14 November 2025

Why the acquisition of Solvinity should be a wake-up call for the Netherlands and Europe

Society

The acquisition of Solvinity by Kyndryl raises concerns across Dutch public institutions and exposes how dependent essential government services have become on foreign infrastructure providers.

Solvinity has announced that it will be acquired by Kyndryl Netherlands, part of the US-based Kyndryl, which was separated from IBM in 2021 as an independent infrastructure company. Solvinity provides secure cloud and infrastructure services to multiple Dutch public institutions. Core systems such as DigiD, MijnOverheid and Digipoort rely on its infrastructure, as do parts of the IT environment of the Ministry of Justice and Security. The proposed acquisition still requires approval from the Dutch Authority for Consumers and Markets, yet the implications already extend far beyond a single supplier relationship.

Within ministries, implementing agencies and municipalities, the announcement has caused considerable concern. Solvinity has long been valued as a provider familiar with public-sector requirements: strong security, high availability and compliance with Dutch and European legal standards. Many civil servants and officials were taken by surprise that this infrastructure will now fall under American ownership, even though Solvinity had been on the market for some time. Parliamentary questions have been submitted, and municipalities such as Amsterdam are examining how the acquisition aligns with their goal of reducing reliance on US technology providers.

Much of the public debate still focuses on operational details: contractual terms, transition timelines and existing safeguards. These issues matter, but they address only the surface. Beneath them lies a more structural shift: a critical layer of the Dutch digital state is moving outside direct Dutch and European influence.

A shift in control

The core concern is not the physical location of servers but the legal framework that governs access. As an American company, Kyndryl is subject to US law. Under the CLOUD Act, US authorities can compel providers to hand over data under their control, even if that data is stored abroad. This principle applies broadly to US service providers and has long been central to debates about European digital sovereignty.

This does not imply immediate misuse of data, nor does it question Kyndryl’s security practices. It means that strategic access to sensitive systems and information becomes partly governed by legal regimes outside Dutch control. At a time when cloud services and identity systems are increasingly classified as critical infrastructure, this introduces a form of long-term strategic vulnerability.

Digital sovereignty starts with foundational layers

Europe has invested heavily in regulations such as the GDPR, DSA, DMA, the Data Act and the AI Act to protect citizens and strengthen public values. Yet the infrastructural base that supports these ambitions is increasingly operated by large international providers, often headquartered in the United States.

The sale of Solvinity fits within this trend. Other Dutch IT companies serving public-sector needs have already been acquired by non-European firms, reinforcing dependence on external providers. This makes it harder for governments to rely on vendors operating fully within European legal protections and governance structures.

Beyond access to data, ownership shapes the future direction of platforms: investment choices, security priorities, incident response and design principles. When these decisions are made outside Europe, aligning infrastructure with public values becomes more difficult.

Implications for resilience and democratic institutions

The systems that power DigiD, MijnOverheid and Digipoort form the digital backbone of Dutch public administration. When that backbone becomes more dependent on foreign jurisdictions, risks shift as well. Geopolitical tensions, unexpected legal demands or commercial decisions abroad may directly affect the availability or security of essential services.

This has implications for democratic resilience. Public institutions need the ability to set conditions for security, access, logging and accountability. When those conditions become influenced by external legal systems and corporate governance structures, the capacity to safeguard public interests diminishes. The vulnerability lies not in a single event but in the slow accumulation of dependencies.

In this context, the Solvinity acquisition is more than a business transaction. It highlights how limited the margin has become for keeping critical infrastructure under European control. For anyone working on digital security, public administration or the protection of democratic institutions, the acquisition underscores a broader question: how should Europe organise the foundations of its digital future?

Author: Roemer Wage

Read also

€ 28 Million for AI Start-up in Amsterdam Aiming to Develop Climate Transition Materials

20 June 2024

Call for Nominations Amsterdam AI Thesis Awards is Now Open

8 August 2024

VU experts call for an independent AI Council in the new coalition agreement

2 February 2026

Subscribe to our newsletter

Would you like to stay informed about what is happening within the Amsterdam AI ecosystem?