The Netherlands recently blocked Kyndryl’s planned acquisition of Solvinity, a Dutch cloud provider tied to the country’s national digital identity system. The decision shows how cloud sovereignty concerns are moving into enterprise technology dealmaking when digital identity systems and foreign government access to data are involved.
Kyndryl, the IT infrastructure services company spun out of IBM, announced last November that it would acquire Solvinity in a deal valued at about 100 million euros, or roughly $113 million, according to Reuters. Kyndryl said at the time that the transaction would expand its secure managed cloud services in the Netherlands and add Solvinity’s sovereign cloud capabilities for customers with sensitive and complex workloads. But Solvinity’s role in Dutch public IT made the deal more than just a routine cloud services acquisition. The company provides the underlying technology for DigiD, the Netherlands’ national digital identity system, which residents use to access taxes, health care records, benefits, pension information, education records and other government services.
Solvinity processes the email and IP addresses associated with DigiD accounts, while more sensitive account data is protected through encryption and is not normally accessible to Solvinity employees. But the Dutch concern was not staff access to citizen records. It was whether control of infrastructure tied to critical public services should move to a company subject to U.S. jurisdiction. The Dutch government blocked the transaction on May 26 after an investment screening review. Reuters reported that it was the first U.S. acquisition blocked by the Dutch Investment Screening Bureau.
The New York Times reviewed a confidential judgment in the case, reporting that Dutch regulators were concerned U.S. authorities could compel Kyndryl to provide information handled by Solvinity for government services. The judgment cited the CLOUD Act, a U.S. law that allows the feds to seek data from American technology companies, including in some cases when the information is stored outside the United States, according to the Times.
The blocked deal echoes a larger European campaign to reduce dependence on foreign technology providers in sensitive parts of the digital economy. The EU recently outlined a technology sovereignty package that would expand regional cloud, semiconductor and data center capacity, while potentially limiting non-European cloud providers from contracts involving sensitive government work and public data. European Commission President Ursula von der Leyen said the plan is meant to reduce Europe’s reliance on outside providers for technologies that support critical services, including hospitals, energy grids and public systems.
Dutch officials said the Solvinity decision was specific to the company’s role in the national identity system and should not be viewed as a blanket rejection of U.S. tech companies. Still, the case shows how sovereignty concerns are now moving from policy debates into actual infrastructure deals. Kyndryl pushed back after the decision, saying the process had become politicized and had overshadowed what the company described as the transaction’s clear benefits.
For governments evaluating cloud and managed infrastructure, it is no longer enough to ask where data is stored or whether it is encrypted. The Solvinity case highlights how officials are also asking who owns the provider, which country’s laws apply, whether a foreign government could demand information and how critical public services would keep running if access were disrupted. Those concerns will likely continue to shape how governments scrutinize the tech firms competing for public-sector and regulated enterprise work, especially when identity systems or other critical infrastructure are involved.

