Digital Sovereignty in European Higher Education: What It Means for Your LMS

Digital sovereignty has moved from principle to procurement condition in European higher education. What it actually requires of a learning platform - and where institutions usually lose control.

ET
EdzLMS Team
·8 September 2026·8 min read
⚡ Quick answer

Digital sovereignty, applied to a university LMS, means the institution can answer three questions without depending on a vendor: where the data physically sits, who can technically access it, and whether the platform can be moved or kept running if a supplier changes terms or disappears. In practice it pushes European institutions toward open-source platforms, national research networks, self-hosted video, and federated identity they operate themselves.

35+5
Universities and AFAM institutions on one sovereign platform (EduNext)
17
Universities on a shared MOOC network with federated sign-in (EduOpen)
GARR
The Italian national research and education network both run over

Key takeaways

  • Sovereignty is not the same as on-premise. It is about control and exit, and a hosted platform inside your own jurisdiction on infrastructure you can leave may qualify where a self-hosted black box does not.
  • The LMS is rarely the hard part. Video, identity and analytics are where data actually escapes.
  • Open source matters less as ideology than as an exit route: it is the difference between migrating and starting again.
  • National research and education networks give European institutions infrastructure they already fund and govern.
  • Federated identity keeps user accounts with the institution rather than centralising them in a supplier's directory.

Why this became a procurement question and not a philosophical one

For most of the last decade, "where is the data hosted" was a box on a form. It is now frequently the question that decides a tender, and the change is not really about technology. Public institutions have watched licensing terms change, products get discontinued, and support move offshore, and have concluded that the relevant risk is not a breach but a dependency.

Digital sovereignty is the current name for the response. Stripped of the rhetoric, it comes down to three questions an institution should be able to answer about any system it runs:

  • Where does the data physically live, and under whose legal jurisdiction?
  • Who can technically access it - not who is contractually permitted to, but who holds keys and credentials?
  • What happens if the supplier changes terms, is acquired, or stops trading? Can the platform be taken over, moved, or kept running by someone else?

The third question is the one that separates sovereignty from data residency. Storing data in an EU region satisfies residency. It does not, on its own, give you anywhere to go.

The LMS is rarely where sovereignty is lost

An open-source LMS on infrastructure the institution controls is the easy part of this problem. The data tends to leave through the things attached to it.

Video is the clearest case. Lecture capture is heavy, expensive to serve and full of identifiable people, which is exactly why institutions push it to consumer platforms - and exactly why that is the least defensible choice. A recording of a seminar is a record of who attended, what they asked, and how they sounded. Self-hosted streaming is the single change that moves the most sensitive material back inside the institution's control. In the EduNext platform this is a self-hosted PeerTube instance rather than a third-party video service.

Identity is the second. If a platform requires institutions to create user accounts in the supplier's directory, the supplier now holds the population. Federated identity inverts that: each institution keeps its own identity provider and releases only the attributes it chooses.

Analytics is the quietest. Third-party tracking, embedded widgets and AI features that call an external API all move learner behaviour outside the boundary, usually without appearing in any architecture diagram.

National research networks are the piece outside Europe often misses

European higher education has infrastructure that has no direct equivalent in most commercial discussions: national research and education networks, funded and governed by the sector itself. In Italy that is GARR. Institutions are already connected to it, already trust it, and already fund it.

Running a shared academic platform over that network rather than over commercial transit changes the sovereignty conversation completely, because the infrastructure is not a supplier - it is a body the institutions collectively own. The same is true of the identity federations that sit alongside these networks, such as IDEM in Italy, with eduGAIN linking national federations to one another.

This is why a European consortium platform tends to look different from a corporate one. It is not built on a vendor stack with sovereignty bolted on; it is built on the sector's own infrastructure from the start.

Open source as an exit route, not an ideology

The strongest practical argument for an open-source LMS in this context has nothing to do with cost or philosophy. It is that the institution can hand the platform to a different supplier, or take it in-house, without the data model going with the outgoing vendor.

That is the difference between a migration and a restart. With a proprietary platform, leaving means exporting whatever the vendor chooses to expose and rebuilding the rest. With an open platform, the database schema, the plugins and the integrations are all inspectable, and continuity is a procurement decision rather than a rescue operation.

