Your 12-year-old sends a photo to her best friend. They live three streets apart. The photo, however, most likely travels to a data centre hundreds of miles away, owned by a company that is not subject to your country's law, and that makes money from your daughter's attention.
That is what digital sovereignty is really about: not a geopolitics seminar, but the question of who is in charge inside the tools our children use every single day.
It is not (only) a question of servers
Digital sovereignty is often reduced to geography: "is my data stored in Europe?" That is a useful criterion, but a badly incomplete one. Three other questions matter at least as much.
1. Which law applies?
A company can store your data in Frankfurt and still answer to US law. The CLOUD Act, passed in the United States in 2018, allows American authorities to compel a company with a US nexus to hand over data β wherever in the world it is stored, without going through the courts of the country concerned, and without notifying the person involved. A European server operated by a US-incorporated company is therefore not, legally speaking, a European server.
2. Who pays for the service?
When an app is free for a child, someone is paying. In the advertising model, that someone is an advertiser, and what they are buying is available brain time. Every design decision that follows β notifications, endless scroll, streaks you must not break, "for you" recommendations β flows mechanically from that economic choice. Sovereignty, here, means not outsourcing the design of your child's habits to a company whose revenue depends on how long they stay on the screen.
3. Who writes the rules?
Moderation, minimum age, how a bullying report is handled, whether a photo comes down: those rules are written by the platform, applied by its staff, and changed without notice. When the platform is far away, so is the rule. Plenty of parents have discovered this while trying to get an image of their child taken down.
The real question is not "where is my data?" but "who can decide what happens to my child, and which court can I go to when it goes wrong?"
Why this is more serious when a child is involved
An adult who accepts terms and conditions is making a trade: data in exchange for a service. You may find the trade unbalanced, but it is a choice. An 11-year-old is not making that trade. They do not understand it, and above all they cannot undo it.
- Childhood data lasts a long time. A Year 7 group chat, photos, daily location history: all of it describes a person who does not quite exist yet, and who will have to live with the record.
- The GDPR grants children reinforced protection β consent, profiling and targeted advertising involving minors are all subject to specific rules. Someone still has to be in a position to enforce them.
- Dependency is built early. What is installed at 11 shapes behaviour at 16. That is precisely the window attention-based business models are aiming at.
Europe is legislating β and finding out that law alone is not enough
The last two years have been busy. A quick status report, because it explains why this will not be settled by a single statute.
In July 2025 the European Commission published guidelines for applying Article 28 of the Digital Services Act: private accounts by default for minors, adjustments to recommender systems, reduction of features that drive compulsive use, and age verification in certain cases. In April 2026 it announced that a European age-verification app β designed to let someone prove their age without handing over other personal information β was ready for rollout across the Union.
Australia went further. Since 10 December 2025, under-16s may no longer hold an account on the major platforms. Six months on, the results invite humility: a large share of the teenagers concerned kept or recreated an account by circumventing verification β and are now treated as adult users, which strips them of the few safeguards designed for minors in the first place.
In France, the law banning under-15s from social media, passed on 21 July 2026 in the wake of a parliamentary inquiry into TikTok, was struck down by the Constitutional Council on 14 August 2026. The reasoning is instructive: the ban applied indiscriminately to services whose harm to minors was not established, took no account of actual age, maturity or parental judgement, and implied that everyone, adults included, would have to prove their age to log in. The government has been told to produce a new draft by spring 2027.
Regulation is moving, but it is slow, contested and technically hard to enforce. In the meantime, the decision with the most impact is still the one made at home: which tool you put in the hands of an 11-year-old, and what for.
Four questions to ask before installing an app
You do not need to be a lawyer. These four questions are enough to sort the wheat from the chaff, and the answers are usually in the privacy policy and on the app store listing.
- Who publishes the app, and where? Look for the company name and its country. A company incorporated in Europe answers to a court you can actually petition, and to a data protection authority you can complain to for free.
- How does it make money? Subscription, in-app purchases, advertising, data resale? If the answer is advertising, the app is engineered to hold your child's attention, not to help them put the phone down.
- Which sub-processors are listed? Any serious privacy policy names them, together with the country where processing takes place. It is the single best indicator of what actually leaves the European Union.
- What happens when you want to leave? Account deletion in two taps, or an obstacle course? How easy it is to walk away tells you a great deal about how users are regarded.
So where does Capaz stand?
Capaz is published in France and falls under European law: GDPR, DSA, and a supervisory authority β France's CNIL β that you can petition free of charge. Our business model is subscription, not advertising. That is the most structural difference of all: we have no interest whatsoever in profiling your child, maximising their screen time, or recommending content to them. There is no algorithmic feed, no likes, no public comments and no endless scroll in the app β and the network is closed: children connect only with approved contacts, through an invitation code. None of that is a setting: Capaz was designed for children from the outset, whereas the large platforms were built for adults and had parental controls added long afterwards.
As for the data itself: Capaz users' data β accounts, messages, photos β is stored in Switzerland. That is not a plumbing detail. Switzerland has one of the most demanding data protection regimes anywhere, and it benefits from a European Commission adequacy decision: the level of protection there is recognised as equivalent to the GDPR.
The list of our providers, with the country of processing for each, is published in our privacy policy.
European hosting on an ad-funded app protects a child less than an app with no advertising, no algorithm and no strangers. Infrastructure matters. Incentives matter more.
For a family, digital sovereignty is not a flag on a server. It is being able to understand the rules, challenge them, and leave. The rest is marketing.
Sources
- French Constitutional Council, decision no. 2026-911 DC of 14 August 2026.
- France 24, "France's Constitutional Council strikes down the under-15 social media ban", 14 August 2026.
- Toute l'Europe, "Minors and social media: which European countries plan a minimum age?".
- Mon enfant et les Γ©crans, "Protecting children online: Europe takes action" (DSA Article 28 guidelines).
- InCyber News, "Can the European Union defend itself against the CLOUD Act?".
- CNews, "In Australia, teenagers are defeating the under-16 ban", 10 April 2026.
- Capaz, privacy policy (list of sub-processors and countries of processing).
A messaging app built for 8-14 year olds
No ads, no likes, no endless scroll, no strangers. Published in France, free to get started.
The Capaz team