By the Linux Association of Canada
For years, digital sovereignty has often been discussed as an abstract policy issue.
Who owns our data? Where is it stored? Who controls the infrastructure on which governments, businesses and citizens increasingly depend?
Recent developments in the Netherlands demonstrate why those questions are becoming much more practical.
The Dutch government is developing a new digitally autonomous government workplace known as DAWO — Digitaal Autonome Werkomgeving Overheid, or Digital Autonomous Work Environment for Government.
At the centre of that project is something particularly interesting to the Linux and open-source community: NixOS.
But the real story is not simply that another government is experimenting with Linux.
It is why.
From Convenience to Dependency
Modern governments depend heavily on digital infrastructure.
Email, identity management, document storage, collaboration platforms, cloud computing, cybersecurity systems and increasingly artificial intelligence are essential to everyday government operations.
Much of that infrastructure is supplied by a relatively small number of technology companies headquartered outside the countries using their services.
For many years, that arrangement has offered significant advantages. Large technology providers can deliver sophisticated systems at enormous scale, often faster and more economically than governments could build themselves.
The problem begins when convenience becomes dependency.
The Dutch government's strategy on digital autonomy identifies exactly this concern. It notes that critical government functions increasingly rely on a small number of, often foreign, suppliers and identifies risks including outages, cyberattacks and geopolitical pressure. Rijksoverheid
Digital sovereignty therefore does not necessarily mean rejecting foreign technology.
It means maintaining choice, control and the ability to continue operating when circumstances change.
That distinction is important.
Then the Theoretical Risk Became Real
In 2025, events involving the International Criminal Court in The Hague provided an unusually visible example of what technological dependency can mean.
The United States imposed sanctions on ICC Chief Prosecutor Karim Khan and subsequently sanctioned additional ICC officials. The U.S. government said the measures were a response to ICC actions concerning the United States and Israel; critics of the sanctions argued that they threatened the court's independence. AP News
Whatever one's position on the underlying political dispute, the technological consequences are relevant far beyond the ICC.
Associated Press reporting found that Khan's official ICC email account was disabled and that sanctions disrupted access to other financial and technology services. The ICC has subsequently worked to reduce its reliance on American technology, including moving from Microsoft products toward a German software provider. The Associated Press
Microsoft has disputed reports characterizing its role in cutting off the prosecutor; the UK government noted in July 2025 that Microsoft had "strongly denied" blocking Khan's email account. UK Parliament
That distinction matters.
The broader digital-sovereignty question does not depend on whether Microsoft wanted to terminate a service.
The issue is that technology providers operate under laws and jurisdictions that may be different from those of their customers.
A service considered essential today can therefore become unavailable tomorrow because of sanctions, legislation, regulatory action, corporate decisions, geopolitical disputes or other circumstances beyond the customer's control.
That turns digital sovereignty from an ideological debate into a business-continuity and national-resilience question.
The Dutch Response: DAWO
The Netherlands is now developing something considerably more ambitious than simply replacing Microsoft Windows on a few computers.
DAWO is an initiative of the Dutch Ministry of the Interior and Kingdom Relations intended to create an interoperable and digitally autonomous foundation for government workplaces. Code Overheid
The project currently includes several components.
Its primary operating-system implementation is DAWO-NixOS, based on the Linux distribution NixOS. A Fedora Kinoite implementation is also being developed as an alternative.
But the architecture extends far beyond the desktop.
The government's DAWO project includes work on fleet management and orchestration, identity and access management, collaboration software, artificial intelligence and an open government cloud. Code Overheid
And importantly for open source, this isn't happening entirely behind closed doors.
The DAWO-NixOS repository is publicly accessible through the Dutch government's code platform. It contains the NixOS configurations used to build reproducible and modular environments across different systems. Code Overheid
The project's deployment architecture also demonstrates that this is being approached as managed infrastructure rather than simply installing Linux manually on individual computers. Documentation describes automated installation, encrypted storage, centralized deployment, automatic updates and fleet management. Code Overheid
This is a serious attempt to investigate what an autonomous government computing environment could look like.
Linux Is Only Part of the Answer
There is another important lesson in the Dutch experience.
Replacing an operating system isn't enough.
The Netherlands has also been developing Mijn Bureau, an open-source workplace environment. According to the Dutch government's Digital Government portal, approximately 200 employees were using the environment by April 2026.
The government's assessment is particularly interesting.
It found that an open-source workplace combining an operating system, office applications and collaboration tools is technically feasible.
The difficult parts increasingly involve people and organizations: support, management, procurement, workflows, document interoperability and collaboration with organizations still using other platforms. Digitale Overheid
Anyone who has managed a technology migration will recognize this immediately.
The biggest obstacle to Linux adoption is not always Linux.
It is the ecosystem surrounding the existing platform.
Documents need to work. People need training. Authentication needs to function. Applications need replacements. Administrators need management tools. Help desks need expertise. Organizations need migration plans.
Digital sovereignty therefore cannot be achieved simply by downloading an ISO.
It requires an ecosystem.
Open Source Changes the Equation
This is where open source becomes strategically important.
Open-source software does not eliminate dependency. Organizations will still depend on developers, hardware manufacturers, hosting providers, consultants, networks and supply chains.
But it can fundamentally change the nature of that dependency.
If an organization possesses the source code, uses open standards, maintains internal technical expertise and can move workloads between providers, the failure or loss of one supplier does not necessarily mean losing the technology itself.
Another provider can potentially operate it.
The organization can operate it internally.
