Digital Sovereignty: eIAM, AGOV, W012

Initial Situation

eIAM and AGOV are jointly developed and operated with Swiss private-sector partners. They are operated on behalf of the Swiss Federal Chancellery in federal data centres and, in the near future, to enhance AGOV’s resilience, additionally in privately operated data centres located in Switzerland and owned by Swiss entities ().

The components required for operating and using eIAM and AGOV are inevitably integrated into international contexts along the entire value chain. This affects users' end devices, the power supply and internet infrastructure, the eIAM and AGOV systems, as well as the authorities' infrastructures and specialized systems. International integration extends across all levels, particularly software, hardware, organizational structures, and the required know-how.

Scientific Classification of the Digital Sovereignty of eIAM and AGOV
×

  1. Theoretical Framework
  2. Digital sovereignty is not a static or binary state, but a relational and gradual property of complex sociotechnical systems. In scientific literature, it is conceptualized in various ways, particularly as technological self-determination, as control over data and information flows, and as institutional and economic independence from external actors [1,2].

    It follows that: Digital sovereignty is not to be understood as complete autarky, but as the ability to autonomously manage a system within existing dependencies.

  3. Layer Model and System Boundaries
  4. The digital sovereignty of eIAM and AGOV can be analyzed along a layer model that reveals different degrees of control and dependency. Such a perspective corresponds to established approaches for analyzing sociotechnical systems, which view technical, organizational, and infrastructural components as inseparably linked [5,6]. It can also be connected with approaches that do not view digital sovereignty merely as control over software and data, but as the ability to shape digital and physical value creation – including hardware, means of production, standards, and know-how [3].

    • Application and Governance Layer:
      The development, source code ownership, and strategic management of eIAM and AGOV reside in Switzerland. This ensures a high degree of control over functionality, further development, and security mechanisms.

    • Operational Layer (Hosting):
      Operations take place in federal data centers as well as in Swiss partner data centers. As a result, legal and physical control remains within national jurisdiction. There are no direct dependencies on foreign cloud platforms for the core process.

    • Interface to Target Systems (Scope of Evaluation):
      eIAM and AGOV function as central IAM (Identity and Access Management) systems. Their scope of influence ends at the technical handover interface (e.g., OIDC, SAML) to the connected specialized applications and registers. The digital sovereignty of these target systems is not subject to this evaluation. eIAM and AGOV provide sovereign access points; responsibility for downstream data processing lies with the respective specialized authorities.

    • Infrastructure Layer (Structural Dependencies):
      Hardware, software components, and network protocols are embedded in global supply chains. Research on IT supply chains shows that such dependencies are structural and significantly shape the control and trust dynamics of digital systems [4]. Complete autonomy is unachievable in this layer; sovereignty manifests here through the active management of dependencies, such as through standardization and diversification.

    • User Layer (Periphery):
      End devices and operating systems lie outside the direct sphere of state influence. This layer marks a systemic limit of state controllability and illustrates that digital services are always embedded in external usage contexts.

  5. Operational Autonomy and the "Killswitch" Criterion
  6. A central criterion for evaluating digital sovereignty is the question of direct external controllability.

    eIAM and AGOV do not feature an external "killswitch" scenario: no external state or private actor can unilaterally and immediately deactivate the services. Operational decision-making power remains within Swiss jurisdiction.

    At the same time, analyses of internet governance show that digital infrastructures are shaped by global standards, protocols, and institutional structures [6]. This results in indirect and distributed avenues of influence that do not leverage a single point of control, but rather act systemically.

  7. Conclusion
  8. eIAM and AGOV are to be classified as highly digitally sovereign in both an institutional and operational sense. The central state function of identity mediation can be performed independently and in a controlled manner under realistic conditions.

    However, this sovereignty is not absolute. It holds within clearly defined system boundaries and is based on the ability to actively shape dependencies, rather than eliminate them entirely. This understanding also aligns with current strategic assessments of digital sovereignty as state capacity to act within an environment of global technological interdependencies [7].

    eIAM and AGOV are thus digitally sovereign within their respective system contexts, yet not independent of the global dependencies in which every digital system is embedded. As set out in the AGOV article AGOV in cloud, SaaS and Hyperscaler architectures – which applies not only to AGOV as the Swiss authorities' authentication service, but to the entire eIAM as the federal administration's central IAM system – international platforms can be integrated without difficulty. This deliberate interoperability demonstrates that digital sovereignty is always relative to the relevant system scope and area of responsibility.

References
[1] Florian Pohle & Thorsten Thiel (2020). Digital sovereignty. Internet Policy Review, 9(4).
[2] Stéphane Couture & Sophie Toupin (2019). What does the notion of sovereignty mean when referring to the digital? New Media & Society, 21(10) ().
[3] Neil Gershenfeld et al. (2017). Designing Reality. Basic Books.
[4] Nir Kshetri (2018). The Economics of Cybersecurity: A Supply Chain Perspective. Springer.
[5] Geoffrey C. Bowker & Susan Leigh Star (1999). Sorting Things Out. MIT Press.
[6] Laura DeNardis (2014). The Global War for Internet Governance. Yale University Press.
[7] OECD (2021). Digital Sovereignty for the Digital Decade.


W012: Digital Sovereignty in the Federal Administration

Directive W012 was issued by the FCh DTI based on Art. 40 DigiV and applies to the central federal administration.
Directive W012 was issued by the BK DTI pursuant to Article 40 of the DigiV and applies to the central federal administration.

Discussion documents on the topic (internal) →