Kammarkoll

Search everything said in the debates of the Swedish Riksdag

← To the search

Response to interpellation 2025/26:542 on the national cloud policy and Sweden's digital sovereignty

18 June 2026 · 7 speeches · KD, SD

Translated from Swedish by AI; the translation may contain errors. The Swedish text is the original.

Summary AI, written in advance

KD considers that the cloud policy is guiding for public administration 1 2 and that public actors are self-responsible for their assessments as legislation regarding data protection already exists 1 2. KD emphasizes the importance of digital sovereignty for security and economy 3 and wants to promote Swedish and European alternatives 1 3. KD argues that the policy creates better conditions through portability 3 and that agencies themselves must manage exit strategies 3. KD considers that Sweden must cooperate within the EU to become digitally independent 4 and that regulatory simplifications are needed so that companies can grow 4. SD argues that the policy lacks concrete incentives to reduce dependence on American suppliers 5.

Written by AI in advance and may contain errors. The numbers lead to the speech a statement builds on; check against the text below.

Civilministern Erik Slottner (KD)

Madam Speaker! Rashid Farivar has asked me

if I consider that the national cloud policy should be regarded as merely advisory or as a governing document for authorities, municipalities and regions and what consequences the government sees if these principles are not followed

if I intend to act to ensure that authorities, municipalities and regions ensure that they fully understand and control contractual terms, jurisdictional issues and data access before agreements on cloud services are entered into

if I judge that the government's cloud policy will reduce Sweden's dependence on American cloud providers when the policy at the same time does not contain any requirements or steering measures that favor Swedish or European alternatives and how I intend to act based on my assessment

if I intend to act to ensure that public actors in practice shall ensure functioning exit strategies and the possibility to change supplier before agreements for cloud services are signed and before agreements are renewed with the same supplier.

It is an ambitious amount of questions and an ambitious content in these questions, perhaps I may add.

The government's cloud policy is guiding and shall be able to be used as support by the public administration in its use of cloud services.

The public actors have needs for various IT solutions, including different cloud services, to ensure cost-effectiveness, high security, and availability for their respective operations. Each actor must, in accordance with the Swedish administrative model, make independent assessments and is itself responsible for its use of cloud services.

The Government has taken several measures to facilitate the public administration in the selection of and procurement of cloud services.

According to the Ordinance (2024:1005) on coordinated and secure state IT operations, Försäkringskassan, Lantmäteriet, Skatteverket and Trafikverket shall provide IT operation services, for example cloud services, within the framework of the coordinated state service offering and support state agencies in the choice of IT operation solution.

The Government has additionally tasked the National Agency for Public Procurement to establish a forum that shall coordinate procurement support linked to IT procurement and provide an opportunity to exchange experiences.

When it comes to the issue of Sweden's dependence on American cloud providers, it is a fact that the use of digital services in Europe is characterized by a dependence on providers with residency outside the EU.

The Government assesses that the public administration's procurement of digital services needs to become more efficient and more accessible for more suppliers.

The National Property Board (Kammarkollegiet) has been tasked with carrying out a preliminary study on a so-called dynamic purchasing system for innovative digital solutions for the public administration. In the preliminary study, Kammarkollegiet shall submit proposals for measures that make it attractive for small and medium-sized enterprises to participate in the system in question. Furthermore, the agency shall analyze what types of products should be covered by such a purchasing system and, in the selection, prioritize product categories where there are many Swedish and European suppliers.

For the government, it is important that the market for cloud services is dynamic and well-functioning. The government therefore welcomes cloud services with standards and solutions that promote portability, that is, the ability to, for example, move data, functions, or services from one system to another.

A so-called exit clause, that is, a contractual term regulating how to handle a termination of a supplier agreement, is normally included in the contracting parties' agreements for various IT solutions – for example, IT operations. Examples of situations where such a term becomes relevant are when an agreement is about to expire and one, as a customer, intends to change suppliers after a new procurement, but it can also be about needing to terminate the agreement with a certain supplier for some other reason. In such a termination, one needs to move – migrate – the information that may have been stored through the supplier, and it can then be included that the supplier shall be helpful in enabling that move.

