Why Dutch Vifo Analysis Should Move Earlier in the Deal Cycle
Category: InsightsWhy Vifo analysis, ownership-chain review and FDI conditionality should move to the start of the Dutch deal process
The Council of the European Union formally adopted the revised EU Foreign Direct Investment Screening Regulation on 8 June 2026. The new framework is designed to make investment screening more consistent across the EU, require all Member States to maintain screening mechanisms and expand the common minimum scope for review in sensitive sectors.
For US and UK buyers of Dutch technology companies, this is not just a Brussels regulatory update. It is a deal execution issue.
The Netherlands already has a developed investment screening regime under the Dutch Vifo Act. The recent Dutch decision to block Kyndryl’s acquisition of Solvinity showed that even a US buyer does not have an automatic safe harbor when the target is relevant to digital infrastructure, cloud, telecom or public-sector sensitivity. See my earlier analysis on Dutch Government Blocks Kyndryl’s Acquisition of Solvinity.
The revised EU framework now reinforces the same direction at European level: more sectors, more coordination, more attention to ownership chains and more pressure to identify FDI issues early.
For buyers looking at Dutch AI, semiconductor, cloud, cybersecurity, defense-adjacent, fintech, data infrastructure or critical technology targets, FDI analysis should no longer be treated as a local filing question for later. It should be part of the first transaction assessment.
This article explains what the revised EU FDI framework means for US and UK buyers of Dutch tech targets and how Dutch deal documentation should respond.
This article is part of the ViottaLaw series on Vifo screening and foreign investments in Dutch acquisitions, Dutch Vifo Act expanded in 2027, regulatory and public-interest sensitivity in Dutch cross-border deals, conditions precedent in Dutch M&A deals and foreign buyers in Dutch M&A.
The EU framework is becoming stricter and more coordinated
The revised EU FDI Regulation does not replace national screening regimes with one single EU filing. Member States remain responsible for their own screening decisions. But the new framework pushes the EU towards a more harmonized baseline.
That matters because the old European FDI landscape was uneven. Some Member States had broad screening regimes. Others had narrower systems. Deal teams often had to manage a patchwork of national rules, different filing thresholds and different sector definitions.
The revised framework is intended to reduce that inconsistency. It requires Member States to maintain screening mechanisms and strengthens cooperation between national authorities and the European Commission. It also expands the common minimum scope for sensitive sectors, including areas such as defense, semiconductors, artificial intelligence, critical infrastructure, critical raw materials and financial infrastructure.
For dealmakers, the practical consequence is clear. FDI screening is becoming less optional and less localized. A cross-border tech transaction involving a Dutch target may need to be assessed not only under Dutch Vifo rules, but also in the wider European context.
The Netherlands remains attractive for US buyers, but screening deserves attention
For many US and UK investors, the Netherlands is seen as an open, sophisticated and business-friendly jurisdiction. That remains true. But “open to investment” does not mean “light touch” for sensitive technology or infrastructure.
The Kyndryl/Solvinity decision is the clearest recent Dutch example. The Dutch government prohibited the acquisition of Dutch cloud and managed services provider Solvinity by Kyndryl, a US-based technology services company. That decision matters because it shows that US ownership is not automatically viewed as low-risk where the Dutch target provides sensitive digital infrastructure or services relevant to public functions.
The point is not that US or UK buyers should avoid Dutch technology targets. The point is that buyer nationality alone does not determine clearance risk.
Dutch authorities may look at the target’s activities, customers, infrastructure role, access to sensitive data, dependency risks, continuity of services, ownership chain, governance rights and post-closing control. A US strategic buyer, UK fund, Luxembourg acquisition vehicle or EU holding company may still raise questions if non-EU control, sensitive infrastructure or strategic technology is involved.
For foreign buyers, that means Dutch counsel should review the investment-screening position before exclusivity or signing, not after the SPA has been negotiated.
Sensitive sectors are no longer narrow defense categories
One of the most important practical developments is the expansion of what counts as sensitive.
FDI screening is no longer limited to traditional defense contractors or obvious military assets. The relevant universe now includes technologies and infrastructure that support digital sovereignty, critical services, strategic autonomy and public order.
