A letter that reframes cloud policy as sovereignty policy
On July 3, 2026, State Secretary Eric van der Burg sent the Tweede Kamer a letter on the revision of national cloud policy, confirming that the cabinet has chosen a cloud environment that is "as sovereign as possible" and, wherever feasible, hosted in the government's own datacenters (ODCs) rather than with commercial hyperscalers. The vehicle is the NDS Cloud Implementation Programme, part of the Netherlands Digitalisation Strategy. Officials expect the first government applications to run on the sovereign cloud by the end of 2026, with proof-of-concept results going back to Parliament by year-end, according to the government's own summary of the programme on digitaleoverheid.nl.
The cabinet did not pick a modest tier. Under the European Commission's Cloud Sovereignty Framework, which scores providers on eight objectives against a five-step SEAL scale, the Netherlands is targeting SEAL-4 — full sovereignty, EU-only legal jurisdiction, no critical dependency on non-EU infrastructure — according to Computable's reporting on the cabinet decision. That is the ceiling of the EU's own sovereignty scale, not a middle rung.
The same logic, a different register
Strip away the EU procedural language and the underlying logic is familiar from Asia. Vietnam's Law on Data (No. 60/2024/QH15), effective July 1, 2025, created "important" and "core" data categories restricted from crossing the border on national-security grounds; its Personal Data Protection Law (No. 91/2025/QH15), effective January 1, 2026, backs this with fines up to 5% of annual revenue for cross-border violations. A fourth draft law, assessed by Vietnam's Ministry of Justice on July 14, 2026, would go further still and ban core-data exports outright. China's Cybersecurity Law took the same premise even earlier: Article 37 requires operators of critical information infrastructure to store personal information and "important data" domestically, with any export requiring a security assessment by the Cyberspace Administration of China.
The throughline connecting The Hague, Hanoi, and Beijing is not ideology — it is the belief that data location determines legal control, and that legal control over infrastructure a state depends on cannot safely sit inside another state's jurisdiction. Van der Burg's letter makes this explicit: the trigger is the coalition's judgment, reached in the July 2, 2026 agreement, that dependence on "a limited number of large, non-European providers" is a strategic risk. The government's own figures back the concern — non-European providers currently hold roughly 70% of the European cloud market, per the cabinet's own statement.
Steelmanning the sovereignty case
The strongest argument for the Dutch plan isn't nationalism, it's continuity risk. The US CLOUD Act gives American authorities a legal claim on data held by US-headquartered cloud providers regardless of where the servers sit, and FISA Section 702 authorizes surveillance of non-US persons' data flowing through American infrastructure. A government that runs its benefits systems, tax administration, or emergency services on infrastructure another state can legally compel access to — or, in an extreme scenario, sanction or cut off — is exposed to a risk that has nothing to do with cybersecurity hygiene and everything to do with jurisdiction. Estonia's post-2007 investment in a "data embassy" model, hosting backup government registries under diplomatic-immunity protections in Luxembourg, reflects the same underlying concern from a country with direct experience of state-level disruption. Given how unpredictable transatlantic trade and tech policy has been since 2025, hedging critical government workloads against a single foreign jurisdiction is a defensible risk-management call, not paranoia.
Where the Dutch approach still diverges from Vietnam and China
The difference that matters is scope and process. The NDS Cloud programme, as described in Van der Burg's letter, currently applies to government workloads — not, as in China, to private operators across telecoms, energy, finance, and healthcare, and not, as in Vietnam's draft fourth law, to all "important" and "core" data generated by any company operating in the country. The Dutch design process ran 3 open dialogue sessions with 69 organisations, including hyperscalers, between November 2025 and January 2026, and the cabinet has committed to publishing the cloud's technical design publicly. Vietnam's Ministry of Public Security veto power and China's CAC security-assessment gate have no equivalent here — decisions run through a parliamentary letter, not a security-ministry approval stamp.
That said, proportionality is the metric to watch, not intent. SEAL-4 is a blanket ceiling; it does not yet distinguish between a tax database that genuinely warrants full EU-only jurisdiction and a low-sensitivity public information service that doesn't need the same infrastructure premium. The European Commission's own framework allows for lower SEAL tiers precisely because uniform maximum sovereignty is expensive and slows procurement — the EU applied a mixed approach in its own April 2026 cloud contract, awarding a combined €180 million across four providers rather than a single sovereign-only vendor. If the Dutch programme drifts from risk-tiered sovereignty toward a flat SEAL-4-for-everything mandate, or if "sovereign" quietly expands from government workloads to the private sector the way China's CII law and Vietnam's core-data regime did, the Netherlands will have imported the costs of the APAC model without the narrower justification that currently distinguishes it. Van der Burg's own caveat — that the programme only works with sufficient government-wide uptake and upfront financing, or it becomes "significantly more complex and prolonged" — is itself an admission that blanket sovereignty is not cheap. Keeping the scope narrow, the process open to market participants including EU-compliant hyperscaler offerings, and the classification tiered to actual risk is what will keep this a genuine resilience measure rather than the digital protectionism it currently, correctly, distinguishes itself from.