Dutch Government Restricts Public Cloud Use to Safeguard National Data
The Hague, Saturday 4 July 2026
To bolster digital sovereignty, the Dutch government has banned hosting citizen registries and emails in public clouds, forcing departments to reduce reliance on non-European tech giants.
A Strategic Shift Towards Digital Autonomy
On Friday, 3 July 2026, the Dutch cabinet announced a significant tightening of its Government Cloud Policy (Rijkscloudbeleid) [1][2]. This strategic intervention aims to bolster the digital sovereignty of the Dutch public sector while mitigating geopolitical risks and reducing reliance on non-European tech conglomerates [1][3]. Under the updated guidelines, national government organisations are now mandated to conduct rigorous risk assessments and formulate a comprehensive cloud strategy prior to procuring any public cloud services [1][2].
This preliminary cloud strategy requires government bodies to explicitly justify their choice of public cloud infrastructure, identify potential security risks, and detail clear mitigation protocols [2]. For critical cloud services, the policy introduces a mandatory exit plan [2]. This ensures that if a service provider experiences a major failure or geopolitical disruption, the public sector can maintain operational continuity by switching to an alternative vendor or transitioning the service to an in-house model [2].
Safeguarding National Interests and Core Registries
Under the revised framework, the Dutch government has designated e-mail and document services as assets of national interest, strongly discouraging departments from hosting them within the public cloud [1][2][3]. Crucially, the policy prohibits the management of primary registry data in public clouds [1][2]. This ban directly applies to core national registries, including the Personal Records Database (Basisregistratie Personen or BRP) and the Land Registry (Basisregistratie Kadaster or BRK), ensuring these highly sensitive datasets remain secure and accessible under direct sovereign control [1][2].
Stricter rules are also imposed on critical government entities, including ministries and independent administrative bodies (ZBOs) [3]. For these organisations, the use of cloud providers subject to legislation outside of the European Union (EU) or the European Economic Area (EEA) is strongly discouraged for core operational tasks [1][3]. Willemijn Aerdts, the State Secretary for Digital Economy and Sovereignty, emphasised that digital sovereignty is about maintaining the autonomy to choose providers, control data access, and guarantee service availability even under challenging geopolitical circumstances [1][2][4].
Implementation Timelines and Market Implications
National government organisations have been allocated a four-year transition period to align their existing services with the new standards, establishing a compliance deadline of 3 July 2030, which is calculated as 2030 [1][2]. While the policy applies to almost all national public bodies, exceptions are granted to the Ministry of Defence and the High Councils of State, such as the Eerste and Tweede Kamer [1][2]. Furthermore, extensions to the transition timeline may be permitted in highly complex scenarios to prevent premature divestments, excessive costs, or critical operational disruptions [1][2].
Looking forward, State Secretary Aerdts plans to initiate collaborative discussions with sub-national authorities to expand these guidelines into a unified, government-wide cloud policy [1][2]. This regulatory shift is expected to have a profound impact on the broader digital economy, particularly within B2B SaaS, cybersecurity, and fintech sectors [GPT]. By restricting the use of non-European public clouds, the Dutch government is driving a surge in demand for local, secure, and fully compliant European sovereign cloud solutions, accelerating the digital transformation of legacy public-sector software systems [GPT].