Your data,
under European law.
Microsoft 365 is a good product and most teams should keep running it. But some of your workloads sit under a jurisdiction you did not choose. This page shows which ones can move, which ones should not, and what the swap actually costs you.
Four things worth knowing.
Residency is not jurisdiction
Data stored in a German datacentre operated by a US company is still reachable under the US CLOUD Act. Where the bytes sit and which law applies are two separate questions, and only one of them is on the marketing page.
The EU Data Act changed the exit maths
The Data Act obliges cloud providers to make switching possible and to phase out egress fees. Leaving got cheaper — which makes it worth knowing what leaving would involve, even if you never do it.
Some data is more equal than others
Board minutes, HR files, legal correspondence and patient records carry a different risk profile than a shared team calendar. Sovereignty is a question you answer per workload, not per company.
Lock-in is a cost you already pay
If moving off a platform would take a year and a consultant, that dependency has a price even while you stay. Knowing the number is useful at renewal time.
Nobody sensible leaves Microsoft entirely.
The useful question is not "Microsoft or open source" — it is which workload belongs where. In practice most teams keep the majority of Microsoft 365 and move two or three things where the jurisdiction genuinely matters. That is a hybrid, and it is the outcome I recommend most often.
- ·Exchange Online — the migration cost rarely pays back
- ·Teams, where your clients already live in it
- ·Entra ID as the identity backbone
- ·Anything your compliance officer has already signed off
- ·Document storage for regulated or confidential material
- ·Meetings where the other party cannot use Teams
- ·Automation, where per-seat licensing scales badly
- ·Code, backups and internal tooling
The tools I use myself.
These are the ones I run day to day and can deploy and hand over to you. Each lists what you gain, what you give up, and roughly what the move costs. Anything I have not run in production is in the directory further down, not here.
File storage, sharing and sync — the OneDrive and SharePoint document layer.
Browser-based document editing on top of Nextcloud — the Office for web replacement.
UK-seated since 2020 — outside EU jurisdiction, but self-hostable on EU infrastructure.
Self-hosted mail, calendar and contacts — the Exchange Online replacement.
Single sign-on and identity brokering — the Entra ID replacement for applications.
Open source, but stewarded by Red Hat/IBM. Self-hosting keeps the data in your jurisdiction; the project's governance is not European.
Chat, calls and screen sharing inside Nextcloud — the Teams conversation layer.
Privacy-friendly web analytics — the Google Analytics replacement, self-hosted.
US-origin open source. Self-hosted, the visitor data never leaves your server — this site runs it first-party at /stats.
Self-hosted Git forge with issues and CI — the GitHub replacement you run yourself.
Hosted Forgejo run by a German non-profit — GitHub without running the server yourself.
European infrastructure — servers, storage and managed databases replacing Azure basics.
Password and secret management for a team — shared credentials without a spreadsheet.
Swiss, so outside EU jurisdiction — but end-to-end encrypted, which makes the seat matter far less here than it does for plaintext workloads.
This site is the demo.
The site you are reading is built and shipped on the stack described above: source on Codeberg, containers on Docker, deployed from a Git stack, analytics on self-hosted Umami. No tracking cookies, no US analytics vendor.
And what I have not moved
The contact form on this site sends your message to Groq, a US provider, to be classified as spam or not. That is inference on visitor-submitted text outside EU jurisdiction, and it is a compromise I made for a working spam filter. I am telling you because a sovereignty page that only lists wins is marketing. Every stack has trade-offs it has not resolved yet, including mine.
European and open-source alternatives.
A reference list, not a recommendation list. Jurisdiction is the vendor’s legal seat, not where they host — those are different questions, and the difference is the whole point.
UK-seated since 2020 — outside EU jurisdiction, but self-hostable on EU infrastructure.
Latvian seat; developed by Ascensio, of Russian origin.
Swiss — strong domestic privacy law, but outside EU jurisdiction; adequacy is a separate arrangement.
Open source, but stewarded by Red Hat/IBM. Self-hosting keeps the data in your jurisdiction; the project's governance is not European.
Open source, owned by 8x8 (US). A self-hosted instance keeps meeting data in your jurisdiction.
UK-seated. Widely used by European public sector precisely because it is self-hostable.
Norway — EEA, so GDPR applies, but not an EU member state.
US-origin open source. Self-hosted, the visitor data never leaves your server — this site runs it first-party at /stats.
Swiss, so outside EU jurisdiction — but end-to-end encrypted, which makes the seat matter far less here than it does for plaintext workloads.
The Sovereignty Scan
A fixed-price assessment of what can move, what should not, and what either choice costs. You get a written answer you can take to a board — whether that answer is "move" or "stay exactly where you are".
€750 credited against any follow-on work booked within 3 months — whether that is a migration or hardening what you already have.
- 01Workload inventory — what your tenant holds and who touches it
- 02Jurisdiction map — where each workload legally sits, not where the datacentre is
- 03Move / keep / hybrid recommendation per workload, with reasoning
- 04Cost model — current licensing versus hosted alternative, including run cost
- 05Migration sequence and effort estimate
- 06A priced "do nothing" baseline
Delivered as a written report plus a 60-minute walkthrough. Over 50 seats is quoted.