clients ask for the list?
A subprocessor is any third party your software uses that handles your client's personal data, such as hosting, email delivery, analytics, or an AI model API. GDPR Article 28 requires the client's prior written authorisation before a processor engages one, so EU clients ask for the list and for notice of changes.
About the author
Giacomo Balli is an independent technology advisor in San Francisco. He has built software and mobile apps since 2010 and reviews software, vendor, and contract decisions for owners before they commit the money.
Disclosure
Giacomo Balli sells fixed-fee independent reviews of technology decisions, including vendor and contract reviews. He does not build software for clients, resell platforms, or take referral fees. No project or company named on this page paid to be mentioned. This page is general guidance and not legal advice.