Skip to content
You can now search across every topic, entity and event.What's new
European Tech Sovereignty
26JUL

Dutch block first US cloud takeover

4 min read
10:21UTC

Dutch minister Willemijn Aerdts prohibited Kyndryl's EUR 100m purchase of Solvinity on 26 May, the first US deal ever blocked under Dutch investment screening, because the firm hosts the country's national digital-identity system.

TechnologyDeveloping
Key takeaway

The Netherlands blocked a US cloud takeover with existing screening law, achieving CAIDA's aim before CAIDA exists.

Dutch minister Willemijn Aerdts prohibited Kyndryl's EUR 100m acquisition of cloud provider Solvinity on Tuesday 26 May, citing risk to the public interest 1. Kyndryl is a US-listed IT infrastructure firm spun out of IBM; Solvinity is a Dutch provider that hosts DigiD, the national digital-identity system citizens use for tax, healthcare and pensions, along with the MijnOverheid government portal. The decision is the first US deal ever blocked under the Dutch Investment Screening Bureau, the body that reviews foreign investments for national-security and public-interest risk.

The ground was the US CLOUD Act, the 2018 statute (the Clarifying Lawful Overseas Use of Data Act) that lets American authorities compel US-linked companies to disclose data held anywhere in the world. That is the precise argument underpinning CAIDA's public-sector restrictions . The Dutch competition authority ACM (the Authority for Consumers and Markets) had cleared the deal on antitrust grounds in February; investment screening ran on a separate track and reached the opposite conclusion. A Kyndryl spokesperson said the firm was "extremely disappointed" 2.

The split outcome shows two regimes testing different questions. Competition law asks whether a deal harms the market; investment screening asks whether foreign control harms the state. The CLOUD Act argument only bites on the second. While CAIDA waited for a College vote , The Hague reached for screening law it already held and reached the result the flagship regulation is still trying to mandate. The precedent is now citable by every member state, including the Berlin government using College silence to blunt the Brussels version.

Deep Analysis

In plain English

Kyndryl is an American IT company that spun out of IBM. It tried to buy Solvinity, a Dutch cloud company that runs the digital-identity system every Dutch person uses to log into government websites for their taxes, doctor and pension. The Dutch government stepped in and said no. The reason was a US law called the CLOUD Act, which lets American authorities demand access to data held by US-owned companies anywhere in the world, including in Europe. The Dutch government decided that having an American firm in control of their national ID system created too much legal risk, even though competition regulators had already approved the deal on separate grounds.

Deep Analysis
Root Causes

GDPR and the US CLOUD Act operate on different jurisdictions with no conflict-of-laws resolution between them. EU data-protection law (GDPR) governs how data may be processed in Europe; the US CLOUD Act governs what American authorities may demand from US-owned processors. These two regimes have no conflict-of-laws resolution mechanism.

A US company operating under both simultaneously cannot fully comply with both when they conflict. The Dutch screening bureau concluded that this structural irresolvability, not any misconduct by Kyndryl, made the public-interest risk unacceptable for national digital-identity infrastructure.

A secondary driver is that DigiD's architecture concentrates access to virtually all Dutch state-to-citizen interactions in a single platform. Tax, healthcare, pensions and government portals share the same credential system. Fragmentation across separate systems would reduce the blast radius of any compelled disclosure, but the Netherlands built efficiency and the current vulnerability in the same architectural choice.

What could happen next?
  • Precedent

    The ruling is the first successful use of EU member-state investment screening to block a US cloud acquisition on CLOUD Act grounds, setting a replicable template across 27 member states.

    Medium term · Assessed
  • Risk

    US trade officials may classify member-state investment screens on CLOUD Act grounds as non-tariff barriers, adding them to the Section 301 dossier already covering DMA cloud probes.

    Short term · Reported
  • Consequence

    European digital-identity infrastructure consolidation via US acquirers is now legally exposed in any member state with an investment screening mechanism modelled on the Dutch bureau.

    Long term · Assessed
First Reported In

Update #7 · Sovereignty arrives, minus Brussels

The Next Web· 3 Jun 2026
Read original
Causes and effects
This Event
Dutch block first US cloud takeover
A member state used national screening law to do what CAIDA is still waiting to legislate, proving the sovereignty tool already exists outside Brussels.
Different Perspectives
China's Ministry of Commerce
China's Ministry of Commerce
Spokesperson He Yadong said on 16 July that Beijing and the Netherlands should let firms settle the Nexperia dispute through consultation, after a Dutch ministerial visit to Beijing. The conciliatory tone contrasts with the confrontational US trade response to the same fortnight's DMA enforcement.
Samsung Electronics
Samsung Electronics
Samsung entered talks reported 22 July to invest up to €1 billion in Mistral AI, part of a round valuing the French lab at roughly €20 billion alongside EQT, Novo Holdings and Santander. The Korean conglomerate, not an EU financing instrument, is positioned to anchor Europe's flagship AI lab.
Poland (Tusk government)
Poland (Tusk government)
Donald Tusk's government proposed a mandatory sovereignty test on 21 July for state technology contracts above 5 million zloty, scoring bids on AI model-weight rights and vendor lock-in rather than waiting for an EU-wide procurement rule. The threshold targets a 20-30 per cent domestic-alternative share.
United States administration
United States administration
Donald Trump ordered a Section 301 investigation into EU digital-enforcement practices on 24 July, a day after USTR's Jamieson Greer said the Google fine created massive uncertainty for US exports, noting Google's cumulative EU fines already exceed 2 per cent of the bloc's budget.
Ecosia
Ecosia
Ecosia said the 16 July FRAND ranking-data order would take it from answering two-thirds of queries to all of them once the obligation activates in January 2027. The Berlin-based challenger has not called the enforcement package adequate, only workable if Google complies rather than appeals.
European Commission
European Commission
Teresa Ribera and Henna Virkkunen announced the €890m fine on 23 July, saying products should succeed on merit, not platform ownership; four days earlier a separate Article 6(7) order compelled Android interoperability. The Commission expects both to hold on appeal after the Court of Justice upheld its earlier €4.1bn Android fine on 2 July.