A domestic company can support it.
A government can modify it.
A community can continue developing it.
That is very different from an environment in which the technology, infrastructure, data formats and administrative expertise are inseparable from one vendor.
The Dutch government explicitly recognizes this relationship. Its digital-autonomy strategy calls for increased use of open standards and open source to reduce vendor lock-in, alongside investment in internal digital expertise and European alternatives. Rijksoverheid
The Dutch government is also advocating stronger European cloud sovereignty, including greater use of open applications and standards. Rijksoverheid
Digital Sovereignty Does Not Mean Digital Isolation
This point deserves emphasis.
Digital sovereignty should not mean that every country attempts to manufacture every computer, write every application and operate every cloud service itself.
That would be neither realistic nor desirable.
Even the Dutch government's strategy explicitly recognizes that complete technological independence does not exist.
The objective is instead to retain enough control to make meaningful choices.
Can we change suppliers?
Can we move our data?
Can we operate critical infrastructure ourselves if necessary?
Do we understand the technology on which we depend?
Can another supplier take over?
Are open standards available?
And perhaps most importantly:
If a critical supplier disappeared tomorrow, could we continue operating?
Those are much more useful measures of digital sovereignty than simply asking where a particular software company is headquartered.
Canada Should Be Asking the Same Questions
Canada is not the Netherlands.
Our government structures, geography, economy and technology ecosystem are different.
But the underlying questions apply here just as much.
Canadian governments, universities, healthcare institutions, businesses and other organizations increasingly depend on infrastructure controlled by a relatively small number of global technology companies.
That does not automatically make those technologies inappropriate.
It does mean that dependency should be understood.
For critical systems, Canada should be asking:
What happens if access to a foreign technology platform is interrupted?
Can Canadian organizations migrate their data without prohibitive technical or financial barriers?
Are open standards being used so information remains accessible across platforms?
Do we have viable alternatives?
And do we have enough people in Canada who know how to build, operate and secure those alternatives?
The last question may ultimately be the most important.
Digital Sovereignty Requires People
A country cannot become digitally sovereign simply by adopting open-source software.
Someone has to operate it.
Someone has to secure the servers.
Someone has to maintain the networks.
Someone has to manage Linux systems, containers and cloud infrastructure.
Someone has to audit the code, automate deployments, respond to incidents and maintain identity systems.
Someone has to train the next generation.
That means Linux administration, DevOps, cybersecurity, automation, cloud infrastructure, open-source development and related skills are more than technology-sector employment skills.
They are part of Canada's national digital capacity.
This is one of the reasons the Linux Association of Canada believes that strengthening Canada's open-technology workforce is important.
A country that wants technological choices must have people capable of implementing those choices.
Without that expertise, alternatives may exist technically while remaining impossible operationally.
The Netherlands Is Not Just Talking About It
Perhaps the most significant aspect of the Dutch example is that the discussion has moved beyond policy documents.
Code is being written.
Systems are being tested.
Government employees are using open-source workplace environments.
Infrastructure is being developed.
And government policy is increasingly treating digital autonomy as part of national resilience.
The movement is also spreading across government. In June 2026, the Dutch Tax Administration announced that strengthening digital autonomy would be a priority, including greater internal IT management, expanded data-centre capacity, increased use of open source and greater internal development capability. Rijksoverheid
That represents a significant shift in how governments can think about technology procurement.
Instead of asking only:
"Which product should we buy?"
Governments can also ask:
"Which capabilities must we retain?"
Those are very different questions.
Canada Does Not Need to Copy the Netherlands
Canada does not necessarily need a Canadian version of DAWO.
It does need the conversation DAWO represents.
Governments should understand their technological dependencies before those dependencies become a crisis.
Critical systems should have credible exit strategies.
Open standards should make interoperability and migration possible.
Open-source alternatives should be evaluated on technical and operational merit rather than dismissed simply because they are different from established commercial platforms.
Public institutions should maintain enough internal expertise to understand and control the systems on which they depend.
And Canada's technology workforce should include the Linux, open-source, cybersecurity, cloud and infrastructure skills necessary to provide genuine alternatives.
This isn't about declaring war on Microsoft, Google, Amazon or any other technology company.
Those companies provide technologies used successfully by millions of organizations.
It is about ensuring that using a supplier does not become the same thing as being unable to operate without that supplier.
There is an enormous difference between the two.
Sovereignty Means Having a Choice
The Netherlands provides a useful case study because it demonstrates what digital sovereignty can mean in practice.
Not isolation.
Not technological nationalism.
Not abandoning every proprietary product.
Choice.
The ability to choose technology.
The ability to understand it.
The ability to move away from it.
The ability to operate critical systems when geopolitical or commercial circumstances change.
And the domestic knowledge required to make those choices meaningful.
Open source cannot guarantee digital sovereignty.
But it can provide something that is extremely difficult to achieve when technology is completely controlled by somebody else:
the ability to choose a different path.
For Canada, that may be one of the most important reasons to invest in Linux, open source and the people who understand them.
The Linux Association of Canada promotes Linux, open-source technology, education and the development of Canadian open-technology skills and infrastructure.
Sources
Dutch Government — DAWO project repository
Dutch Government — DAWO-NixOS repository
Government of the Netherlands — Digital Autonomy and Sovereignty strategy
Digital Government Netherlands — Autonomous Workplace case study
Associated Press — Effects of U.S. sanctions on the ICC
Government of the Netherlands — Digital autonomy at the Tax Administration



Comments (0)