Stakeholders and Impact
The Observatory is a civic monitoring project at the service of all. Every stakeholder has a role in the journey towards the digital sovereignty of the Italian Public Administration.
Digital sovereignty is not a purely technical matter. It concerns national security, citizens' rights, economic competitiveness and European strategic autonomy. This is why the Observatory addresses a plurality of actors, each with different motivations and capacity for action.
National political decision-makers
Who: Members of Parliament, Under-Secretaries, the Presidency of the Council of Ministers, the Department for Digital Transformation.
Why: Digital sovereignty is a national security issue. Decision-makers need concrete, verifiable data for parliamentary questions, amendments and bills.
What they can do: Parliamentary questions, legislative proposals, committee hearings, strategic direction.
For Decision-makersAuthorities and regulators
Who: AgID, ACN (National Cybersecurity Agency), Garante Privacy, ANAC, Consip.
Why: The Observatory measures the effectiveness of existing policies. The data highlight compliance gaps (GDPR, Schrems II) and jurisdictional risks (CLOUD Act).
What they can do: Update guidelines, embed sovereignty requirements in framework agreements, launch compliance audits.
PA managers and IT officers
Who: CIOs and Heads of Information Systems of municipalities, regions, local health authorities, universities, ministries — around 23,000 public bodies.
Why: Many public bodies are unaware they depend on non-EU providers. The Observatory provides a mirror: each body can check its own position and compare itself with peer bodies.
What they can do: Plan migration, request funding, justify IT investments with objective data.
Italian and European providers
Who: Aruba, Register.it, Infocert, TIM, OVHcloud, Proton, Infomaniak and other European email and cloud providers.
Why: The data quantify the potential migration market. If the majority of the PA uses non-EU providers, there is an enormous addressable market.
What they can do: Develop offerings tailored to the PA, support the project, engage in informed lobbying with concrete data.
Journalists and media
Who: Specialist journalists (Cybersecurity360, CorCom, Key4biz, Agenda Digitale) and general-interest media (Sole 24 Ore, Wired, RAI).
Why: Data make headlines. Verifiable figures and a citable source are exactly what a journalist needs to write a piece in two hours.
What they can do: Articles, investigations, features. Every publication amplifies the project and puts pressure on decision-makers.
Press KitAcademia and research
Who: Lecturers and researchers in IT law, cybersecurity and political science. PhD candidates and undergraduate dissertation students.
Why: Open dataset, documented methodology, current topic. For a researcher these are real data to publish with; for a student it is a ready-made thesis.
What they can do: Peer-reviewed publications, in-depth analysis, predictive models, international comparisons.
Open DataCivil society and activism
Who: Hermes Center, Transparency International Italia, Italian Linux Society, digital civic networks, open source and privacy activists.
Why: Digital sovereignty is a matter of fundamental rights. The Observatory turns an abstract concept into concrete data for advocacy campaigns.
What they can do: Public campaigns, informed petitions, pressure on local administrators, participation in public consultations.
European institutions
Who: European Commission (DG CONNECT, DG DIGIT), ENISA, European Parliament, EU Cybersecurity Competence Centre.
Why: Italy would be the first country to systematically measure the digital sovereignty of the PA in an open way. The model is replicable in every Member State of the Union.
What they can do: Adopt the model as best practice, fund its extension to other countries, include analogous metrics in evaluation criteria.
Local administrators
Who: Mayors, innovation councillors, regional presidents, directors-general of local bodies.
Why: Competition between bodies is a powerful lever. If your municipality is at the bottom of the ranking, someone will point it out. If it is at the top, it is an achievement worth communicating.
What they can do: Migration resolutions, funding allocation, adherence to framework agreements for sovereign services, political communication.
Public and policy domains
Digital sovereignty intersects multiple policy domains. The Observatory provides relevant data for each of them.
| Domain | Why it matters | Main lever |
|---|---|---|
| National security | PA email on foreign servers means exposure to third-country intelligence | Geopolitical risk, CLOUD Act, surveillance |
| Personal data protection | Non-EU transfer of citizens' data via PA email | GDPR, CJEU Schrems I and II rulings |
| Public procurement | Consip framework agreements shape the choices of thousands of bodies | Spending volume, available alternatives |
| Digital transformation | The PNRR invests billions in the digitalisation of the PA — towards which providers? | Destination of public funds |
| Industrial policy | The PA cloud/email market is dominated by non-EU operators | Competitiveness, employment, local economy |
| EU strategic autonomy | Dependence on non-EU infrastructure for critical state functions | Geopolitics, resilience, European sovereignty |
Expected impact
The Observatory aims to generate concrete and measurable impact in each of these domains:
Press articles, citations in institutional documents, public debate informed by data.
Parliamentary questions, updated guidelines, sovereignty requirements in framework agreements.
Bodies starting the transition to sovereign providers, a measurable reduction in non-EU dependence.
The Business Case sets out the market opportunity of migrating to sovereign providers and the lever of public procurement.
Download Business Case (PDF)Want to contribute?
The Observatory is an open project. Every stakeholder can take part within their own area of expertise.
How to take part For decision-makers