Dutch court reviews blocked DigiD takeover

The Dutch state petrifies its digital borders as ownership of infrastructure becomes law.
Image composition · tobriefEvery time a Dutch citizen files taxes online, checks a government benefit, or logs into a public service, they pass through DigiD, the country's national authentication system. Most people never think about what sits underneath it. They probably should.
A private company called Solvinity runs the platform on which DigiD operates (AG Connect). When US-headquartered IT firm Kyndryl tried to buy Solvinity, the Dutch government blocked the deal on national-security grounds. In June, Solvinity challenged that decision in a Rotterdam court. Part of the hearing took place behind closed doors (Tweakers). The case turns a phrase politicians love, "digital sovereignty," into a concrete legal fight over who gets to own the companies that keep government running online.
The control room behind the grid
Think of digital government services like a public power grid. The state sets the rules and puts its name on the interface. But a private contractor often holds the keys to the control room: the maintenance manuals, the encryption keys, the operational knowledge needed to keep things running under stress (policyreview.info). Solvinity was that contractor for part of the Dutch digital state.
On 26 May 2026, State Secretary Willemijn Aerdts formally blocked the takeover (Logius). The detailed risk assessment has not been fully disclosed. Parliament received confidential information, and the court hearing included a closed segment where both sides discussed sensitive material away from journalists (Tweede Kamer).
What is public: members of parliament raised fears that US ownership could allow Washington to request data or, in a worst case, disrupt access to services citizens depend on daily (NOS). The US CLOUD Act featured prominently in that debate.
The CLOUD Act is real, but the public conversation risks inflating it. US law requires a provider under American jurisdiction to hand over data in its "possession, custody, or control" when served with a lawful order, even if that data is stored in Europe (Cornell LII). That is a genuine legal exposure. What the law does not do is give Washington a remote switch to browse systems or shut down a service on command. The broader fear of a "kill switch" belongs in a different category: dependency risk, contract disputes, loss of admin access, or the sheer difficulty of replacing a supplier during a crisis. Those risks are serious. They are also different from the CLOUD Act itself. Conflating them weakens the argument by making it sound conspiratorial rather than structural.
The structural point is strong enough on its own. When "the data stays in Europe" becomes the reassurance, it answers the wrong question. Data location is one layer. Control is the deeper layer: who can administer systems, push updates, and keep the service alive if the commercial relationship breaks down.
Three countries, three approaches
France has tried to make sovereignty boring and enforceable. If a cloud provider wants sensitive state work, it must earn a certification called SecNumCloud, which requires proving that foreign laws cannot easily reach the service (Alliancy). That turns a political slogan into a procurement filter: you either qualify or you don't bid.
Sweden takes a different path. Rather than screening every vendor, it makes sure the state controls the root of identity. The Justice Ministry has proposed a new state-issued ID card with biometrics and built-in electronic identification (Dagens.se), and Sweden has led work on the certification system for the EU's upcoming digital identity wallet (Digg). Private companies can handle the plumbing, but the state keeps the master key.
The Netherlands, by contrast, looks more reactive. Dutch parliamentary documents show broader thinking about sovereign cloud services (1848.nl), but the Solvinity case is a specific deal blocked after a confidential risk assessment, now defended in court.
What the court will actually decide
The EU is not trying to build a separate internet. It is building tools that let governments question takeovers, demand cybersecurity safeguards and make cloud suppliers easier to replace. Foreign-investment screening lets member states review acquisitions in sensitive sectors (Paul Weiss). The NIS2 directive adds security and supply-chain duties for critical infrastructure operators (European Commission). The Data Act addresses switching between cloud providers and protections against unlawful foreign data requests (EUR-Lex). None of these alone solves the problem. Together, they shift the question from "where is the server?" to "who governs the dependency?"
The Rotterdam case will sharpen that question. If the government prevails, it strengthens the principle that ownership changes in public digital infrastructure can be blocked even when the full risk analysis stays classified. If Solvinity wins, it may force the state to prove it considered less drastic options: contractual controls, separating sensitive operations from the foreign parent, mandatory exit plans. The court will decide how much evidence a state must show when it blocks a takeover to protect a service citizens cannot realistically opt out of. For the millions of people who log in to DigiD without a second thought, that is the question that matters.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 7/7/2026, 3:10:01 AM
- Pipeline run:
- eu_pipeline_20260707_005006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication