The Dutch cabinet has sharply tightened its government-wide cloud policy. Public bodies will no longer be allowed to deploy new email or document management systems in the public cloud. Stricter rules also apply to data processing, dependence on foreign vendors, and exit strategies. The changes are laid out in a letter to Parliament from State Secretary W.J.M. Aerdts (Economic Affairs and Climate), sent to the House of Representatives on Friday.
The overhaul follows investigations by the Government Audit Service and
the Netherlands Court of Audit, which flagged risks around cloud use within central government. Shifting geopolitics and the dominance of large international cloud providers are also driving the new approach.
Public cloud pushed to the sidelines
One of the most striking shifts: the cabinet now advises against using public cloud for email and document management. Existing environments will get a transition period, after which they must migrate to alternative solutions.
According to the cabinet, emails and documents together contain vast amounts of government information. Even if individual files aren’t classified, their aggregation can pose significant
security risks. Nearly all public bodies also rely on these systems for day-to-day operations.
Tougher rules for data and vendors
The policy gets markedly stricter across the board.
Key changes include:
- The cloud policy will apply to virtually the entire central government, excluding Defence and the High Councils of State.
- Organizations get a four-year transition period to bring existing cloud environments in line with the new rules.
- Data in public cloud environments may be stored and processed only within the European Economic Area (EEA).
- Data must be encrypted by default, except when it is public information.
- Cloud choices must explicitly consider dependency on vendors subject to non-European laws.
- Every major cloud application must have a comprehensive exit plan, including an emergency scenario if a cloud provider suddenly fails.
- Large cloud applications must be centrally reported to the Government CIO for improved oversight.
Boost for sovereign cloud
The cabinet acknowledges many public bodies can’t meet the new requirements overnight. A generous transition period is intended to bridge that gap—and to spur the development of European and Dutch sovereign cloud solutions.
According to the letter, no extra funding is being made available. Implementation must be covered by existing IT budgets and capacity, meaning rollout could take several years.
Critical systems less tied to foreign clouds
For organizations covered by the Critical Entities Resilience Act and the Cybersecurity Act, the cabinet further advises avoiding reliance on cloud providers that fall partly under non-European jurisdictions for core tasks.
Public cloud also remains off-limits for state secrets and other highly sensitive data. Base registries may use public cloud only for performance or scalability; the source data must remain under the government’s direct control.
Wider government rollout in the works
The cabinet plans to extend the renewed policy to municipalities, provinces, and water authorities. It is also preparing a broader decision framework for digital services and aligning with upcoming EU rules, including the proposed Cloud and AI Development Act (CADA).
Why it matters
This marks a clear pivot in Dutch cloud strategy. After years of embracing public cloud, the focus shifts to digital sovereignty, risk control, and reducing dependence on big foreign tech. U.S. hyperscalers like Microsoft, Amazon Web Services, and Google Cloud will be watching closely, as new government projects are likely to favor European or hybrid cloud options.