Frequently Asked Questions
Answers to the most common questions about the Observatory and the digital sovereignty of the Italian Public Administration.
The Observatory
The Observatory is an independent project that measures and monitors the state of digital sovereignty in the Italian Public Administration. It analyses the PA's dependence on foreign digital infrastructure and services, with particular attention to email providers.
MxMap.it is the technical project that collects the raw data by analysing the MX (Mail Exchange) records of Italian PA domains. The Observatory uses this data as a primary source, contextualises it and publishes it in the form of accessible reports and periodic analyses.
sovranita-digitale.it is another independent Italian civic initiative, with which we share the goal. The difference lies in the breadth and the angle:
- Observatory (with MxMap.it) — a focused, in-depth analysis of the PA's email: for each public body we identify the email provider and its jurisdiction (legal sovereignty), with an open and reproducible methodology and data updated daily.
- sovranita-digitale.it — a multidimensional analysis: it collects and cross-references multiple databases and public sources (cloud, DNS, ASN, TLS, lock-in, interoperability) for a broader picture of technological dependence, with maps and indices per body.
The two initiatives are complementary: we go deep into a single critical service (email), they offer a cross-cutting overview. You can find both, along with other European initiatives, on the Related initiatives page.
All reports are public and freely available. The contents are released under the Creative Commons BY-SA 4.0 licence, so they may be reused by citing the source.
The data is collected periodically and the reports are published at regular intervals to monitor the evolution over time. The exact frequency depends on the availability of updated and significant data.
Digital Sovereignty
By digital sovereignty we mean the ability of a public body to maintain effective control over its own digital infrastructure and over citizens' data. This includes the jurisdiction under which the data falls, operational control over the infrastructure and independence from non-European technology providers.
Email is one of the most widely used communication channels in the PA. When a public body uses a foreign provider, institutional communications — often containing sensitive citizen data — transit through and are stored on infrastructure subject to foreign jurisdictions, such as the US CLOUD Act.
Not with certainty. Heard under oath before the French Senate committee of inquiry on 10 June 2025, Microsoft France's Director of Public and Legal Affairs, Anton Carniaux, was asked by the rapporteur whether he could guarantee that French citizens' data would never be transmitted following an injunction from the US government, without the explicit agreement of the national authorities. His answer: “No, I cannot guarantee it, but, once again, this has never yet happened.” The provider itself therefore admits it cannot rule out such a transfer — “it has never happened” is not the same as “it cannot happen”.
The question concerned French data, but the mechanism is identical for Italy: jurisdiction follows the supplier's nationality, not the customer's. There is however a way out, and it does not require abandoning these technologies: see Certifications and Sovereignty.
Sources: French Senate record · heise (EN)
MX (Mail Exchange) records are DNS records that indicate which server handles the email for a given domain. By analysing the MX records of PA domains, we can determine which provider handles each body's mail and whether it is an Italian, European or non-European service.
It is not a question of technical security — the major providers generally offer high security standards. The issue is jurisdiction: data hosted by US providers is potentially accessible to US authorities through the CLOUD Act, even if physically located in Europe. The Observatory does not judge the quality of the service, but documents the jurisdictional dependence.
Why it should matter to me
When you communicate with your local health authority, your municipality or your school by email, your personal data transits through the servers of the provider chosen by that body. If the provider is subject to foreign jurisdiction, your data may be accessible to authorities of other countries — without you knowing and without the guarantees provided by the European GDPR.
You can check your body's position on digital sovereignty and compare it with comparable bodies. The data can support an internal proposal to migrate to compliant providers, justify budget requests and demonstrate a proactive approach to managing jurisdictional risk.
Absolutely. All data is public and released under the CC BY-SA 4.0 licence. You can cite it freely, indicating as the source "National Digital Sovereignty Observatory, based on MxMap.it data". Visit the Press Kit section for ready-to-use materials and press contacts.
It depends on your role. If you are a citizen, share the reports and ask your municipality about its position on digital sovereignty. If you work in a PA, check your body and propose an internal assessment. If you are a politician, use the data for formal questions and proposals. If you are a researcher, analyse the data and publish. See the Get Involved section for all the ways to contribute.
No. The Observatory does not judge the quality of the services and is not against any provider. It documents a fact: when the PA entrusts its data to a provider subject to non-EU jurisdiction, a jurisdictional dependence is created that has concrete implications for the protection of citizens' data and for institutional autonomy. Our work is to measure and make this dependence visible with objective data.
Data and Methodology
The list of bodies and their domains comes from the Index of Public Administrations (IndicePA), the official database managed by AgID that gathers information on all Italian PAs. The data on email providers is then obtained by analysing the MX records of each domain.
Yes. All data and reports are released under the CC BY-SA 4.0 licence. They can be freely consulted, downloaded, reused and redistributed, provided that the source is cited and the same licence is maintained for derivative works.
You can open a report on GitHub Issues. We appreciate every contribution to improving the quality and accuracy of the data.