When a European company switches on a Datadog account to monitor its infrastructure, it isn't just subscribing to a metrics dashboard — it is continuously streaming detailed telemetry about its servers, network traffic and security architecture to data centres operated by a NASDAQ-listed American corporation. That telemetry — which ports are open, which services are running, where configuration vulnerabilities sit — is, in practice, a map of the organisation's attack surface. Datadog today processes metrics for more than 30,000 customers worldwide, and a substantial share of that data transits or rests on infrastructure subject to US law, including the 2018 CLOUD Act, which lets American authorities compel access to data held by US companies regardless of where the servers physically sit.
In most product categories Democratic Market covers, democratic origin is measured by where a physical object is manufactured. For observability software the question is different but equally material: under which legal jurisdiction does the vendor processing your infrastructure metrics actually live, and how much control do you retain if that vendor stops being trustworthy? Monitoring data is neither anonymous nor trivial — it exposes a network's internal topology, an organisation's traffic patterns and, not infrequently, credentials or tokens accidentally leaked into logs. A security incident at the monitoring vendor itself indirectly compromises every one of its customers.
Origin and Software Governance
Datadog was founded in 2010 in New York by two French engineers, Olivier Pomel and Alexis Lê-Quôc, but since its 2019 IPO it has operated as a fully American corporation, legally headquartered in New York and listed on NASDAQ under the ticker DDOG. The United States scores 7.85 on the EIU Democracy Index — an unambiguous full democracy. The issue isn't the country's democratic quality; it's its legal framework for data access. The CLOUD Act compels US companies to hand over requested information even when the servers sit in Europe, a direct collision with GDPR that Brussels has spent a decade trying to resolve through adequacy frameworks that European courts keep striking down.
Prometheus was born in 2012 in SoundCloud's Berlin offices, where engineers Matt T. Proud and Julius Volz needed a monitoring tool that didn't depend on a third party. In 2016 it became the second project — after Kubernetes — hosted by the Cloud Native Computing Foundation, the non-profit that governs the cloud-native ecosystem under the Apache 2.0 licence. Unlike Datadog, Prometheus isn't a company: it's free software that any organisation can install, modify and host wherever it decides. That trait removes the jurisdiction question entirely, because the decision of where the data lives sits with whoever deploys it, not with an external vendor.
The Best Democratically Sourced Options
Prometheus's advantage isn't purely technical — it's structural. Because it's self-hostable, a German company can run it on a Hetzner data centre in Nuremberg (Germany, 8.58) or an OVHcloud facility in Strasbourg (France, 7.99), guaranteeing its infrastructure metrics never leave the European Union. That makes Prometheus the lower geopolitical-risk option of the two: there is no corporate third party that can be legally compelled to hand over the data, because no such third party exists in the equation.
Grafana, the visualisation layer that almost always sits alongside Prometheus in production, reinforces this logic. Grafana Labs was founded by Swedish engineer Torkel Ödegaard and maintains an open-source model with dual headquarters in Stockholm (Sweden, 9.39) and New York. Prometheus plus Grafana, deployed on European infrastructure, is today the observability stack with the strongest democratic profile available to any technical team capable of self-hosting, without sacrificing maturity or community: both projects are past a decade of active development with thousands of contributors.
Adoption figures back this up: CNCF's own annual survey consistently finds Prometheus in use across roughly 80% of Kubernetes-based cloud-native deployments worldwide, making it the de facto standard rather than a niche alternative. That scale matters for a democratic-origin recommendation, because it means choosing Prometheus isn't a trade-off against maturity or hiring pool — European engineers with Prometheus experience are as easy to find as those with Datadog experience, removing the usual objection that sovereign choices come at a talent-availability cost.
The ecosystem is rounded out by OpenTelemetry, the open instrumentation standard also governed by the CNCF, which by 2026 has become the de facto format for exporting metrics, traces and logs from any application. By instrumenting code with OpenTelemetry instead of Datadog's proprietary agent, an organisation keeps the freedom to send that data to Prometheus, to a European commercial backend such as Finland's Aiven, or to Datadog itself if it ever chooses to, without rewriting instrumentation code. That format neutrality is, in itself, a form of technological sovereignty: it avoids getting locked into a single vendor's proprietary ecosystem.
Datadog's Real Risk: Jurisdiction, Not Authoritarianism
It's worth being precise here: Datadog doesn't pose a democratic risk in the sense that, say, a component manufactured under forced labour in Xinjiang does. The United States is a consolidated democracy. Datadog's risk is of a different, subtler kind: the combination of the CLOUD Act, Section 702 of FISA (which permits surveillance of foreign communications through US providers) and the uncertain status of the EU-US adequacy framework after the Court of Justice of the EU's Schrems I and Schrems II rulings creates a legal grey zone in which European data processed by American companies can end up accessible to intelligence agencies without the same judicial oversight that would exist inside the EU.
The Court of Justice of the European Union struck down Safe Harbor in 2015 and its successor, Privacy Shield, in 2020, precisely because it found US surveillance law didn't offer protections equivalent to Europe's. The current EU-US Data Privacy Framework, in force since 2023, has already been challenged before the same court by activists including Max Schrems, and much of the data-protection expert community considers a third invalidation — a hypothetical 'Schrems III' — plausible within the next few years. Any European organisation relying on Datadog to monitor critical infrastructure should treat that track record as a sign of medium-term legal instability, not a distant hypothetical.
