Skip to content
You can now search across every topic, entity and event.What's new
Russia-Ukraine War 2026
3AUG

Dutch block first US cloud takeover

4 min read
10:16UTC

Dutch minister Willemijn Aerdts prohibited Kyndryl's EUR 100m purchase of Solvinity on 26 May, the first US deal ever blocked under Dutch investment screening, because the firm hosts the country's national digital-identity system.

ConflictDeveloping
Key takeaway

The Netherlands blocked a US cloud takeover with existing screening law, achieving CAIDA's aim before CAIDA exists.

Dutch minister Willemijn Aerdts prohibited Kyndryl's EUR 100m acquisition of cloud provider Solvinity on Tuesday 26 May, citing risk to the public interest 1. Kyndryl is a US-listed IT infrastructure firm spun out of IBM; Solvinity is a Dutch provider that hosts DigiD, the national digital-identity system citizens use for tax, healthcare and pensions, along with the MijnOverheid government portal. The decision is the first US deal ever blocked under the Dutch Investment Screening Bureau, the body that reviews foreign investments for national-security and public-interest risk.

The ground was the US CLOUD Act, the 2018 statute (the Clarifying Lawful Overseas Use of Data Act) that lets American authorities compel US-linked companies to disclose data held anywhere in the world. That is the precise argument underpinning CAIDA's public-sector restrictions . The Dutch competition authority ACM (the Authority for Consumers and Markets) had cleared the deal on antitrust grounds in February; investment screening ran on a separate track and reached the opposite conclusion. A Kyndryl spokesperson said the firm was "extremely disappointed" 2.

The split outcome shows two regimes testing different questions. Competition law asks whether a deal harms the market; investment screening asks whether foreign control harms the state. The CLOUD Act argument only bites on the second. While CAIDA waited for a College vote , The Hague reached for screening law it already held and reached the result the flagship regulation is still trying to mandate. The precedent is now citable by every member state, including the Berlin government using College silence to blunt the Brussels version.

Deep Analysis

In plain English

Kyndryl is an American IT company that spun out of IBM. It tried to buy Solvinity, a Dutch cloud company that runs the digital-identity system every Dutch person uses to log into government websites for their taxes, doctor and pension. The Dutch government stepped in and said no. The reason was a US law called the CLOUD Act, which lets American authorities demand access to data held by US-owned companies anywhere in the world, including in Europe. The Dutch government decided that having an American firm in control of their national ID system created too much legal risk, even though competition regulators had already approved the deal on separate grounds.

Deep Analysis
Root Causes

GDPR and the US CLOUD Act operate on different jurisdictions with no conflict-of-laws resolution between them. EU data-protection law (GDPR) governs how data may be processed in Europe; the US CLOUD Act governs what American authorities may demand from US-owned processors. These two regimes have no conflict-of-laws resolution mechanism.

A US company operating under both simultaneously cannot fully comply with both when they conflict. The Dutch screening bureau concluded that this structural irresolvability, not any misconduct by Kyndryl, made the public-interest risk unacceptable for national digital-identity infrastructure.

A secondary driver is that DigiD's architecture concentrates access to virtually all Dutch state-to-citizen interactions in a single platform. Tax, healthcare, pensions and government portals share the same credential system. Fragmentation across separate systems would reduce the blast radius of any compelled disclosure, but the Netherlands built efficiency and the current vulnerability in the same architectural choice.

What could happen next?
  • Precedent

    The ruling is the first successful use of EU member-state investment screening to block a US cloud acquisition on CLOUD Act grounds, setting a replicable template across 27 member states.

    Medium term · Assessed
  • Risk

    US trade officials may classify member-state investment screens on CLOUD Act grounds as non-tariff barriers, adding them to the Section 301 dossier already covering DMA cloud probes.

    Short term · Reported
  • Consequence

    European digital-identity infrastructure consolidation via US acquirers is now legally exposed in any member state with an investment screening mechanism modelled on the Dutch bureau.

    Long term · Assessed
First Reported In

Update #7 · Sovereignty arrives, minus Brussels

The Next Web· 3 Jun 2026
Read original
Causes and effects
This Event
Dutch block first US cloud takeover
A member state used national screening law to do what CAIDA is still waiting to legislate, proving the sovereignty tool already exists outside Brussels.
Different Perspectives
Belarus
Belarus
Minsk announced completion of its own 37th Separate Airborne Assault Brigade near Gomel, under plans dating to August 2025 rather than a response to any single frontline event this window, keeping its hedge of hosting the war without formally joining Russia's mobilisation drive.
European Union / Operation IRINI states
European Union / Operation IRINI states
Italy, Greece and Poland boarded the sanctioned tanker Toa Payoh off Pantelleria under a standing EU mandate rather than a national decision, extending enforcement from the Channel and Baltic and the Black Sea and Azov into the Mediterranean. Italian Defence Minister Guido Crosetto praised the crew; the captain's refusal to produce documentation left detention unconfirmed.
Poland and the NATO eastern flank
Poland and the NATO eastern flank
Warsaw's Coordination Team said explicitly its forces tracked the 30 July missile incursion and were ready to shoot it down, then flew air cover for an EU tanker interdiction three days later. Poland is simultaneously the war's nearest spillover victim and a contributor to enforcing sanctions against the state causing that spillover.
Ukraine (government, defence establishment and civilians)
Ukraine (government, defence establishment and civilians)
Kyiv runs its manpower crisis through acting Defence Minister Yevhen Khmara, whose formal appointment waits for parliament's 18 August return, and a fortnight-old Commander-in-Chief, Mykhailo Drapatyi. Reported attacks on enlistment officers rose from 5 cases in 2022 to 341 in 2025, reaching Odesa's Territorial Recruitment Centre staff directly on 2 August.
Kremlin and Russian domestic economic voices
Kremlin and Russian domestic economic voices
Moscow has not addressed July's advance-rate collapse or Sberbank's OFZ warning; Novak's diary ran to OPEC+ quota diplomacy with no diesel item logged since 15 July. Economist Nikolai Korzhenevsky calls the Central Bank's RUB 2.3tn in bank lending effectively deficit monetisation, a framing Sberbank's Skvortsov, with his own institutional interest, has not disputed.
IAEA (Rafael Grossi)
IAEA (Rafael Grossi)
IAEA inspectors logged Zaporizhzhia's 22nd loss of off-site power, ten of them in the last three months, after a thunderstorm knocked out the plant's sole surviving backup line. Grossi reads the accelerating frequency, not any single outage, as the safety signal now that the plant's redundancy is exhausted.