For Dutch transactions, this can include AI systems, cloud infrastructure, semiconductor technology, cybersecurity, data centers, telecom services, financial infrastructure, energy infrastructure, logistics, defense-adjacent technology, satellite systems, advanced sensors and certain critical suppliers.
The Dutch Vifo regime was already moving in that direction. The expected 2027 expansion of the Dutch Vifo Act will further broaden the scope of sensitive technology. The revised EU framework adds another layer by making clear that Member States are expected to screen a wider baseline of sensitive sectors.
This affects both strategic buyers and financial sponsors.
A private equity fund buying a Dutch cloud services provider may face different issues from a strategic defense buyer. But both need to understand the screening analysis. Governance rights, information access, control over strategic decisions and ultimate ownership can all matter.
Intra-EU acquisition structures may still be relevant
A frequent structuring assumption is that if the buyer is an EU vehicle, the transaction is less exposed to FDI screening.
That assumption is increasingly dangerous.
The revised EU framework brings more attention to intra-EU structures where the ultimate investor is controlled by a non-EU person or entity. That is highly relevant in sponsor-backed transactions. A US or UK fund may acquire a Dutch target through a Luxembourg, Irish, Dutch or other EU acquisition vehicle. The immediate buyer may be European, but the ultimate ownership and control chain may still point outside the EU.
Dutch Vifo analysis should therefore not stop at the signing entity.
It should review the full ownership chain, fund structure, general partner and manager arrangements, limited partner sensitivities where relevant, governance rights, board appointment rights, veto rights and information rights.
This is also important for consortium deals, continuation vehicles, minority investments and structured equity investments. Screening risk may arise not only from legal ownership percentage, but also from influence and access.
What should change in Dutch deal process?
The main change is timing.
FDI and Vifo analysis should move to the front of the process. It should be addressed before exclusivity, before sensitive due diligence access and before the SPA is largely settled.
In practice, this means that the buyer and seller should identify early whether the target operates in a sensitive sector, whether the buyer’s ownership chain creates additional questions and whether a filing may be required.
This analysis should influence the LOI, due diligence protocol, data room structure, SPA conditionality, timing assumptions and communication strategy.
A seller of a Dutch tech target should also think about bidder eligibility. The highest bidder is not always the most executable bidder. If a potential buyer is unlikely to obtain clearance, that buyer should not automatically receive the same access to sensitive technical, customer or infrastructure information as a buyer with a stronger clearance profile.
Dutch SPA drafting should reflect FDI execution risk
If a Dutch transaction may be subject to Vifo or other FDI review, the SPA should not treat clearance as a boilerplate condition precedent.
Several provisions become important.
The condition precedent should identify which clearance is required and whether completion is prohibited until approval has been obtained. The cooperation covenant should allocate responsibility for filings, information requests and engagement with authorities. The long-stop date should reflect realistic review timelines. The interim covenants should regulate conduct of business while clearance is pending.
The parties should also address remedies. Must the buyer accept conditions? Is there a hell-or-high-water obligation? Can the buyer walk away if approval is delayed or granted subject to burdensome conditions? What happens if the authority requires governance limitations, information restrictions or operational commitments?
These are commercial issues, not just regulatory issues. They affect price certainty, timing certainty and execution risk.
Clean-team planning becomes more important
FDI-sensitive transactions also require careful due diligence planning.
Potential buyers of Dutch tech companies may request access to source code, cybersecurity architecture, cloud infrastructure, customer contracts, public-sector contracts, data flows, encryption methods, AI models, training data, semiconductor designs or sensitive service continuity information.
Not all of that information should be shared with every bidder at the start of the process.
Where a transaction may raise Vifo or FDI concerns, sellers should consider staged disclosure, clean teams, restricted data rooms, access logs and delayed release of sensitive information. This is especially relevant where bidder eligibility is uncertain.
Clean-team planning should not be seen only as an antitrust issue. In sensitive technology transactions, it can also be part of national-security-aware deal execution.
Minority investments also deserve attention
FDI screening is not only relevant for full acquisitions.
Minority investments can also raise issues where the investor obtains governance rights, information rights, veto rights, board seats, observer rights or access to strategic technology. This is particularly relevant for venture capital and growth equity investments in Dutch AI, semiconductor, defense-adjacent, cybersecurity, cloud and data infrastructure companies.
A US or UK investor may not acquire control in the traditional M&A sense, but may still receive influence over strategic decisions or access to sensitive information.
That means investment agreements and shareholders’ agreements should be reviewed carefully. Reserved matters, board rights, information packages, technical reporting and investor consent rights may be relevant to the screening analysis.
For Dutch startups and scale-ups, this matters because venture documentation is often prepared quickly. If Vifo-sensitive rights are added casually, they may create avoidable execution risk.
What US and UK buyers should do before signing
A buyer considering a Dutch tech target should start with a practical screening memo.
That memo should answer several questions. Does the target operate in a sector likely to be sensitive under Dutch or EU screening rules? Does the target serve public authorities, critical infrastructure operators, defense customers, financial infrastructure, telecom or cloud customers? Does the target process sensitive data or provide continuity-critical services? Does the buyer’s ownership chain raise non-EU control issues? What governance rights will the buyer obtain? What information will the buyer access before and after closing? Is a filing required? If uncertain, should the parties seek informal guidance?
The answer to those questions should feed directly into the transaction timetable and documentation.
If the risk is low, the parties can proceed with more confidence. If the risk is moderate or high, the LOI and SPA should allocate that risk deliberately.
The mistake is to leave the issue until the closing checklist.
Conclusion
The revised EU FDI Regulation confirms the direction of travel in European deal practice. Investment screening is becoming broader, more coordinated and more relevant to technology transactions.
For US and UK buyers of Dutch tech targets, the practical lesson is not that the Netherlands is closed to foreign investment. It is not. The lesson is that Dutch Vifo and EU FDI analysis should be treated as a front-end deal structuring issue.
Kyndryl/Solvinity showed that a US buyer has no automatic safe harbor in Dutch sensitive digital infrastructure. The revised EU framework reinforces the broader message: ownership chain, sector sensitivity, governance rights, information access and deal documentation all matter.
For buyers, sellers and advisers, the best approach is early analysis, clear conditionality, realistic timing, clean-team planning and transaction documents that reflect regulatory execution risk.
In sensitive Dutch technology deals, the best buyer is not always the highest bidder. It is the bidder that can complete.
FAQ
Does the revised EU FDI Regulation replace Dutch Vifo screening?
No. National screening regimes remain important. The revised EU framework creates a more harmonized baseline and strengthens coordination, but Dutch Vifo analysis remains central for Dutch targets.
Why does this matter for US and UK buyers?
Because US or UK ownership does not automatically remove Dutch screening risk. Target sensitivity, ownership chain, governance rights and information access can still create issues.
Which Dutch sectors are most relevant?
Relevant sectors include AI, semiconductors, cloud, cybersecurity, telecom, data infrastructure, defense-adjacent technology, financial infrastructure, critical infrastructure and other sensitive technologies.
Can intra-EU acquisition vehicles still be screened?
Yes. If an EU vehicle is ultimately controlled by a non-EU investor, the ownership chain may still be relevant to the screening analysis.
Should FDI analysis be done before signing?
Yes. For sensitive Dutch technology targets, Vifo and FDI analysis should be addressed before exclusivity, diligence access and SPA signing.
What should the SPA include?
The SPA should address clearance conditions, cooperation covenants, filing responsibility, long-stop dates, interim covenants, remedies and termination rights if approval is delayed, refused or conditional.
About Dirk de Waard
Dirk de Waard is a Dutch corporate and M&A lawyer and partner at Venture Lawyers in Amsterdam. He advises US and UK buyers, investors, founders and technology companies on Dutch M&A, Vifo-sensitive transactions, governance rights, cross-border deal implementation and Dutch BV transaction mechanics.
Buying or investing in a Dutch technology company?
For Dutch technology targets in AI, cloud, semiconductors, cybersecurity, data infrastructure, defense-adjacent technology or other sensitive sectors, FDI screening should be assessed before the deal process becomes competitive or sensitive information is shared.
Dirk de Waard advises US and UK buyers, investors and international counsel on Dutch Vifo analysis, ownership-chain review, SPA conditionality and deal execution planning. Contact Dirk at dirk.dewaard@viottalaw.com to discuss Dutch implementation risks in a sensitive technology transaction.
