> Source: https://meetrix.io/blogs/sovereign-video-conferencing/
> Markdown copy of that page. Cite the URL above, not this file.

Collaboration

# Digital Sovereignty & Video Conferencing

[By Shalomi Umeshika](https://meetrix.io/blogs/authors/shalomi-umeshika/) • September 21, 2026 • 14 min read

Your meetings can sit on a server in Frankfurt and still be reachable by a court order from Washington.

That is the whole problem, and it is why "sovereign video conferencing" went from a phrase in government strategy papers to something procurement teams ask about by name. A data centre inside the EU tells you where the bytes live. It tells you nothing about who can be forced to hand them over.

This guide is for the person who has been asked to find a sovereign option and needs to know what that actually means before choosing a vendor. I will cover what counts as sovereign, why the big platforms' EU regions do not get you there, what European governments have already switched to, and what it takes to run it yourself.

The short version

Sovereignty is about **jurisdiction**, not location. If the company operating your video platform is subject to US law, an EU data centre does not change that. The only setup that fully removes the question is open source software (Jitsi Meet or LiveKit-based tools) running on infrastructure you or an EU provider control, with the encryption keys in your hands. Everything else is a point on a spectrum, and for plenty of organisations a middle point is fine.

## What sovereign actually means

Three terms get used as if they were the same thing. They are not.

**Data residency** is geography. Your recordings and chat logs are stored in a particular country. Most large vendors offer it, usually on higher plans.

**Data sovereignty** is law. The data is subject only to the laws of the place where it lives, and no outside government can reach it through the company holding it. This is the part residency does not give you.

**Digital sovereignty** is the wider version. It means being able to keep running, change supplier or change the software itself without asking anyone's permission. An organisation that cannot move off a platform without rewriting its workflows has a sovereignty problem even if its data is perfectly safe.

So a sovereign video conferencing setup is one where the software, the servers, the operators and the encryption keys all sit under a jurisdiction you chose. Remove any one of those and you have something weaker. Weaker can still be fine. You just need to know which one you gave up.

## Why an EU region falls short

The [US CLOUD Act](https://www.justice.gov/criminal/cloud-act-resources), passed in 2018, lets US authorities require a US company to produce data in its "possession, custody, or control", wherever in the world that data is stored. The server's location does not matter. The company's nationality does.

For a long time that was a theoretical argument. In June 2025 it stopped being one. Anton Carniaux, legal counsel at Microsoft France, was asked under oath at a French Senate inquiry whether he could guarantee that French citizens' data held by Microsoft would never be passed to US authorities without French approval. [His answer](https://www.theregister.com/2025/07/25/microsoft_admits_it_cannot_guarantee/) was "Non, je ne peux pas le garantir." No, I cannot guarantee it. He added that Microsoft contests such requests and that it had not happened in practice. But he could not promise it.

That is the same Microsoft that finished its EU Data Boundary in February 2025, the programme that keeps Microsoft 365 and Teams data stored and processed inside the EU. Both things are true at once. The data is in Europe, and a US legal order can still reach it.

Zoom is in the same position. Its EU Public Sector Sovereignty Controls offer dedicated EU infrastructure, customer-managed keys and an on-premises Zoom Node, which is a serious offer. Zoom's own explainer still lists exceptions where data can leave, including "as required by applicable law".

### What about the Data Privacy Framework?

The EU-US Data Privacy Framework is what currently makes transfers to certified US companies legal under GDPR. The EU General Court upheld it in September 2025 in the Latombe case. Latombe appealed to the Court of Justice in October 2025 (case C-703/25 P), and no ruling is expected before late 2026 at the earliest.

The Court of Justice struck down the two previous frameworks, Safe Harbor in 2015 and Privacy Shield in 2020. I would not build a five-year communications plan that depends on the third one surviving. If it falls, every organisation relying on it has to work out new legal grounds for its transfers, all at the same moment.

## Governments have already moved

These are the clearest examples of what a sovereign video platform looks like when an organisation actually commits to one.

