Sources checked: 23 September 2026
Short answer: No. The reviewed official sources do not show a France-wide migration of all public-sector computers to Linux. DINUM announced a Linux move for its own workstations, while Cnam’s separate initiative concerns LaSuite collaboration tools for more than 80,000 staff.
France’s public-sector technology policy quickly generated headlines suggesting that tens of thousands of officials had already abandoned Windows. The official announcements are more measured, but their legal and commercial implications are more significant. The central issue is not simply Windows versus Linux; it is the extent to which public data, critical workflows and technology suppliers remain subject to effective institutional control.
On 8 April 2026, France’s Interministerial Digital Directorate, DINUM, announced its move from Windows to Linux workstations. Ministries, including their public operators, were asked to prepare plans by the autumn to reduce dependencies on non-European technology. The review extends beyond operating systems to collaboration tools, antivirus, AI, databases, virtualisation and network equipment.1
The development turns digital sovereignty from an abstract policy concept into a concrete governance and legal question. Three issues matter most: who can access the information, which legal systems can affect the relationship, and whether the organisation can leave the provider in practice—not merely on paper.
What France actually announced
The widely repeated figure of 80,000 staff belongs to a different initiative. On 1 April 2026, France’s national health insurance body, Cnam, announced a partnership covering more than 80,000 employees to support the deployment of LaSuite collaboration tools. Tchap and Visio are part of that programme; DINUM also identifies FranceTransfert for document exchange. This is not evidence that 80,000 people have completed a Linux migration or abandoned every American software product.2
The reviewed 8 April announcement does not establish a completed France-wide Linux migration or a binding rollout timetable covering the public administration as a whole. It sets a dependency-reduction direction and requires institutions to prepare plans; an announced objective should not be reported as an achieved result.1
The State Procurement Directorate’s 16 April account adds another dimension: it describes work under way since 2025 to map sovereignty risks in state purchasing.3 The Pacte Numérique et IA, signed on 10 September 2026, creates a further framework for cooperation between the state and the French digital sector on cloud, cybersecurity and AI. It does not certify that the migrations are complete and expressly states that participation creates no privileged access to state procurement.4
The significance of the announcement is therefore not an overnight replacement of France’s public-sector computers. It is a change in procurement and governance: technology is no longer being assessed only by features and price, but also by dependency, continuity, data access and strategic control.
What does digital sovereignty mean in practice?
Digital sovereignty is not defined solely by where technology is developed. From a corporate perspective, it concerns the ability to exercise meaningful decision-making, oversight and exit rights over critical technology. Knowing where information is processed, controlling access, understanding service conditions and retaining a workable alternative are core elements of that capability.
The idea looks different depending on who is asking. For a state, it may concern continuity of public services. For a company, it may mean avoiding dependence on one supplier’s decisions. For an individual, it includes being able to exercise rights over personal information. Julia Pohle and Thorsten Thiel explain that digital sovereignty is a contested concept, encompassing different claims to self-determination by states, economies and individuals rather than one settled legal definition.5
The distinction is therefore between purchasing a service and becoming structurally dependent on it. A contractual right to terminate offers limited protection if the organisation cannot transfer its data, permissions, logs and operational processes to another environment.
The less visible cost: technology dependency
The licence fee for an email service or cloud platform is easy to quantify. Transition costs, data portability, operational disruption and single-provider dependency are less visible and often become apparent only after implementation. Organisations should assess in advance what would happen if the provider raised prices, removed a critical feature or terminated the relationship.
This assessment is not solely a procurement exercise. Legal, information security, IT and business teams should determine whether documents remain usable, permissions and activity records can be transferred, and operations can continue during migration. Those questions distinguish a contractual exit clause from an exit plan that works in practice.
There is also exposure to legal demands. Hosting data in Europe does not, by itself, establish that the provider is unaffected by laws elsewhere. The contracting entity, its corporate group, support access and possible government demands all need consideration. France’s ANSSI takes technical, operational and legal requirements into account in its SecNumCloud approach.6
This is not a finding that foreign providers are inherently unsafe. The narrower—and more useful—point is that a data-centre address is not a complete risk assessment.
