Skip to content
You can now search across every topic, entity and event.What's new
Iran Conflict 2026
3AUG

Dutch block first US cloud takeover

4 min read
15:23UTC

Dutch minister Willemijn Aerdts prohibited Kyndryl's EUR 100m purchase of Solvinity on 26 May, the first US deal ever blocked under Dutch investment screening, because the firm hosts the country's national digital-identity system.

ConflictDeveloping
Key takeaway

The Netherlands blocked a US cloud takeover with existing screening law, achieving CAIDA's aim before CAIDA exists.

Dutch minister Willemijn Aerdts prohibited Kyndryl's EUR 100m acquisition of cloud provider Solvinity on Tuesday 26 May, citing risk to the public interest 1. Kyndryl is a US-listed IT infrastructure firm spun out of IBM; Solvinity is a Dutch provider that hosts DigiD, the national digital-identity system citizens use for tax, healthcare and pensions, along with the MijnOverheid government portal. The decision is the first US deal ever blocked under the Dutch Investment Screening Bureau, the body that reviews foreign investments for national-security and public-interest risk.

The ground was the US CLOUD Act, the 2018 statute (the Clarifying Lawful Overseas Use of Data Act) that lets American authorities compel US-linked companies to disclose data held anywhere in the world. That is the precise argument underpinning CAIDA's public-sector restrictions . The Dutch competition authority ACM (the Authority for Consumers and Markets) had cleared the deal on antitrust grounds in February; investment screening ran on a separate track and reached the opposite conclusion. A Kyndryl spokesperson said the firm was "extremely disappointed" 2.

The split outcome shows two regimes testing different questions. Competition law asks whether a deal harms the market; investment screening asks whether foreign control harms the state. The CLOUD Act argument only bites on the second. While CAIDA waited for a College vote , The Hague reached for screening law it already held and reached the result the flagship regulation is still trying to mandate. The precedent is now citable by every member state, including the Berlin government using College silence to blunt the Brussels version.

Deep Analysis

In plain English

Kyndryl is an American IT company that spun out of IBM. It tried to buy Solvinity, a Dutch cloud company that runs the digital-identity system every Dutch person uses to log into government websites for their taxes, doctor and pension. The Dutch government stepped in and said no. The reason was a US law called the CLOUD Act, which lets American authorities demand access to data held by US-owned companies anywhere in the world, including in Europe. The Dutch government decided that having an American firm in control of their national ID system created too much legal risk, even though competition regulators had already approved the deal on separate grounds.

Deep Analysis
Root Causes

GDPR and the US CLOUD Act operate on different jurisdictions with no conflict-of-laws resolution between them. EU data-protection law (GDPR) governs how data may be processed in Europe; the US CLOUD Act governs what American authorities may demand from US-owned processors. These two regimes have no conflict-of-laws resolution mechanism.

A US company operating under both simultaneously cannot fully comply with both when they conflict. The Dutch screening bureau concluded that this structural irresolvability, not any misconduct by Kyndryl, made the public-interest risk unacceptable for national digital-identity infrastructure.

A secondary driver is that DigiD's architecture concentrates access to virtually all Dutch state-to-citizen interactions in a single platform. Tax, healthcare, pensions and government portals share the same credential system. Fragmentation across separate systems would reduce the blast radius of any compelled disclosure, but the Netherlands built efficiency and the current vulnerability in the same architectural choice.

What could happen next?
  • Precedent

    The ruling is the first successful use of EU member-state investment screening to block a US cloud acquisition on CLOUD Act grounds, setting a replicable template across 27 member states.

    Medium term · Assessed
  • Risk

    US trade officials may classify member-state investment screens on CLOUD Act grounds as non-tariff barriers, adding them to the Section 301 dossier already covering DMA cloud probes.

    Short term · Reported
  • Consequence

    European digital-identity infrastructure consolidation via US acquirers is now legally exposed in any member state with an investment screening mechanism modelled on the Dutch bureau.

    Long term · Assessed
First Reported In

Update #7 · Sovereignty arrives, minus Brussels

The Next Web· 3 Jun 2026
Read original
Causes and effects
This Event
Dutch block first US cloud takeover
A member state used national screening law to do what CAIDA is still waiting to legislate, proving the sovereignty tool already exists outside Brussels.
Different Perspectives
Lloyd's Market Association
Lloyd's Market Association
War-risk underwriters price the Houthis' Red Sea attacks because the group announces its targets in advance, but the unclaimed Damietta drone gives insurers a hit with no author to price against. An attack nobody claims costs shipping more than one that is claimed, since premiums are set against a known pattern, not raw damage.
US Central Command
US Central Command
CENTCOM has announced no strike on Iran since resuming bombing on 30 July within hours of an IRGC salvo on Jordan, and centcom.mil did not respond to requests to confirm any pause. The command has gone quiet before while a larger operation was being weighed, so silence alone proves nothing about what it has or has not done.
Hengaw
Hengaw
Hengaw recorded at least 67 executions in Iran during July, of which the state acknowledged only eight, and reported the 1 August execution of protest detainee Arvin Kheirkhahan at Shahrud with no advance notice to his family. A family's first notice of a death sentence is now usually the instruction to collect a body.
Egypt
Egypt
Egypt's government asked media on 2 August to report the Damietta attack accurately, named no author, and said no findings will be published before its own investigation concludes. Cairo holds the debris and jurisdiction over an attack on its own soil, and naming a culprit now would pull it into a dispute it has avoided for five months.
Iran's Foreign Ministry
Iran's Foreign Ministry
Araghchi called the Hormuz talks with Oman final-stage on 2 August, four days after his own deputy rejected Oman's lane proposal, and denied the Damietta drone strike as an Israeli false flag while two Iranian officials privately claimed it for Tehran. Iran's public position now contradicts itself on both files at once.
Bahrain and Kuwait
Bahrain and Kuwait
Bahraini and Kuwaiti aircraft flew their own strikes on Iranian depots in July with Emirati air cover behind them, and Ynetnews reports some Gulf capitals wanted the 2 August strike to proceed rather than stop. States that have already taken fire see a closing window on Iranian weakness, not a reason to pause.