**France.** In January 2026 the government announced that [Visio](https://lasuite.numerique.gouv.fr/) would replace Teams and Zoom across state services, with around 200,000 civil servants moving by 2027. The CNRS, the national health insurance fund, the public finance directorate and the armed forces ministry were first in line. Visio is built by DINUM on [La Suite Meet](https://github.com/suitenumerique/meet), an MIT-licensed project that runs on LiveKit, and it is hosted by Outscale on infrastructure qualified under ANSSI's SecNumCloud scheme. The government puts the saving at about one million euros a year for every 100,000 users who come off paid licences.

**Germany.** [openDesk](https://www.opendesk.eu/en), the federal government's sovereign workplace suite run by ZenDiS, uses Jitsi Meet for video, with Jigasi for phone dial-in. Schleswig-Holstein is moving its administration off Microsoft Office, with openDesk as the collaboration layer, and many German courts already use Jitsi for video hearings.

**The International Criminal Court** announced in October 2025 that it was replacing Microsoft Office with openDesk. That one is worth thinking about. It is an organisation whose work can put it at odds with the US government, and it chose not to rely on a US vendor.

**The European Commission** published its [Cloud Sovereignty Framework](https://commission.europa.eu/news-and-media/news/sovereign-cloud-framework-explained-2026-06-01_en) in October 2025 and used it to award a 180 million euro sovereign cloud contract in April 2026. The framework scores providers on eight objectives, from legal jurisdiction to supply chain, and on a SEAL scale of 0 to 4, where SEAL-4 means full sovereignty down to the hardware. In June 2026 the Commission also proposed the [Cloud and AI Development Act](https://digital-strategy.ec.europa.eu/en/policies/cloud-and-ai-development-act), which would tie public sector cloud contracts to graduated sovereignty levels. It is a proposal for now, but the direction is clear.

Notice what these projects have in common. None of them picked a US platform in an EU region. Every one of them went with open source, run by someone inside the jurisdiction. And between them they use the two engines that matter here, Jitsi and LiveKit. We compared those two directly in [LiveKit vs Jitsi](https://meetrix.io/blogs/livekit-vs-jitsi/).

## The four-layer test

When someone tells me they need a "sovereign" option, the useful next question is: sovereign at which layer? There are four, and a vendor can be strong on one and absent on another.

1.  **Software.** Can you read the code, run it without the vendor and keep it running if the vendor disappears or changes its terms? Open source licences such as Apache 2.0 (Jitsi) and MIT (La Suite Meet) answer yes. A proprietary platform cannot, however it is hosted.
2.  **Infrastructure.** Who owns the servers, and which country's law applies to that company? A US hyperscaler's Frankfurt region answers "Frankfurt" to where and "the US" to whose law.
3.  **Operations.** Who holds admin access, patches the servers and answers support tickets? If engineers outside your jurisdiction can log in, that is a way in, even when everything else is local.
4.  **Keys.** Who can decrypt the media? With standard WebRTC, traffic is encrypted between each browser and the media server, and the server decrypts it to forward it. With [end-to-end encryption in Jitsi Meet](https://meetrix.io/blogs/jitsi-meet-end-to-end-encryption/), the server only handles ciphertext.

Run each option you are considering through all four. Most "sovereign" marketing is about layer two, and a lot of it is only about data residency.

## Your realistic options

There are four realistic ways to set this up, and each gives up something different.

| Setup | Software | Infrastructure | Operations | Keys | Good fit for |
| --- | --- | --- | --- | --- | --- |
| Teams or Zoom with EU data residency | Proprietary | EU data centre, US company | Vendor | Vendor, or customer-managed keys on some plans | Businesses whose only concern is GDPR data location |
| US hyperscaler sovereign cloud (for example AWS European Sovereign Cloud) | Your choice | EU-only region and staff, US parent company | EU-resident staff | Yours | Regulated firms that want the hyperscaler toolset |
| Open source (Jitsi, LiveKit) on an EU-owned provider | Open source | EU company, EU law | You or an EU partner | Yours | Public sector, healthcare, legal, anyone facing a sovereignty requirement in a tender |
| Open source on your own hardware | Open source | Yours | You | Yours | Defence, courts, closed networks, air-gapped sites |

A note on the second row. AWS made its European Sovereign Cloud generally available in January 2026, with the first region in Brandenburg, run by a separate EU entity with EU-resident staff and no operational dependency outside the EU. It is a real engineering effort and it closes the operations gap. Plenty of European lawyers still argue that a US parent company leaves the CLOUD Act question open. My honest read: it is a big improvement over a normal EU region, and whether it counts as sovereign depends on who is judging. If a tender asks for SecNumCloud or SEAL-3 and above, check the exact wording before you bid with it.