The Government has also tasked the Swedish Post and Telecom Authority, PTS, with supporting the application of the cloud policy. Within the framework of the assignment, PTS shall provide guidance to the public administration on issues regarding the balance between efficiency and security in relation to the actors' needs for cloud services for various purposes.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Rashid Farivar (SD)

Madam Speaker! Thank you, Minister for Civil Affairs Erik Slottner, for a detailed answer!

I welcome that the government has now presented a national cloud policy. It is an important step forward and does not come a day too early.

Cloud services are fundamentally something positive. They can create more efficient public operations, better digital services, and better opportunities to use artificial intelligence. But precisely because of that, it is important that we manage the risks in a responsible manner.

Madam Speaker! What perhaps most clearly emerges from the Minister's answer is that the government regards the cloud policy as a guiding document. This means in practice that every agency, municipality, and region must decide for themselves how the policy shall be applied. If the policy is not followed, it also has no direct consequences.

I must say that I am somewhat surprised by this. The government itself states in the cloud policy that issues regarding data, jurisdiction, supplier dependencies, and digital sovereignty are of strategic importance for Sweden. But when it comes to implementation, the responsibility is handed back to each individual public actor.

Madam Speaker! The problem is that it looks very different in reality. Some authorities have extensive legal and technical competence; others do not. Many smaller authorities, municipalities, and regions have limited resources to analyze complex contract structures, subcontractor chains, jurisdictional issues, and foreign legislation.

When the government itself identifies risks linked to, among other things, extraterritorial legislation, the question should be obvious: How can the government be sure that each individual agency has the ability to make these assessments on its own?

Madam Speaker! I note that the Minister refers to support from Försäkringskassan, Lantmäteriet, Skatteverket, Trafikverket, Upphandlingsmyndigheten and PTS. This is naturally positive, but support is not the same as governance. Guidance is not the same as requirements, and recommendations are not the same as compliance.

Therefore, I want to ask the Minister: If the government judges that issues of digital sovereignty, data access, and strategic dependencies are as important as described in the cloud policy, why does the government then settle for a guiding policy without requirements for compliance?

The speech at riksdagen.se, in Swedish (opens in a new tab)

Civilministern Erik Slottner (KD)

Madam Speaker! A policy is just a policy. A policy is guiding and does not become legislation.

This is the cloud policy that we announced in the digitalization strategy that the government decided on last year. There, we promised to return with a cloud policy to support agencies, municipalities, and regions in their use of various cloud services. The purpose is to increase the use of cloud services, because we believe that is good, but also that cloud service use should occur in as secure and safe a way as possible.

The legislation exists today. We have data protection legislation, and we are well aware of GDPR and the EU's data protection legislation for personal privacy. We have various secrecy legislations that mean we are not allowed to handle and share data however we please. The legislation exists, therefore, and it is up to the implementing authorities, the municipalities, and the regions to follow this legislation.

If one violates the law, it is the same as with other legislation, so it must be reported and decided in court. Depending on how the legislation looks, different types of fines or other orders can then be imposed, so there is nothing strange about that in itself. This policy is about helping exactly municipalities, authorities, and regions to implement more cloud services and at the same time do this in accordance with the legislation that exists regarding personal privacy and secrecy. That is the point of this.

As a support in the implementation of the cloud policy, we have designated the Swedish Post and Telecom Authority as a supporting and guiding authority.

I understand the question from the member, but I do not think we are actually that far apart. What I do not quite understand, however, is whether the Sweden Democrats want to make the cloud policy into law. It is not designed in that way, as the legislation is already there at the base.