For a startup that just wants a nice-looking dashboard, this might read as an irrelevant nuance. For a hospital, an energy grid operator or a European public administration, it isn't: the NIS2 Directive, in force since October 2024, requires thousands of essential and important entities across the EU to assess exactly this kind of digital supply-chain risk before contracting providers that monitor their critical systems.
Technical and Democratic Comparison
On raw capability, Datadog offers a SaaS platform ready to use within minutes, with more than 700 native integrations, machine-learning-driven smart alerting, and a per-host pricing model that can exceed $15-23 per host per month on its Pro plan, scaling quickly across large fleets. Prometheus, by contrast, requires the team itself to deploy, scale and maintain the metrics server, which means a steeper learning curve and in-house engineering cost — but no recurring licence fee: the software is free, and the only expense is the infrastructure hosting it.
Cost is a decisive factor in this comparison. A mid-sized infrastructure with around 50 intensively monitored servers can generate Datadog bills of $15,000 to $30,000 a year in the infrastructure module alone, before APM, logs or network monitoring, which are billed separately. The same infrastructure on a self-hosted Prometheus stack on a European provider can cost €200-600 a month in dedicated servers, plus initial deployment engineering time. Over the medium term, cost savings and data sovereignty tend to point in the same direction.
From a democratic standpoint, the difference is stark. Datadog centralises control in a single American corporation subject to extraterritorial legislation; Prometheus distributes that control to whichever organisation deploys it, wherever it sits. For small teams without the capacity to run their own infrastructure, Datadog remains a reasonably functional short-term option, provided it's paired with encryption in transit and at rest and a clear policy on what data actually gets sent. For organisations with strict regulatory obligations — banking, healthcare, the public sector — the technical comparison takes a back seat to data sovereignty.
Applicable EU Legislation in 2026
The European regulatory framework relevant to monitoring software has tightened noticeably. The NIS2 Directive extends cybersecurity obligations to sectors including energy, transport, banking, healthcare and public administration, requiring an assessment of third-party provider risk, including observability tools that hold privileged access to infrastructure. The EU Data Act, applicable since September 2025, requires cloud service providers to enable portability and easier switching, reducing the vendor lock-in that has tied European companies to American platforms for years.
In parallel, the European Cybersecurity Certification Scheme for Cloud Services (EUCS) is still being debated in Brussels, aiming to introduce a 'high+' certification level that would require immunity from foreign data-access legislation — a measure that, in its strictest form, would exclude providers like Datadog unless they operate through legally independent EU entities. While the EUCS's final shape remains unsettled in 2026, the regulatory direction is clear: Europe is moving toward requiring verifiable data sovereignty in critical infrastructure, not just encryption.
Democratic Market's Methodology for Software
To evaluate software tools, Democratic Market applies the same principles it uses for physical products, adapted to the digital context: we verify the parent company's legal domicile and stock listing, the country where data centres reside by default, whether the code is open source and therefore auditable and self-hostable, and the ownership structure when the company is private. When software is open source, we place particular weight on the ability to deploy it on European infrastructure, because that shifts the data-sovereignty decision to the user rather than leaving it with a foreign vendor.
Buying Guide: How to Choose
If your organisation handles European citizens' personal data, health information or critical infrastructure, prioritise self-hosted Prometheus on a European cloud provider such as Hetzner, OVHcloud, Scaleway or Switzerland's Infomaniak (9.15), paired with Grafana for visualisation. Budget engineering time to deploy it: one to three weeks for a team with Kubernetes experience.
If you're a small startup without a dedicated platform team and need operational monitoring today, Datadog remains a viable short-term option, but it demands diligence: review the Data Processing Addendum, enable end-to-end encryption, limit the data sent to what's strictly necessary, and have a migration plan toward a European alternative as your team grows. This isn't an all-or-nothing decision — you can start with Datadog for your first months and migrate to a self-hosted Prometheus stack once your engineering team can support it.
A third path, increasingly common among mid-sized European companies, is the hybrid approach: run self-hosted Prometheus and Grafana for the most sensitive infrastructure metrics — databases holding personal data, payment systems, internal networks — and reserve a commercial tool like Datadog only for non-critical public-facing services where speed of implementation matters more than data sovereignty. This sensitivity-based segmentation, rather than an all-or-nothing call, is what Democratic Market recommends to organisations with limited engineering resources.
Conclusion: Observability With Sovereignty
Monitoring infrastructure is, by 2026, as critical a function for an organisation as accounting or the physical security of its offices. Delegating that function to a foreign vendor subject to extraterritorial legislation isn't a neutral decision — it has real implications for who can, ultimately, access the data describing how your company works on the inside. Prometheus, born in Berlin and governed by a non-profit foundation, offers the stronger democratic profile whenever your organisation has the capacity to self-host it. Datadog is a technically excellent tool built by an American company subject to a legal framework Europe has spent a decade trying to work around. Democratic Market's recommendation is clear: if you can absorb the learning curve, choose sovereignty over convenience.
This article was originally published at Democratic Market. Read the full version with additional analysis on our site.