Where does Meetrix fit? We build and support self-hosted Jitsi Meet, so we sit in rows three and four. The [Jitsi Meet image in our store](https://meetrix.io/store/jitsi-meet/) runs on AWS and Google Cloud, which suits teams that want control of the software and keys and are comfortable with a US cloud underneath. For the stricter cases, our [self-hosted video conferencing service](https://meetrix.io/services/self-hosted-video-conferencing/) deploys the same stack on your own servers, including closed networks with no internet access.

One thing I have to say plainly because people get it wrong: Jitsi Meet is developed mainly by 8x8, a US company. That does not matter for sovereignty once you self-host it. The code is Apache 2.0, it runs on your servers, and 8x8 has no access to a deployment it does not operate. Using 8x8's hosted meet.jit.si service is a different matter, since that one is run by a US company.

## Where self-hosting gets hard

Self-hosted Jitsi is the most common route to sovereign video conferencing, and installing it is the easy part. These are the problems that come after the install.

### Your install still talks to the outside world

A default Jitsi Meet install can make requests to outside services, such as avatar lookups, which leak IP addresses and meeting activity to third parties. The fix is `disableThirdPartyRequests` in `config.js`, and then checking the browser's network tab to confirm nothing leaves your domain. Do not skip the check. Our [Jitsi Meet security best practices](https://meetrix.io/blogs/jitsi-meet-security-best-practices/) guide goes through this and the other common settings people miss.

### End-to-end encryption has a price

Jitsi's E2EE uses the browser's insertable streams API, so it works in Chromium-based browsers such as Chrome, Edge and Brave, and support elsewhere varies. Turn it on and you lose recording, live streaming, transcription and phone dial-in, because each of those needs a server that can see the media. The [Jitsi security page](https://jitsi.org/security/) lists the current limits. For most sovereign deployments you do not need E2EE at all. If you control the server, you control the decryption point, and that is the point. Save E2EE for meetings where you do not trust the host, even when the host is you.

### TURN, capacity and the people who run it

Some users will be on networks that block the UDP ports WebRTC prefers, so you need a TURN server, and it has to be on sovereign infrastructure as well. A sovereign Jitsi instance that quietly relays through a US-hosted TURN service has undone its own purpose. Our guide to [setting up a TURN server for Jitsi](https://meetrix.io/blogs/setting-up-a-turn-server-for-jitsi-meet/) covers the build.

Then there is capacity and upkeep. One videobridge carries a lot, but a company all-hands will find its limits. Someone has to renew certificates, apply security patches and pick up the phone when the board meeting drops. We laid out the real numbers in [what self-hosting Jitsi actually costs](https://meetrix.io/blogs/jitsi-meet-self-hosting-cost/). The cost that catches people out is not the servers. It is the time of the engineer who looks after them.

### Don't forget identity

If people log in to your sovereign video platform with a US-hosted identity provider, part of your data is still outside your jurisdiction: who attended, when, and from where. Put authentication on the same side of the line. Keycloak works well for this, and we covered [Jitsi with Keycloak SSO](https://meetrix.io/blogs/jitsi-keycloak-sso/) separately.

## So which one do you need?

If you are a private company whose only concern is GDPR, Teams or Zoom with EU data residency is probably enough, as long as the Data Privacy Framework holds. Just know that it is residency, and do not call it sovereignty in a document someone will check later. The same distinction applies to file storage, as our [Nextcloud vs Google Drive](https://meetrix.io/blogs/nextcloud-vs-google-drive/) comparison shows.

