The Netherlands Authority for Consumers and Markets (ACM) has published a practical guide, a handreiking, on digital autonomy. According to the ACM's publication page, it explains how companies, governments and users can use competition law, the Data Act, the Digital Markets Act (DMA) and the Wet Markt en Overheid to become less dependent on a single IT provider. It is the first operational follow-up to the July position paper by five regulators, and it is a better template than most of what is being proposed under the label of "tech sovereignty".
The case for acting
The regulators' concern is real, and it deserves a fair statement. In their July paper, De route naar digitale autonomie, the ACM, AFM, AP, DNB and RDI argue that reliance on a small number of IT providers, many of them non-European, threatens the continuity of digital services. It also limits choice and makes switching costly and complex. Accountant.nl's report on the paper lists the risks: outages, cyber incidents, political pressure from non-European countries, and foreign data-access laws such as the US Cloud Act. A hospital, a bank or a municipality that cannot realistically leave its cloud provider has weak bargaining power and a fragile continuity plan. Treating that as a policy problem is legitimate.
What the guidance actually does
The notable thing about the handreiking is what it does not do. It does not ban non-EU providers, and it does not impose a local-hosting requirement. The regulators' own definition is modest: autonomy means control and choice over the IT services an organisation uses, and it "does not require full technological independence". The guidance mostly clarifies what is already lawful.
For competitors, the ACM says cooperation, for example on open standards or joint cloud purchasing, can be allowed if four conditions hold. The benefits must be clear and demonstrable, the cooperation must be necessary to achieve them, consumers must receive a fair share, and enough competition must remain. Those are the familiar tests of the competition-law exemption for efficiency-enhancing agreements, applied to a new setting. The ACM also offers to give an informal, early assessment of a cooperation agreement. That matters, because the main obstacle to joint procurement among small firms is usually fear of a cartel investigation, not the law itself.
On the user side, the guidance points to two instruments that already exist. The Data Act (Regulation (EU) 2023/2854) is meant, in its own words, to "facilitate switching between data processing services", and the ACM notes that it makes it easier to change cloud provider and take data along. Under the DMA, designated gatekeepers must support data portability and interoperability. The Wet Markt en Overheid applies when government bodies offer digital services as economic activities, so that public providers do not distort the market.
Where the risk lies: procurement
The harder questions come from the other half of the agenda. The July paper says autonomy should count as a full quality criterion alongside price and functionality, and as a precondition for vital infrastructure. It floats requiring vendors to fall only under European law. It also says that higher spending or fewer features may be justified during a transition. The new guidance asks governments, businesses and organisations to include digital autonomy in tenders as a requirement or a preference, and notes that governments can act as launching customers to help develop and scale digitally autonomous solutions.
A launching customer is a defensible tool. Early public demand can help a young firm reach scale, and the regulators frame it around open standards, not a particular nationality of vendor. That design choice matters. Open standards and interoperability widen the field: a European startup, a US hyperscaler and an open-source project can all compete if the interface is public. A tender that instead requires a particular legal domicile narrows the field and tends to raise prices. The first approach builds capability, and the second risks paying more for a worse service and calling it resilience.
There is also an accountability gap. Accepting "higher costs or fewer features" is a trade-off that falls on taxpayers and on patients, students and benefit claimants who depend on public systems. Procurement officers should therefore measure what they buy. If a tender specifies autonomy, it should say which risk it addresses (an exit from a provider, a legal exposure, a supply disruption), and the public body should publish a tested exit plan rather than a label.
What a proportionate approach looks like
Three principles follow from the ACM's own material.
- Prefer portability over provenance. Rules that make leaving easy, such as the Data Act's switching provisions and DMA interoperability duties, reduce lock-in with every provider, including European ones. Provenance tests protect against one kind of dependency and can create another, because a domestic incumbent can lock customers in just as well.
- Let competition law be the enabling framework. Treating joint purchasing and standards work as presumptively legitimate, with an early-assessment channel, lowers legal risk for firms without a new statute. The four-condition test keeps the safeguard against buyer cartels intact.
- Evaluate the launching-customer programme. If governments commit demand to digitally autonomous solutions, the commitments should be time-limited, tied to open interfaces, and reviewed against price and uptime. Without review, a launching-customer scheme becomes permanent preference.
The Netherlands has also tied this agenda to resilience law. Accountant.nl reports that the regulators link their recommendations to DORA and the NIS2-based Cyberbeveiligingswet, which takes effect on 15 August, because both regulate supply-chain risk. That framing is healthier than a purely industrial-policy one: the question is whether an organisation can keep operating when a supplier fails, not whether the supplier has the right flag.
Verdict
The ACM has done something useful and unglamorous. It has explained that firms can already collaborate, that users already hold portability rights, and that regulators will answer questions before an agreement is signed. The risk is not in the guidance but in what ministries and procurement offices do with it. If autonomy is written into tenders as measurable, standards-based exit capability, the Dutch approach could improve the market for everyone. If it hardens into a domicile test, it will cost more and deliver less, and it will weaken the open, interoperable internet that made cloud competition possible in the first place.