
Imagine this: you open your laptop on Monday morning, only to find that your email no longer works. Not because something has gone wrong with your server, but because a company in the United States has decided to suspend your access. It may sound like science fiction, but this became a reality in 2025 for the Chief Prosecutor of the International Criminal Court in The Hague. Following U.S. sanctions, he lost access to his Microsoft email account. The situation illustrates the potential consequences of digital dependency on U.S.-based technology providers and the extent to which U.S. law can affect organisations outside the United States.
This is at the heart of the issue analysed by the Rathenau Instituut in its 2025 report Setting a Course Towards Digital Autonomy. The message is not that technology is inherently bad, or that Microsoft is necessarily a problem. The message is that digital dependency has become a risk that directors need to take seriously — and that the issue is more complex than many people realise.
Most public-sector organisations — as well as many private companies — rely on the services of a handful of large U.S. technology companies. Microsoft, Google and Amazon dominate cloud storage, email, collaboration platforms and office software. That, in itself, is not necessarily a problem. The issue is what can happen as a result of this dependency.
IT teams are increasingly spending less time on technology itself and more time on user support, causing internal expertise to erode. As a result, organisations may lose the knowledge required to fully understand their systems or replace them. Updates are often rolled out automatically, even when an organisation would have preferred to assess them first. For example, Microsoft Copilot was rolled out at educational institutions without sufficient consideration of applicable privacy requirements. And switching to another provider? In theory, possible — but in practice so complex and costly that it is no longer a realistic option for most organisations.
In July 2024, cybersecurity company CrowdStrike made an error in a software update. The result: Windows systems around the world went down. Thousands of flights were cancelled and hospitals had to scale back their operations. Not because of a cyberattack or deliberate action, but simply because of a single update from one company on which much of the world had come to depend.
This is what the Rathenau Instituut means by vulnerability: when everything runs through a single provider, one disruption can be enough to cause significant damage.
The geopolitical context makes this issue even more urgent. All major cloud providers are U.S. companies, which means they are subject to U.S. law. Under Section 702 of the Foreign Intelligence Surveillance Act (FISA), U.S. intelligence agencies can require access to large amounts of data relating to non-U.S. citizens without an individual court order. The fact that your data is stored on servers in Amsterdam makes little difference in this respect: the company operating those servers is American and therefore subject to U.S. law.
Moreover, relations between Europe and the United States are under pressure. Major technology companies maintain close ties with the U.S. government, and there are indications that Europe could face trade-related pressure if it seeks to curb the power of Big Tech too aggressively. As the report points out, at a time when the United States can no longer automatically be regarded as a European ally, this increases the urgency of the issue.
In recent years, the European Union has invested heavily in regulation. The Digital Markets Act, for example, requires major platforms to provide greater openness and interoperability. In the education sector, the ICT cooperatives SURF and SIVON have secured improved privacy arrangements with Microsoft and Google through collective negotiations. These are positive developments.
But the Rathenau Instituut is clear: measures like these will not solve the problem as long as organisations continue, in practice, to choose the same major providers. According to the Rathenau Instituut, genuine autonomy only begins when organisations actually make different choices — with every procurement process and every contract renewal.
This may sound like a distant issue, but Germany has already demonstrated what is possible. The state of Schleswig-Holstein migrated the computers of 30,000 civil servants from Microsoft to open-source alternatives: LibreOffice replaced Office, Linux replaced Windows and Nextcloud replaced OneDrive. It was neither cheap nor without challenges — but it was done.
In the Netherlands, the government is working on initiatives such as PubHubs, a public online environment through which organisations can communicate with their stakeholders outside commercial platforms. The Dutch House of Representatives has also adopted a motion aimed at ensuring that, by 2029, at least 30% of the government cloud infrastructure is hosted on Dutch or European soil.
The report does not call for an overnight revolution. It does, however, call for a different approach to IT procurement. Treat the choice of a digital service provider not as a technical decision, but as a strategic one. Calculate the true costs carefully — including the cost of switching providers if you ever need to do so. Be prepared to sacrifice some convenience where this means retaining greater control over your systems and data. And, last but not least, include contractual safeguards to protect digital and operational sovereignty as far as possible.
After all, digital sovereignty is not just a government issue. It affects anyone who works with data, personal information or confidential information — and who asks themselves who is ultimately in control of it.
Would you like to know more about how you, as a director, can ensure that you retain as much control as possible over your data? Please feel free to contact one of our specialists within our IT, Privacy & Cybersecurity team. We are happy to assist you!
Would you like to receive a monthly overview of our latest legal updates and blog articles? Subscribe to our newsletter.