The Netherlands’ Tax and Customs Administration is backing away from a planned Microsoft 365 cloud migration after an ICT review raised concerns about control over sensitive government data.
The agency now plans to rely more heavily on government-controlled infrastructure and alternative software rather than move the affected services into Microsoft’s cloud.
The decision reflects a broader concern facing governments and enterprises alike: how much control organizations give up when critical data and services depend on infrastructure operated by an outside provider.
Tax agency reverses its Microsoft 365 migration
According to a letter shared with the Dutch House of Representatives, and seen by Tweakers, the Dutch Tax and Customs Administration wants to end its reliance on Microsoft 365 software and move to open-source alternatives.
Importantly, the agency had previously chosen Microsoft 365 because suitable alternatives appeared unavailable. However, expanded data center capacity has since made an on-premises approach likely to work, giving officials a route away from the original cloud model.
The Microsoft 365 rollout had already been paused before the latest decision, according to Tweakers. The change therefore formalizes a shift away from the planned cloud deployment rather than representing a sudden removal of Microsoft software across the Dutch government.
Part of a bigger shift toward homegrown alternatives
While the Dutch government’s decision appears independent, it fits nicely into a broader shift to reduce reliance on foreign third-party providers.
That risk became more visible in June when Anthropic was temporarily forced to suspend access to its Fable 5 and Mythos AI models for non-U.S. citizens. Anthropic restored access after lifting the restrictions. Still, the episode clearly showed how a technology service used by organizations outside its territory can suddenly be affected by a foreign government’s decision.
Singapore took a different route in July, saying that export controls and geopolitics could shape access to frontier AI and announcing a strategy to diversify across multiple providers rather than depend on one.
Closely related to the Dutch migration plans and connected to data sovereignty is a September plan from Switzerland to ditch Microsoft 365 across over 3,000 government PCs.
Together, the moves show governments putting more emphasis on reducing dependence on foreign technology providers.
What happens next
The transition will take several years. The Dutch government plans to begin moving email and calendar services to government-controlled servers in 2027, followed by storage and collaboration services through 2028.
The bigger test will be whether the replacement systems can match the reliability, security, and scale of the existing setup.
That makes the transition a test of whether the government can regain control of its infrastructure without sacrificing the performance and services employees depend on.
Must-read security coverage
- UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case
- Blackpoint Cyber vs. Arctic Wolf: Which MDR Solution is Right for You?
- How GitHub Is Securing the Software Supply Chain
- 8 Best Enterprise Password Managers
What enterprises can learn from the Dutch decision
The Dutch decision may be worth watching for enterprises that have built critical operations around a small number of technology providers.
Dependency can become a business risk when control of the underlying infrastructure sits elsewhere. A provider’s legal obligations, geopolitical position, or ability to change access to its services can suddenly affect an organization thousands of miles away.
That makes data portability, independent, reliable backups, and data transparency more than technical housekeeping. They can determine how much leverage a company has when a supplier changes its terms, suffers an outage, faces government restrictions, or simply stops meeting the organization’s needs.
Other news: South Korean President Lee Jae Myung ordered an investigation into a series of financial-sector data breaches affecting tens of thousands of customers, as regulators examine whether AI-assisted tools played a role in the attacks.