This legislation currently results in a degree of uncertainty regarding how data should be handled. When, for example, can one handle and store data on a third country's data servers or in a cloud service? This now provides guidance on that to create greater security and greater safety for municipalities, regions, and authorities regarding the ability to use cloud services. We see this as very positive, and that usage can increase.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Rashid Farivar (SD)

Madam Speaker! Thank you, Minister for Civil Affairs, for the answer!

I want to continue with the question regarding digital sovereignty and Sweden's dependence on foreign cloud providers.

In the cloud policy, the government notes that both Sweden and Europe need to strengthen their digital sovereignty. It is also noted that unilateral dependencies on foreign suppliers can entail significant risks. It is an analysis that I share. It is, however, at the same time difficult to see how the government's policy will actually reduce these dependencies.

Madam Speaker! Today, the public sector's cloud usage is largely dominated by a few very large American providers – in the same way that the Riksdag's cloud services are dominated by these. The Minister himself notes that this dependency exists.

At the same time, the cloud policy contains no requirements, no steering mechanisms, and no concrete incentives to strengthen Swedish or European alternatives. I therefore find it difficult to see how the development is to change.

Madam Speaker! I also want to touch upon the issue of exit strategies. The Minister says in his answer that exit clauses are normally included in agreements for various IT solutions. This is a statement that several researchers and experts in the field question. I have, for example, asked this question regarding the Riksdag's use of cloud services. I have not received any answer regarding exit strategies.

Research shows on the contrary that many public activities lack both functioning exit strategies and contractual prerequisites to leave certain cloud services in a controlled manner.

If one does not know how to leave a service, one is practically locked in. If one is locked in, one does not have full control over one's digital future. This applies particularly when business-critical functions, large amounts of data, and central work processes are built around a specific supplier's platform.

Madam Speaker! Digital sovereignty is not about shutting out international actors. It is about ensuring that Sweden and Swedish public operations have real freedom of action to be able to choose, to be able to switch, to be able to leave and to be able to maintain control over their data and their digital assets.

My question to the Minister is therefore: How will the government ensure that public actors, municipalities and regions actually have functioning exit strategies in practice and not just in theory, when research and experiences indicate that many operations already today have great difficulty leaving their existing cloud providers?

The speech at riksdagen.se, in Swedish (opens in a new tab)

Civilministern Erik Slottner (KD)

Madam Speaker! The question of digital sovereignty is important. During my nearly four years as Civil Minister, this is an issue that has truly increased in explosive power and become increasingly relevant in the debate both within Sweden and not least at the EU level. The political developments in the USA have, of course, driven this debate in Europe, and we need to increase our digital independence.

It is not only for security policy reasons that this is important, but also for economic reasons in order to create better growth opportunities for Europe moving forward.

It is not good, and it is a proof of poverty, that Europe is so dependent on a number of American tech giants to be able to handle our data and offer us cloud services etcetera. Therefore, many initiatives are now underway, not least at the EU level, to increase Europe's digital sovereignty. Everyone understands, however, that this is not something that is done overnight, and we will continue to use American tech providers for many years to come.

We do not have a goal to get rid of them completely either, but we do want to have the best IT services and the best cloud service providers we can have. Today, many of them are American. My hope is that more of them in the future will be European and preferably Swedish.

Just a few days after the government presented its cloud policy, the EU Commission presented its Cloud and AI Development Act, where they provide some answers on how Europe can become more digitally independent. It looks very positive in principle. There, they also classify different types of data and cloud services into different risk categories in order to be able to guide users regarding what should be stored or what type of cloud services should be used for which type of activity.

Here, among other things – just as in our AI strategy – increased computing power is pointed out as being completely decisive to achieve this digital sovereignty. A number of gigafactories and AI factories are currently being established around Europe, and we know that Sweden is an attractive country to establish various data centers in. We see a series of establishments of data centers in Europe that also create conditions to handle data, obtain increased computing power, and be able to offer more of cloud service providers.