If you are public sector, healthcare, legal, or bidding on tenders that now include sovereignty criteria, go with open source on infrastructure you control. Jitsi Meet has the longest track record in European government. Run it on an EU-owned provider or your own hardware, close off the third-party requests, host your own TURN and identity, and you have met every layer of the test.

And if you are somewhere in between, start with the software layer. An open source platform can be moved to a more sovereign host later without retraining anyone. A proprietary platform cannot be moved off its vendor. For more on how the platforms compare on security, see our [review of secure video conferencing tools](https://meetrix.io/blogs/secure-video-conferencing-tools-review-2026/). To see what else you could run instead of Jitsi, read [seven self-hosted video conferencing options](https://meetrix.io/blogs/open-source-video-conference-software/).

## Frequently Asked Questions

What is sovereign video conferencing?

Video conferencing where the software, the servers, the encryption keys and the people who operate them all sit under a jurisdiction you choose. In practice that means no foreign government can compel the provider to hand over your meeting data, because there is no foreign provider in the chain.

Is Microsoft Teams sovereign if the data stays in the EU?

No. Microsoft's EU Data Boundary keeps customer data stored and processed in the EU, but Microsoft is a US company and falls under the US CLOUD Act. In June 2025 Microsoft France's legal counsel told the French Senate under oath that he could not guarantee EU data would never reach US authorities.

Does hosting in an AWS or Azure EU region make video conferencing sovereign?

It gives you data residency, not sovereignty. The servers are in Frankfurt or Paris, but the provider is still a US company. The AWS European Sovereign Cloud, live since January 2026, adds EU-only staff and a separate EU entity, which narrows the gap. Whether that closes it is still debated.

Is self-hosted video conferencing automatically sovereign?

Only if you also control where it runs. Self-hosted Jitsi on a US hyperscaler still puts the servers under US jurisdiction. Self-hosted Jitsi on an EU provider or your own hardware, with third-party requests switched off, is about as sovereign as video conferencing gets.

Is Jitsi Meet GDPR compliant?

The software does not make you compliant or non-compliant on its own. What matters is how you run it. A self-hosted Jitsi deployment with no accounts, no stored recordings and no third-party requests processes very little personal data, which makes a GDPR assessment much simpler. Our [GDPR and WebRTC article](https://meetrix.io/blogs/gdpr-webrtc-solutions-meetrix/) covers this in more detail.

What video conferencing does the French government use?

Visio, built by the interministerial digital directorate DINUM on the open source La Suite Meet project, which runs on LiveKit. It is hosted on SecNumCloud-qualified infrastructure at Outscale and is replacing Teams and Zoom across state services by 2027.

Does end-to-end encryption solve data sovereignty?

It solves part of it. With E2EE on, the media server cannot see the audio and video, so a legal order against the host gets encrypted streams. It does not hide metadata such as who met, when and for how long, and in Jitsi it switches off recording, transcription and phone dial-in.

## Run Jitsi Meet on Infrastructure You Control

We deploy and support Jitsi Meet on AWS, Google Cloud, your own servers or a fully closed network, so the servers and the keys stay with you.

[See Self-Hosted Video Conferencing Options](https://meetrix.io/services/self-hosted-video-conferencing/)

Meetrix Store

Jitsi Meet

Self-hosted video calls for 50 to 500 users

[Deploy it](https://meetrix.io/store/jitsi-meet/)

Meetrix Store New

Deploy what this guide covers, pre-configured.

-    [Jitsi Meet Self-hosted video calls for 50 to 500 users](https://meetrix.io/store/jitsi-meet/)
-    [Coturn TURN/STUN for WebRTC, no per-minute relay fees](https://meetrix.io/store/coturn/)
-    [Mattermost Team chat, a self-hosted Slack alternative](https://meetrix.io/store/mattermost/)
-    [RustDesk Remote desktop AMI, a TeamViewer alternative](https://meetrix.io/store/rustdesk/)
-    [OpenVPN Encrypted remote access, no per-user fees](https://meetrix.io/store/openvpn/)
-    [Plane Issues, cycles and roadmaps, a Jira alternative](https://meetrix.io/store/plane/)

[Browse all products](https://meetrix.io/store/)
