Netherlands Netherlands ACM platform competition Big Tech

The ACM's Digital Autonomy Guidance Is Sound Because It Treats Autonomy as a Competition Question, Not a Mandate

The Dutch competition authority's new handreiking shows existing law already allows joint cloud buying and open standards, and that is better than a sovereignty mandate.

ACM Digital Autonomy Guidance at a Glance People of Internet Research · Netherlands 5 Regulators behind position paper ACM, AFM, AP, DNB and RDI co-autho… 4 Conditions for cooperation Benefits, necessity, fair consumer… 4 Core recommendations in paper Government demand, procurement, se… peopleofinternet.com
ACM Digital Autonomy Guidance at a Gla… People of Internet Research · Netherlands 5 Regulators behind position paper 4 Conditions for cooperation 4 Core recommendations … peopleofinternet.com

Key Takeaways

The Netherlands Authority for Consumers and Markets (ACM) has published a practical guide, a handreiking, on digital autonomy. According to the ACM's publication page, it explains how companies, governments and users can use competition law, the Data Act, the Digital Markets Act (DMA) and the Wet Markt en Overheid to become less dependent on a single IT provider. It is the first operational follow-up to the July position paper by five regulators, and it is a better template than most of what is being proposed under the label of "tech sovereignty".

The case for acting

The regulators' concern is real, and it deserves a fair statement. In their July paper, De route naar digitale autonomie, the ACM, AFM, AP, DNB and RDI argue that reliance on a small number of IT providers, many of them non-European, threatens the continuity of digital services. It also limits choice and makes switching costly and complex. Accountant.nl's report on the paper lists the risks: outages, cyber incidents, political pressure from non-European countries, and foreign data-access laws such as the US Cloud Act. A hospital, a bank or a municipality that cannot realistically leave its cloud provider has weak bargaining power and a fragile continuity plan. Treating that as a policy problem is legitimate.

What the guidance actually does

The notable thing about the handreiking is what it does not do. It does not ban non-EU providers, and it does not impose a local-hosting requirement. The regulators' own definition is modest: autonomy means control and choice over the IT services an organisation uses, and it "does not require full technological independence". The guidance mostly clarifies what is already lawful.

For competitors, the ACM says cooperation, for example on open standards or joint cloud purchasing, can be allowed if four conditions hold. The benefits must be clear and demonstrable, the cooperation must be necessary to achieve them, consumers must receive a fair share, and enough competition must remain. Those are the familiar tests of the competition-law exemption for efficiency-enhancing agreements, applied to a new setting. The ACM also offers to give an informal, early assessment of a cooperation agreement. That matters, because the main obstacle to joint procurement among small firms is usually fear of a cartel investigation, not the law itself.

On the user side, the guidance points to two instruments that already exist. The Data Act (Regulation (EU) 2023/2854) is meant, in its own words, to "facilitate switching between data processing services", and the ACM notes that it makes it easier to change cloud provider and take data along. Under the DMA, designated gatekeepers must support data portability and interoperability. The Wet Markt en Overheid applies when government bodies offer digital services as economic activities, so that public providers do not distort the market.

Where the risk lies: procurement

The harder questions come from the other half of the agenda. The July paper says autonomy should count as a full quality criterion alongside price and functionality, and as a precondition for vital infrastructure. It floats requiring vendors to fall only under European law. It also says that higher spending or fewer features may be justified during a transition. The new guidance asks governments, businesses and organisations to include digital autonomy in tenders as a requirement or a preference, and notes that governments can act as launching customers to help develop and scale digitally autonomous solutions.

A launching customer is a defensible tool. Early public demand can help a young firm reach scale, and the regulators frame it around open standards, not a particular nationality of vendor. That design choice matters. Open standards and interoperability widen the field: a European startup, a US hyperscaler and an open-source project can all compete if the interface is public. A tender that instead requires a particular legal domicile narrows the field and tends to raise prices. The first approach builds capability, and the second risks paying more for a worse service and calling it resilience.

There is also an accountability gap. Accepting "higher costs or fewer features" is a trade-off that falls on taxpayers and on patients, students and benefit claimants who depend on public systems. Procurement officers should therefore measure what they buy. If a tender specifies autonomy, it should say which risk it addresses (an exit from a provider, a legal exposure, a supply disruption), and the public body should publish a tested exit plan rather than a label.

What a proportionate approach looks like

Three principles follow from the ACM's own material.

The Netherlands has also tied this agenda to resilience law. Accountant.nl reports that the regulators link their recommendations to DORA and the NIS2-based Cyberbeveiligingswet, which takes effect on 15 August, because both regulate supply-chain risk. That framing is healthier than a purely industrial-policy one: the question is whether an organisation can keep operating when a supplier fails, not whether the supplier has the right flag.

Verdict

The ACM has done something useful and unglamorous. It has explained that firms can already collaborate, that users already hold portability rights, and that regulators will answer questions before an agreement is signed. The risk is not in the guidance but in what ministries and procurement offices do with it. If autonomy is written into tenders as measurable, standards-based exit capability, the Dutch approach could improve the market for everyone. If it hardens into a domicile test, it will cost more and deliver less, and it will weaken the open, interoperable internet that made cloud competition possible in the first place.

Sources & Citations

  1. ACM: guide on digital autonomy
  2. ACM et al.: De route naar digitale autonomie
  3. EU Data Act (Regulation 2023/2854)
  4. Accountant.nl: regulators on procurement choices