GDPR: data location is not the whole assessment
The GDPR does not generally require organisations to use software of European origin. It requires lawful processing, purpose limitation, data minimisation, security and accountability. Data protection by design is not simply a privacy notice added after a purchasing decision.7
Take a meeting application. Video quality is only one consideration. Is recording enabled by default? Where is a transcript generated? Who can download it, and for how long is it kept? Does switching on an AI feature give another supplier access? These are the questions that turn broad legal principles into an ordinary product decision.
Where a provider processes personal data on the customer’s behalf, Article 28 requires sufficient guarantees and a suitable processing agreement. Subprocessors, safeguards, audit assistance and the return or deletion of information at the end of the service form part of that relationship. CNIL’s work on cloud infrastructure providers likewise emphasises documented assurances.8
What does “hosted in Europe” leave unanswered?
That statement may be accurate without telling the whole story. Support access, backups, logs and subservice providers still matter. CNIL explains that some cloud security and performance tools also collect personal data and can introduce additional questions, including international transfers and the decryption of TLS traffic.9
Encryption deserves a follow-up question too. Encryption at rest is not the same as a system in which the provider cannot read the content. Who controls the keys? Must the data be decrypted for processing? CNIL’s guidance distinguishes these arrangements rather than treating “encrypted” as a single, conclusive assurance.10
Are US-linked services prohibited?
No. Where personal data are transferred outside the European Economic Area, the applicable transfer requirements must be met. For example, transfers to participating US organisations can rely on the EU–US Data Privacy Framework adequacy decision, subject to checking its scope and the recipient’s participation.11
Where standard contractual clauses are used, contractual promises are not the whole assessment. In Schrems II, the Court of Justice stressed the importance of ensuring that the required protection remains effective in light of the destination country’s law and practice. The EDPB’s recommendations on supplementary measures explain the technical and organisational work that may be required.1213
A direct request from a foreign authority is not automatic permission to disclose data either. Article 48 GDPR and the EDPB’s final guidance explain that third-country judgments and decisions cannot simply be recognised or enforced in the EU without the relevant legal framework. A response also requires an assessment of the processing basis and the transfer conditions. Article 48 does not itself supply a transfer ground.14
There is an important distinction here: a service that can be used lawfully is not necessarily the service that best meets an institution’s sovereignty objectives. French public-sector policy should not be converted into a supposed GDPR-wide ban on particular brands.
Türkiye’s KVKK: cloud use does not transfer responsibility
France’s announcement creates no obligation for businesses in Türkiye to migrate to Linux. It does, however, expose an important governance question: how well does the organisation understand the provider’s legal structure, subprocessors, access model and exit conditions?
Under Article 12 of Türkiye’s Personal Data Protection Law, commonly known as the KVKK, controllers must take the technical and organisational measures needed to provide an appropriate level of security. Where another person processes data on their behalf, they share responsibility for the required security measures. “It was in the cloud” does not bring the controller’s own duties to an end.15
International transfers require a separate assessment. Following the 2024 amendments, Article 9 provides a framework involving processing conditions and adequacy decisions, appropriate safeguards subject to the statutory requirements, and more limited routes for occasional transfers. Sending information to Europe does not, by itself, establish a valid Turkish transfer route. A European Commission adequacy decision is not a decision of the Turkish Board.16
A routinely used foreign cloud service should not be treated as an exceptional, occasional transfer simply because that is administratively convenient. The Turkish Authority’s guidance interprets the occasional-transfer routes narrowly. It also explains that, where the relevant criteria are met, making information remotely accessible to another controller or processor abroad can constitute a transfer. No physical movement of a file is necessary.17
Where Turkish standard contracts are the chosen safeguard, a foreign supplier’s generic data processing agreement is not a substitute. The relevant Board-approved contract type must be used, and the signed standard contract must be notified to the Authority within five working days. EU standard contractual clauses and Turkish standard contracts are not automatically interchangeable.18
For further detail, see our guides to Türkiye–EU personal data transfers under the KVKK and GDPR and liability for cloud-provider data breaches.
Cross-border projects require a two-way data-flow map
Imagine an Istanbul employer moving employee records to a cloud service in France. The employer’s Turkish security and transfer obligations remain. A French hosting location does not answer them on its own.