Sovereignty, in other words, is mostly about what your options look like on the worst day.

What this looks like when it is actually built

The pattern is consistent across the European consortium platforms we have worked on: an open-source core, self-hosted media, federated sign-in the institutions control, and hosting on infrastructure the sector governs.

EduNext runs 45 accredited online degrees for 35 universities and 5 AFAM institutions across six connected portals, over GARR with IDEM federated login and self-hosted PeerTube video. EduOpen runs a 17-university MOOC network on one Moodle platform with SAML and Shibboleth single sign-on. In both cases no institution had to move its user accounts into a supplier's system, and no lecture recording sits on a consumer video platform.

  1. 1
    Map where the data actually goes

    Not the LMS - the attachments. Video, identity, analytics, embedded tools, AI features and anything that calls an external API. This list is usually longer than expected.

  2. 2
    Separate residency from sovereignty

    Ask each supplier where data sits AND what happens if you leave. A vendor can satisfy the first and fail the second completely.

  3. 3
    Decide who holds identity

    If institutions must create accounts in a supplier directory, that is a sovereignty decision being made by default. Federated identity keeps the population with the institution.

  4. 4
    Check whether video has been thought about at all

    It is the heaviest, most sensitive data in the system and the most likely to have been pushed to a consumer platform without a decision being recorded.

  5. 5
    Write the exit into the procurement, not the contract renewal

    Establish now what a handover would involve: schema access, plugin source, data export format, and who could take it over.

Data residency only

  • Data stored in an EU region
  • Supplier still holds keys and access
  • Exit means exporting what the vendor exposes
  • Video and identity often still external
  • Satisfies a compliance checkbox

Actual sovereignty

  • Institution or sector controls the infrastructure
  • Identity stays with each institution, federated
  • Media self-hosted rather than on consumer platforms
  • Open schema means handover, not rebuild
  • Survives a supplier changing terms or disappearing

Sovereignty is not automatically on-premise

A hosted platform inside your jurisdiction, on open source, with an inspectable schema and a credible handover path, can be more sovereign than a self-hosted proprietary system nobody but the vendor can maintain. The test is control and exit, not the location of the rack.

💡

The deployment question underneath this

If you are weighing self-hosted against cloud for a Moodle platform specifically - cost, upgrades, operational burden - that is a separate decision with its own trade-offs, covered in our guide to Moodle deployment options.

Frequently asked questions

What does digital sovereignty mean for a university LMS?

That the institution can say where its learning data physically sits, who can technically access it, and what would happen if the supplier changed terms or ceased trading. The third point is the one that distinguishes sovereignty from data residency: residency tells you where data is, sovereignty tells you whether you have anywhere else to go.

Is digital sovereignty the same as hosting on-premise?

No. On-premise is one way to achieve it and not always the best one. A hosted platform within your jurisdiction, built on open source with an inspectable data model and a realistic handover path, can offer more genuine control than a self-hosted proprietary system that only the original vendor can maintain.

Where do universities usually lose control of learning data?

Rarely in the LMS itself. Most commonly through lecture video pushed to consumer platforms, user accounts created in a supplier's directory instead of federated from the institution, and analytics or AI features that call external services without appearing in any architecture diagram.

What is GARR and why does it matter here?

GARR is Italy's national research and education network - infrastructure funded and governed by the academic sector rather than supplied commercially. Running a shared academic platform over it means the network underneath is not a vendor relationship, which changes the sovereignty position substantially. Most European countries have an equivalent.

How does federated identity support sovereignty?

Each institution keeps its own identity provider and releases only chosen attributes to the platform, normally over SAML with Shibboleth. The platform never becomes the system of record for who your users are. National federations such as IDEM, linked internationally through eduGAIN, make this practical across many institutions at once.

Does choosing open source guarantee sovereignty?

No, but it preserves the option. Open source means the schema, plugins and integrations are inspectable, so changing supplier is a handover rather than a rebuild. A closed platform can be perfectly well run and still leave you with no route out.

Read next

Working on this?

If you are scoping a platform for a university or a consortium and sovereignty is a procurement condition rather than a preference, the useful conversation starts with where your data actually goes today.

Book a Free Demo

See EdzLMS in action.

Book a 45-minute demo tailored to your industry.

Book a Free Demo →