Designing the technological and legal fabric of digital sovereignty for critical governmental data and essential services extraterritorially: The “data embassy” model

Amidst the renewed debate on Europe's digital sovereignty, this paper counterintuitively questions the implicit assumption, underpinning legal scholarship and policymaking, that sovereignty can be effectively materialised solely within a state’s territory. The paper argues that the creative tailoring of international law and innovative technologies can be leveraged to effectively exercise digital sovereignty also outside a state’s territory. The discussion focuses on Estonia’s novel data embassy, which includes the establishment of a data centre in Luxembourg’s territory to host and run Estonia’s critical governmental datasets and essential services. Although initially perceived as an “oddity”, this model of digital sovereignty gains increasing traction in international practice. The legal means for Estonia to retain sovereign control over its data centre vis-à-vis Luxembourg is the creation of a sui generis bilateral treaty regime which assigns diplomatic status to the data centre. The analysis critically evaluates the parties’ rights and obligations concerning the functioning, inviolability and protection of the centre, and the protection of the centre’s content and communications. It does so by analysing their agreement, in light of diplomatic law and EU cybersecurity law. Furthermore, the paper furnishes new insights on third states’ obligations under diplomatic law, international humanitarian law and the principle of sovereignty regarding the protection of the data centre from physical and cyber interferences. The analysis identifies certain legal concerns pertaining to the implementation of the data embassy model and paves the way for states and other actors to navigate legal hurdles with legal certainty.

Authors

Institutions

Publication Details

Journal
Computer law & security review
Published
2026-09-19
DOI
https://doi.org/10.1016/j.clsr.2026.106409
Primary Topic
Cybersecurity and Cyber Warfare Studies
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Designing the technological and legal fabric of digital sovereignty for critical governmental data and essential services extraterritorially: The “data embassy” model

Mando Rachovitsa
Computer law & security review
Cybersecurity and Cyber Warfare Studies
article

Designing the technological and legal fabric of digital sovereignty for critical governmental data and essential services extraterritorially: The “data embassy” model

Mando Rachovitsa
article en

Abstract

Amidst the renewed debate on Europe's digital sovereignty, this paper counterintuitively questions the implicit assumption, underpinning legal scholarship and policymaking, that sovereignty can be effectively materialised solely within a state’s territory. The paper argues that the creative tailoring of international law and innovative technologies can be leveraged to effectively exercise digital sovereignty also outside a state’s territory. The discussion focuses on Estonia’s novel data embassy, which includes the establishment of a data centre in Luxembourg’s territory to host and run Estonia’s critical governmental datasets and essential services. Although initially perceived as an “oddity”, this model of digital sovereignty gains increasing traction in international practice. The legal means for Estonia to retain sovereign control over its data centre vis-à-vis Luxembourg is the creation of a sui generis bilateral treaty regime which assigns diplomatic status to the data centre. The analysis critically evaluates the parties’ rights and obligations concerning the functioning, inviolability and protection of the centre, and the protection of the centre’s content and communications. It does so by analysing their agreement, in light of diplomatic law and EU cybersecurity law. Furthermore, the paper furnishes new insights on third states’ obligations under diplomatic law, international humanitarian law and the principle of sovereignty regarding the protection of the data centre from physical and cyber interferences. The analysis identifies certain legal concerns pertaining to the implementation of the data embassy model and paves the way for states and other actors to navigate legal hurdles with legal certainty.

Computer law & security reviewVol. 63
University of Nottingham (GB)
Peace, Justice and strong institutions
Openalex Percentile: Top 3%
Cybersecurity and Cyber Warfare Studies
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Designing the technological and legal fabric of digital sovereignty for critical governmental data and essential services extraterritorially: The “data embassy” model — Mando Rachovitsa · Computer law & security review (2026) | TGRS Research Map | TGRS