Just as I said in my response, we also give the National Agency for Public Procurement various assignments to promote good IT procurement. Among other things, one of the goals is to increase the procurement of Swedish and European companies in this area. We also have, not least, the assignment to Kammarkollegiet to develop a dynamic purchasing system. We have truly expressed that one should develop purchasing systems with product categories and select product categories within areas where we know there are many Swedish and European small and medium-sized enterprises.

We are actually doing quite a lot to strengthen digital sovereignty. With the cloud policy, we are creating better conditions for this. In the cloud policy, we also mention what we call portability, that is to say that if a service does not deliver what it has promised or we do not feel that it is as secure as we thought when we entered into an agreement, one should be able to easily retrieve these data and switch to another system instead. This is also mentioned in the cloud policy.

I want to say again that in the Swedish administrative model, it is the individual agencies, municipalities and regions that must make these decisions on their own. This also applies to the exit strategies.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Rashid Farivar (SD)

Madam Speaker! I would like to thank Minister for Civil Affairs Erik Slottner for the debate. I did not quite receive an answer regarding exit strategies, but I only intend to point out that it is a major problem.

I believe that we fundamentally share the view that cloud services will play a decisive role for the public sector's digitalization during the coming years. We likely also share the view that security, robustness, innovation, and efficiency must go hand in hand. But after today's debate, some important questions still remain.

The government itself notes that digital sovereignty needs to be strengthened. The government notes that dependencies on foreign suppliers can entail risks. The government notes that control over data, portability and exit strategies are important principles, which the Minister for Civil Affairs explained. But at the same time, the government chooses to make the cloud policy guiding rather than governing and leaves the majority of the responsibility to individual agencies, municipalities and regions. I think that is a problem.

Madam Speaker! My perception is that this risks creating a situation where the problems that are identified also become the problems that are left unsolved. Digital sovereignty does not arise through good intentions; rather, it requires practical capability, competence, follow-up, and in some cases, clearer governance. I therefore hope that the government continues the work diligently and follows the developments.

In conclusion, I would like to thank the Minister for Civil Affairs for a rewarding debate here today and for the work he has performed during the mandate period. I also want to thank him for the good cooperation we have had over the years, both in the Committee on Transport and Communications and in the Committee on Civil Affairs. I wish the Minister a happy Midsummer and a very nice summer holiday with the opportunity for rest and recovery before the election campaign that awaits.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Civilministern Erik Slottner (KD)

Madam Speaker! I thank you, and accept the thanks, for the good cooperation we have had during the parliamentary term. We shall see how relaxing and calm just this summer will be, but I also hope for a bit of winding down. I also wish member Rashid Farivar a nice Midsummer and a nice summer.

On the theme of this interpellation debate, I can only say that we definitely have more to do. It is not that we have now taken the measures that need to be taken to make Europe much more digitally independent and sovereign, but we have more to do. However, it is a work that has begun, and where the debate – and the awareness – of the seriousness that the issue carries has emerged.

Sweden cannot work on its own here, however, we must do this together in the EU. I actually see all of this primarily as a European issue. But Sweden will be an important contribution in the work of making Europe more digitally independent, because we have very good conditions in the form of many companies that could offer all the services that will make Europe more digitally independent.

We talk very much about Europe's dependence on American tech giants, but do not forget that the USA is also dependent on us. Not least when it comes to building out connectivity and 5G – as well as 6G in the future – a Swedish and a Finnish company are very important. We therefore have a mutual dependence on each other, which I think is worth being reminded of from time to time. That means that the USA actually also has a great interest in maintaining good relations with Europe, not least in this area.

Then we need to make it much more favorable for companies to invest, innovate, and not least grow in Europe through regulatory simplifications and deregulation at the European level. That is the only way we can become digitally sovereign in the long term.

The interpellations debate was hereby concluded.

The speech at riksdagen.se, in Swedish (opens in a new tab)

Source: The Swedish Parliament. The speeches come from the open data of the Riksdag, translated into English by AI, which may contain errors.