Verdict
Move the compute. Keep what you actually need from PaaS.
For most teams the right play is not "leave DigitalOcean entirely". It is to recognise that a droplet is a fungible resource — there is no good privacy reason to keep it on a US identity-bound platform when the same shape of compute is available KYC-free at a lower per-spec price under constitutional Nordic protection.
Move the compute. If you depend on Managed Postgres, Spaces or App Platform, keep those on DigitalOcean for now — there is no managed-services equivalent on NordBastion, by doctrine. As your stack moves from “PaaS-everywhere” to “infrastructure-I-own”, the bridge shortens; some teams complete the move in a quarter, others run a hybrid indefinitely.
NordBastion will not be everything DigitalOcean is. It will be a faster, cheaper, KYC-free droplet pinned in one of four Nordic legal regimes with a published canary, and that is exactly the part you came here for.