Who manages access to data? The challenge of operational sovereignty
For a long time, the debate on digital sovereignty has centred primarily on the localisation of data and the belief that information stored within national or European borders is automatically under control. This approach has guided technological strategies, infrastructure investment and regulatory decisions. Today, this framework appears increasingly inadequate for describing the operational reality faced by companies, businesses and public institutions. The evolution of cloud computing, the spread of hybrid and multi-cloud architectures, and the growing complexity of digital supply chains have gradually separated two dimensions that in the past tended to coincide: the location where systems reside and the location from which they are managed. An organisation may have data stored in Italia or within the EU, use particularly advanced encryption technologies and operate in full compliance with European regulatory requirements. However, this does not preclude the day-to-day management of the infrastructure being carried out by staff operating from other jurisdictions via privileged remote access. In this scenario, the location of the data is a necessary but not always sufficient condition for ensuring effective control over the data itself.
The central question then becomes another: who can actually access the systems? The concept of sovereignty is gradually taking on a more operational rather than infrastructural dimension, extending beyond the ownership of platforms and the geographical location of data centres to include the ability to govern access, supervise administrative activities and maintain control over critical operations. This line of thinking forms part of a broader context, in which strategic autonomy and the reduction of technological dependencies have heightened the focus on the issue of effective control over digital infrastructure – a condition that various experts consider essential for Europe’s economic and industrial competitiveness. Similarly, EU initiatives dedicated to cloud computing, AI and cybersecurity are gradually shifting the focus from the mere use of technologies to their governance. In other words, the question facing CEOs, CIOs and public decision-makers is essentially this: who is actually able to intervene in the systems that host and safeguard data?
Privileged access and operational resilience
The intersection between security and sovereignty lies in privileged access – that is, administrative accounts that allow users to configure infrastructure, modify settings, access data and manage critical components of a digital environment. From a cybersecurity perspective, these access rights have always been one of the main areas of risk; whilst, in the context of sovereignty, they represent the true point of control over systems. To give a concrete example, an administrator with elevated privileges can, in fact, influence the operation of an environment far more than procedures, policies or formal constraints ever could.
For this reason, the physical and legal location of the teams administering the platforms is becoming increasingly important, and the place from which they operate and the legal system to which they are subject are also crucial. Managing this access means adopting models in which every action is authorised, monitored and logged; looking deeper, it means having Privileged Access Management tools, models to limit (access) privileges to the time strictly necessary, and applying principles of segregation of duties and mutual oversight.
The difference is substantial: it is not simply a matter of preventing unauthorised access, but of building a system capable of ensuring that no access can take place without supervision, awareness and verifiability. Added to this is a second dimension, which is increasingly strategic for digital security, namely operational resilience. The geopolitical tensions of recent years have highlighted how the continuity of digital services can be influenced by factors entirely beyond the control of individual organisations, ranging from international sanctions to regulatory changes, from trade restrictions to decisions taken by entities in other jurisdictions that can have a direct impact on the availability of essential technologies and services. Operational sovereignty and resilience are thus converging towards a single objective: to ensure that control over digital infrastructure remains effectively in the hands of those who are truly responsible for it.
Control, governance and continuity: the approach of TIM Enterprise
Whilst digital sovereignty is increasingly measured by the ability to manage access and maintain control over operations, it is easy to see how addressing this issue solely from a technological perspective is reductive. Instead, expertise, processes, governance and a clear legal framework for critical activities are required. It is within this context that the proposal from TIM Enterprise fits, built around the principles of operational control, access supervision and service continuity.
The first area of focus concerns the legal and organisational dimensions. The systems managed by TIM are, in fact, administered by teams based throughout Italia and are subject to Italian law; from the perspective of operational sovereignty, the difference is far from marginal: privileged access exercised by staff operating within the Italian regulatory framework has profoundly different characteristics compared to access exercised by parties subject to different legal systems. The second element concerns governance. TIM Enterprise adopts models that ensure every intervention on its critical systems is visible and controllable, and that privileged access is managed through structured procedures, time-limited authorisations and the application of the ‘four-eyes’ principle. Furthermore, the client company always maintains an active role in the process, being able to authorise interventions by the technology provider in advance in accordance with defined and traceable procedures.
A third distinctive feature of TIM Enterprise’s approach to sovereignty, and by no means the least important, is operational resilience. Management and support activities do not depend on facilities located outside the European Union and can therefore guarantee continuity in any scenario. This feature is particularly important for organisations required to meet the continuity requirements set out in NIS2 and the DORA regulation for the financial sector. Finally, this approach is reinforced by the experience TIM has gained in managing critical infrastructure and sensitive environments for the public administration and regulated sectors – contexts in which security, reliability and control are essential requirements.
Ultimately, digital sovereignty is not just about where data is stored, but also about the people who can access the systems, the processes governing such access, and operational continuity over time. Given the complexity of the current landscape, the control of privileged access and operational resilience are set to become two of the most concrete indicators of an organisation’s ability to maintain control over its digital infrastructure.