Now reverse the direction. A French customer allows a separate Turkish support company to access its data. Access from outside the EEA may require its own assessment under the EU transfer rules. In the same commercial relationship, the legal questions can run in both directions. One compliance document will not necessarily answer both.1613
Local, European or open source: is any label sufficient on its own?
None is sufficient on its own.
Local hosting concerns geography. Open source concerns rights and possibilities under the relevant software licence, including inspection and development of code. Security concerns the controls actually in place. Digital sovereignty asks a broader question about decision-making, oversight and practical alternatives. DINUM’s open digital resources portal also addresses shared standards and governance alongside software openness.19
An open-source application still needs secure configuration, access control and maintenance. A locally incorporated provider may still rely on foreign infrastructure or overseas support. These are not allegations about particular vendors; they are possibilities that an assessment should not exclude.
A list of “European alternatives” can therefore be a starting point, not a legal conclusion. Norway, Switzerland and EU membership are not the same jurisdictional category. The provider’s legal entity and actual processing arrangements still require examination. ANSSI also cautions that qualification of a cloud offering under SecNumCloud does not automatically establish the security of a customer’s application running on it.6
There is a further limit to the sovereignty argument. Moving information from a foreign company into a domestic system does not automatically strengthen the individual’s rights. Excessive monitoring or unaccountable access can exist locally too. Pohle and Thiel warn against treating sovereignty as an end in itself: the power exercised in its name must also be subject to scrutiny.5
A four-question governance framework for companies
A corporate response should not begin with replacing the entire technology stack at once. It should begin by measuring dependency in a limited number of critical services. The following framework is a practical starting point for legal, procurement, information security and IT teams; it is not a substitute for a complete compliance assessment.
| Question | Evidence worth asking for |
|---|---|
| Where is the information, and who can reach it? | A map covering primary data, backups, support, logs and subprocessors |
| Which legal and contractual arrangements support the service? | Processing roles, transfer route, government-request procedure and any specific applicable requirements |
| Can the business continue if the relationship fails? | Separate backups, a restoration test, access records and named owners |
| Can we take usable information with us when we leave? | Export formats, transition assistance, timing, charges and deletion evidence |
The final question has a legislative dimension. The EU Data Act introduces switching obligations for data processing services within its scope. Switching charges are prohibited from 12 January 2027; until then, reduced charges must not exceed the provider’s directly related switching costs. This does not mean that every subscription fee or early-termination charge disappears.20
The practical counterpart is a periodic exit test: export a sample data set and confirm that it can be used in another environment. This provides stronger evidence of operational portability than an untested contractual clause.
For Turkish technology businesses serving European customers, this is also a useful way to prepare. “Your data are safe” is less informative than showing who can access them, which subcontractors are involved, how incidents are communicated and what happens at contract end. That evidence does not confer an automatic right to a contract or public tender. It makes the supplier’s answer more useful.
Conclusion: digital sovereignty is operational exit capacity
The lesson from France is not that every organisation should select the same operating system. It is that critical technology should be assessed not only by familiarity, price or brand, but also by control, auditability, data access and migration capability.
Digital sovereignty does not require organisations to avoid cross-border technology relationships. It requires them to understand the conditions of those relationships, preserve their own legal accountability and maintain a workable alternative.
The most useful corporate question is: “If this provider relationship ended tomorrow, how much of our data, permissions and operational capability could we transfer?” The answer should be owned jointly by legal, management, procurement, information security and IT.
Frequently asked questions
Has France moved every public-sector computer to Linux?
The reviewed French official statements do not establish a completed nationwide migration. DINUM’s Linux announcement, Cnam’s collaboration-tools programme covering more than 80,000 staff and ministries’ dependency-reduction plans are separate steps.
Is digital sovereignty the same as keeping data in the country?
No. Location is one factor. Access rights, the provider’s legal exposure, encryption-key control, auditability and the ability to leave the service also matter.
Does the GDPR prohibit American software?
There is no general ban. The processing, security and, where relevant, international-transfer conditions must be assessed. An institution’s stricter sovereignty or procurement policy is not the same as a GDPR-wide prohibition on a brand.
