Dutch Court Weighs DigiD Takeover

The Dutch state petrifies its digital borders as ownership of infrastructure becomes law.
Cumadóireacht íomhá · tobriefEvery time someone in the Netherlands files a tax return online, checks a benefit payment or logs into a public service, they pass through DigiD, the Dutch national identity system. Like most infrastructure that works, it disappears into the background. That is precisely why the row now before a Rotterdam court matters.
DigiD itself is a public service. The platform beneath it, however, is operated by Solvinity, a private company (AG Connect). When Kyndryl, the US-headquartered IT group, moved to buy Solvinity, the Dutch government blocked the deal on national-security grounds. Solvinity challenged that decision in June, and part of the court hearing was held behind closed doors (Tweakers).
The phrase around all this is "digital sovereignty", a term that can sound like Brussels conference language until it lands in a courtroom. The real question is plainer: who is allowed to own the companies that keep the state functioning online?
The control room behind the grid
Digital government works a little like the electricity grid. The state sets the rules, puts its crest on the front door and tells citizens where to log in. But a contractor may hold much of the operational knowledge: the manuals, encryption arrangements, maintenance routines and emergency access needed to keep the system running under pressure (policyreview.info). For part of the Dutch digital state, Solvinity sits in that control room.
On 26 May 2026, State Secretary Willemijn Aerdts formally blocked the takeover (Logius). The full risk assessment has not been published. Parliament received confidential material, and the court held a closed session in which both sides discussed sensitive evidence away from the press (Tweede Kamer).
What is known is that Dutch MPs raised concerns about US ownership. They feared Washington could seek access to data, or in an extreme scenario, that citizens could lose access to services they use every day (NOS). The US CLOUD Act became central to that debate.
The CLOUD Act is not imaginary. It requires a provider under US jurisdiction to hand over data in its "possession, custody, or control" when served with a lawful order, even where that data is stored in Europe (Cornell LII). That is a real legal exposure.
But it is not a magic switch that lets Washington browse through European systems or shut down a public service at will. The fear of a "kill switch" belongs to another set of risks: dependence on a supplier, contract breakdown, loss of administrator access, or the difficulty of replacing a contractor in a crisis. Those risks are serious enough without being blurred into the CLOUD Act. If the argument is made too dramatically, it becomes easier to dismiss.
The stronger point is structural. Saying that "the data stays in Europe" answers only part of the problem. Location matters, but control matters more: who can administer the system, deploy updates, recover it after a failure and keep it alive if the commercial relationship turns sour?
Three countries, three approaches
France has tried to make digital sovereignty into a procurement rule rather than a slogan. A cloud provider seeking sensitive state work must obtain SecNumCloud certification, which requires proof that foreign laws cannot easily reach the service (Alliancy). In practice, that turns sovereignty into a filter: qualify, or do not bid.
Sweden has taken a different route. Instead of screening each vendor in the same way, it is trying to ensure the state controls the root of identity. The Justice Ministry has proposed a new state-issued ID card with biometrics and built-in electronic identification (Dagens.se), while Sweden has led work on the certification system for the EU's coming digital identity wallet (Digg). Private firms can still manage parts of the plumbing, but the master key remains with the state.
The Dutch approach looks more reactive. Parliamentary papers show wider thinking about sovereign cloud services (1848.nl), but the Solvinity dispute is a concrete takeover blocked after a confidential risk assessment and now being defended in court.
What the court will actually decide
The EU is not trying to build a separate internet. It is building a set of legal tools that allow governments to scrutinise takeovers, impose cybersecurity obligations and make cloud suppliers easier to replace. Foreign-investment screening lets member states review acquisitions in sensitive sectors (Paul Weiss). The NIS2 directive adds security and supply-chain duties for critical infrastructure operators (European Commission). The Data Act deals with switching between cloud providers and protection against unlawful foreign data requests (EUR-Lex).
None of these instruments solves the issue on its own. Together, they move the debate away from the old question of where the server sits and towards the harder one of who governs the dependency.
That question will matter in Ireland too. A state that has put tax, welfare, health and business services online cannot treat the companies behind those systems as ordinary suppliers. We know, from the corporate tax debate and from the border after Brexit, that legal control and practical dependence are not always the same thing.
If the Dutch government wins, it will strengthen the principle that changes of ownership in public digital infrastructure can be blocked even where the full security case remains classified. If Solvinity wins, the state may have to show it considered less drastic options: tighter contractual controls, separating sensitive operations from the foreign parent, or mandatory exit plans.
The court is being asked how much evidence a government must reveal when it blocks a takeover to protect a service citizens cannot realistically avoid. For the millions of Dutch people who log into DigiD without thinking about it, that is the point of the case.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 7/7/2026, 3:10:01 AM
- Pipeline run:
- eu_pipeline_20260707_005006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication