Dutch government blocks Kyndryl-Solvinity: what foreign tech investors should know
Category: InsightsThe Solvinity decision is not a general ban on US tech investment but it is a serious signal for deals involving Dutch digital infrastructure
The Dutch government has prohibited the proposed acquisition of Solvinity by the US IT services company Kyndryl after advice from the Dutch Investment Screening Bureau (Bureau Toetsing Investeringen – BTI). Solvinity is relevant because it provides cloud and infrastructure services connected to sensitive Dutch public-sector digital systems, including DigiD and MijnOverheid. The decision was reportedly taken under the Dutch telecom foreign investment framework, not under the more recent general Dutch FDI screening regime known as the Vifo Act.
For US and UK investors, the important point is not that Dutch tech companies have suddenly become uninvestable. They have not. The important point is more specific: where a Dutch target is deeply connected to critical public infrastructure, identity systems, sensitive government data, telecom infrastructure, cloud infrastructure or digital sovereignty concerns, deal certainty now requires a much more serious regulatory workstream.
This article is part of VIOTTA’s cross-border deal and Dutch M&A analysis, including M&A Insights on Dutch deal practice, AI & Dutch Transactions Insights and Cross-Border Deal Implementation.
What happened?
Kyndryl’s proposed acquisition of Solvinity had already attracted significant political and public attention in the Netherlands. The sensitivity was not classic merger-control economics. The concern was digital autonomy: who ultimately controls infrastructure used for Dutch public digital services, and what happens if that control sits within a foreign, non-EU corporate group?
The Dutch competition authority had previously cleared the transaction from a competition-law perspective, finding no competition concerns. That is important. The competition question was whether the transaction would significantly restrict competition. The sovereignty question was different: whether the acquisition could create unacceptable risks for the public interest or national security in a sensitive digital infrastructure context.
That distinction matters for transaction planning. A deal may be acceptable from an antitrust perspective and still fail, or become politically and legally difficult, under a national-security, telecom or sector-specific screening framework.
Not Vifo, but telecom screening
A key point for international deal teams is the legal basis. This was not, according to current reporting, a decision under the Dutch Vifo Act. The assessment appears to have been made under the Wet ongewenste zeggenschap telecommunicatie, the Dutch rules on undesirable control in telecommunications, which are implemented in Chapter 14a of the Dutch Telecommunications Act.
That is not just a technical distinction. The Vifo Act is the general Dutch investment screening regime for vital providers and sensitive technology. The telecom regime is older and sector-specific. It is designed to prevent a party from acquiring such control over telecommunications infrastructure or services that this control could be misused, including in ways that may affect national security or public order.
For foreign investors, the practical lesson is that Dutch screening risk does not sit in one statute only. A transaction can raise issues under general FDI rules, telecom rules, sector-specific regimes, procurement arrangements, public contracts, cybersecurity frameworks and political oversight. A narrow “is this Vifo?” analysis may therefore be insufficient.
Why the decision matters for US and UK investors
The decision will inevitably be read internationally against the background of digital sovereignty, US cloud dependency and the earlier political controversy around Nexperia. That is why communication matters. If the Dutch government does not explain clearly why this case is exceptional, the market may hear a broader message: Dutch tech infrastructure is becoming difficult to buy.
That would be the wrong conclusion, but it is a real perception risk.
Most Dutch technology companies can still be acquired by, or receive investment from, US and UK investors. The Netherlands remains open to foreign capital and international technology businesses. The government itself appears to have emphasised that the review is country-neutral, risk-based and proportionate, and that the Netherlands values foreign technology companies, including US companies, and their contribution to the Dutch economy and digital infrastructure.
But deal teams should not ignore the signal. Where a Dutch target is close to vital digital infrastructure, identity services, public-sector cloud, defence-adjacent technology, telecoms, cybersecurity, sensitive data or continuity of government services, regulatory strategy is no longer a late-stage condition precedent. It is a core transaction issue.
The real issue: control, dependency and continuity
The Solvinity case is not simply about nationality. It is about control over infrastructure that the Dutch state and citizens rely on. The public concern was that foreign control could create risks around access, continuity, confidentiality, dependency and potential foreign legal compulsion. NOS reports that concerns included the possibility that US legal powers could be used to block access or secretly request data, while Kyndryl has maintained that Dutch data would not be at risk.
From a deal perspective, that means the analysis should move beyond formal ownership. Regulators may ask practical questions: who can influence operations, who controls access, where is data stored, who administers systems, where are encryption keys held, what are the parent-company rights, what happens in a geopolitical crisis, and can Dutch public services continue if the owner is under foreign pressure?
Those questions are not always solved by saying that the servers are in the Netherlands or that the Dutch operating company remains locally incorporated. Governance, access rights, technical architecture, contractual control and operational dependencies may matter just as much.
What should deal teams do differently?
For US and UK buyers, this type of transaction requires earlier mapping. Before signing, buyers should understand whether the target provides services to government bodies, critical infrastructure operators, telecom providers, identity systems, healthcare infrastructure, security-sensitive customers or public-sector cloud environments.
The transaction documentation should then reflect that risk. Conditions precedent should be specific, not generic. Regulatory filings should be prepared early. Cooperation covenants should address information requests, mitigation discussions and timing. Long-stop dates should allow for realistic review periods. Termination rights should distinguish between ordinary delay and an outright prohibition.
The SPA should also anticipate mitigation. In some cases, regulators may accept governance commitments, ring-fencing, Dutch board requirements, local operational controls, data-access restrictions, security protocols, customer commitments or carve-outs. In other cases, as Solvinity shows, mitigation may not be enough.
For sellers and founders, the lesson is different but equally important. If the business is in a sensitive sector, deal certainty depends on buyer selection. The highest price may not be the most executable transaction if the buyer creates a serious screening risk.
Dutch tech is not closed, but sensitive digital infrastructure is different
The most important message to the US and UK market should be clear: this decision should not be read as a general closing of the Dutch tech market. The Netherlands needs international capital, international technology partnerships and international strategic buyers.
But the threshold is different for companies that sit close to the digital state. A SaaS company selling workflow tools to private customers is not the same as a provider embedded in national identity infrastructure. A cloud services business with public-sector dependencies is not the same as a general software company. A cybersecurity or telecom infrastructure target is not the same as a consumer app.
That distinction should be made explicitly in deal communications, investor briefings and government messaging. Without that distinction, the risk is that every foreign tech deal becomes politically framed as a sovereignty issue.
Why communication from Dutch authorities matters
For international investors, legal predictability is as important as legal power. The Dutch government may have good reasons to block a specific transaction. But if the reasoning is not communicated clearly, the decision can create uncertainty beyond the individual case.
The market needs to understand the boundaries. Which types of technology businesses are sensitive? Which dependencies matter? What mitigation measures are credible? When is a public-interest risk too serious to manage? How should investors engage with the Bureau Toetsing Investeringen? At what stage should parties seek informal guidance or prepare a filing strategy?
Clear communication will help protect both sides of the policy objective. It protects national security and digital sovereignty, while also preserving the Netherlands’ reputation as a serious, investable and internationally connected technology market.
Practical conclusion
The Solvinity decision is a landmark signal for cross-border tech M&A in the Netherlands. It does not mean US or UK buyers can no longer acquire Dutch technology companies. It does mean that transactions involving sensitive digital infrastructure require a more sophisticated regulatory and governance strategy from the start.
For deal teams, the key question is no longer only whether the acquisition requires merger clearance or Vifo analysis. The better question is whether the target creates a digital sovereignty, telecom, public infrastructure, cybersecurity or continuity-of-service concern that needs to be addressed in the transaction structure.
Foreign investment into Dutch tech remains possible. But in sensitive infrastructure deals, execution certainty now depends on understanding the Dutch public-interest framework before signing — not after political attention has already gathered around the transaction.
About Dirk de Waard
Dirk de Waard is a Dutch corporate and M&A lawyer, partner of Venture Lawyers in Amsterdam focusing on Dutch M&A, venture capital, private equity, governance and cross-border deal implementation. He advises investors, founders, companies and international counsel on Dutch transaction structuring, shareholder arrangements, regulatory execution risk and practical implementation of international deal terms in Dutch BV structures.
Considering an acquisition, investment or financing involving a Dutch technology company, cloud provider, AI business or digital infrastructure target?
Dirk de Waard advises US and UK investors, founders and deal counsel on Dutch M&A implementation, governance, transaction documentation and regulatory execution risk. Contact dirk.dewaard@viottalaw.com to assess Dutch deal-implementation points before signing, regulatory filings or public-interest concerns become time-critical.