Does the KVKK apply to a transfer from Türkiye to a European cloud?
Yes. Where the activity is an international transfer within the KVKK, Article 9 must be addressed. European hosting or a supplier’s GDPR compliance statement does not replace that assessment.
Does using open source establish KVKK and GDPR compliance?
Not automatically. Open source may help with oversight and switching, but a processing basis, access safeguards, retention rules and the necessary transfer arrangements must still be established.
This article provides general information and legal analysis. It is not an assessment of a particular product, supplier, procurement process or data transfer. The news section is based on French official announcements; the legal discussion draws on the materials cited below. The examples are hypothetical.
Online sources last accessed on 23 September 2026. Official announcements, legal rules and the author’s analysis are distinguished throughout.
Sources and footnotes
-
Direction interministérielle du numérique (DINUM), ‘Souveraineté numérique : l’État accélère la réduction de ses dépendances extra-européennes’ (2026-04-08), official source. ↩1 ↩2
-
Caisse nationale de l’Assurance Maladie (Cnam), ‘L’Assurance Maladie adopte les outils numériques souverains de l’État’ (2026-04-01), official source. ↩
-
Direction des achats de l’État (DAE), ‘Souveraineté numérique : une dynamique collective pour accélérer la réduction des dépendances extra-européennes’ (2026-04-16), official source. ↩
-
Ministère de l’Économie et des Finances, communiqué n° 1010, ‘Pacte Numérique et IA : l’État s’engage aux côtés de la filière française pour un numérique souverain et résilient’ (2026-09-10), official source. ↩
-
Julia Pohle and Thorsten Thiel, ‘Digital sovereignty’ (2020) 9(4) Internet Policy Review, doi:10.14763/2020.4.1532, full text. ↩1 ↩2
-
Agence nationale de la sécurité des systèmes d’information (ANSSI), ‘Cloud’, official source. ↩1 ↩2
-
Regulation (EU) 2016/679 (GDPR) [2016] OJ L119/1, arts 5, 6, 25, 28, 32 and 44–49, EUR-Lex. ↩
-
Commission nationale de l’informatique et des libertés (CNIL), ‘La CNIL approuve le premier code de conduite européen dédié aux fournisseurs de services d’infrastructure cloud (IaaS)’ (2021-06-11), official source. ↩
-
CNIL, ‘Les outils de sécurisation d’applications web dans l’informatique en nuage (cloud)’ (2024-01-22), official source. ↩
-
CNIL, ‘Les pratiques de chiffrement dans l’informatique en nuage (cloud) public’ (2024-01-22), official source. ↩
-
European Commission, ‘EU–US data transfers’, official source. ↩
-
Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (C-311/18) EU:C:2020:559, 16 July 2020, official judgment. ↩
-
European Data Protection Board (EDPB), ‘Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data, version 2.0’ (2021-06-18), official source. ↩1 ↩2
-
EDPB, ‘Guidelines 02/2024 on Article 48 GDPR, version 2.1’ (2025-06-04), official source. Adopted 4 June 2025; v2.1 updated 20 June 2025; executive summary and paras 9–11. ↩
-
Law No 6698, art 12; Kişisel Verileri Koruma Kurumu, ‘Veri Güvenliğine İlişkin Yükümlülükler’, official source. ↩
-
Law No 6698, art 9, as amended by Law No 7499; Kişisel Verileri Koruma Kurumu, ‘Yurt Dışına Aktarım’, official source. ↩1 ↩2
-
Kişisel Verileri Koruma Kurumu, ‘Kişisel Verilerin Yurt Dışına Aktarılması Rehberi’ (2025), official source. Printed pp 16, 65–66. ↩
-
Kişisel Verileri Koruma Kurumu, ‘Standart Sözleşme Bildirim Modülü Hakkında Kamuoyu Duyurusu’, official source. See also the Board’s standard-contract documents (in Turkish). ↩
-
DINUM, ‘À propos — Ouvert’, official source. ↩
-
Regulation (EU) 2023/2854 (Data Act) [2023] OJ L 2023/2854, arts 23–30, particularly art 29, EUR-Lex. ↩
