DigiD whistleblower Pieter van Oordt at Cybersec Netherlands 2026
For many organisations, digital sovereignty still sounds like an abstract geopolitical concept. Wrongly so. Dependence on foreign technology partners can create unacceptable risks. And stakeholders need to be informed about them. As soon as a critical IT supplier changes ownership, the issue suddenly becomes very concrete. Does foreign legislation affect control over systems and data integrity? And is the continuity of essential services guaranteed?
The proposed acquisition of Dutch IT company Solvinity by US-based Kyndryl brought these questions into sharp focus. Solvinity manages the Picard platform on which important digital government services such as DigiD, MijnOverheid and Digipoort run. A change in ownership of Solvinity therefore raised questions that went far beyond a regular commercial transaction. What are the consequences for society and security? Which legislation applies to the operator of a platform? Who can gain access to the systems and data of the digital government? And what happens when geopolitical developments directly affect a technology partner?
This case forms the basis of the keynote “Inside the DigiD Storm: Digital Sovereignty and the Story of a Whistleblower”, which Pieter van Oordt will deliver at Cybersec Netherlands 2026. Drawing on his personal involvement in the Solvinity case, he will show how an apparently commercial acquisition can develop into an issue involving threats to public interests, including national security and the functioning of vital services in society.
Ownership is not control
An important misconception surrounding digital sovereignty is that it is sufficient to physically store data within the Netherlands or Europe. In reality, the issue is much more complex. Control is determined by factors such as where systems run, who manages the cryptographic keys, who has access, which contracts have been concluded and under which jurisdiction a supplier falls. Can a technology partner genuinely exclude foreign interference, or is there legislation in the country of the parent company that can have an impact on European territory? And can the application of that legislation be enforced?
An organisation can therefore be the owner of its data on paper while, in practice, remaining dependent on an external party that determines how that data is processed, secured or made available. For public organisations, this issue is even more sensitive. Services such as DigiD, MijnOverheid and DigiPoort form an essential part of the digital government. Disruption does not only affect IT, but directly affects citizens, businesses and the continuity of public services.
Europe’s battle for digital sovereignty
Just as the territory of the European Union is undisputed, the digital sovereignty of the European Union should also be undisputed. It is a simple statement that is difficult to put into practice. And with the acquisition of Solvinity, this is where an actual battle is being fought.
After all, this concerns DigiD with 700 million authentications per year, MijnOverheid with 100 million government letters and 10 million digital mailboxes, and DigiPoort as the hub that enables confidential data to be exchanged between government organisations. Where cybersecurity covers accessibility, data integrity and continuity, the acquisition of Solvinity by a US company would give the United States the ability to influence all of these elements.
Blocking the Solvinity acquisition is a benchmark in Europe’s battle for digital sovereignty. Digital dependency is therefore a legal and geopolitical issue that companies, organisations and governments must take into account. And every strategic technology decision should also include the question of what happens when circumstances change.
Sovereignty becomes governance
Digital sovereignty does not mean that every organisation must become completely independent of foreign technology. In a global digital economy, that is often simply unrealistic. It is much more about taking a risk-based approach and retaining sufficient freedom to act.
Can you switch providers when necessary? Can you actually move your data and systems? Are contracts designed to deal with a change of ownership? Are responsibilities within the organisation clear? And is there a realistic exit scenario when a supplier is no longer acceptable?
Sovereignty ultimately becomes a governance issue. Not only the CIO or CISO, but also the board, procurement, legal functions and privacy officers must jointly determine which dependencies are acceptable.
Do not wait for a crisis
The Solvinity case shows that digital sovereignty is often only seriously discussed when something is actually at stake. That is precisely why it is important not to wait until a crisis before asking the logical questions.
Organisations can already carry out a risk and impact analysis. Change-of-control provisions, alternative suppliers, migration options, exit strategies, contractual safeguards and the division of responsibilities are all important areas of attention. Have sovereignty risks been identified and are they manageable? And have stakeholders been informed?
That is also the core of the keynote “Inside the DigiD Storm: Digital Sovereignty and the Story of a Whistleblower”, which Pieter van Oordt will deliver at Cybersec Netherlands 2026.
Drawing on his personal experience with the Solvinity case, he will show how digital dependency, legal power and national security come together in practice. The key questions that follow are how much control organisations really have over the systems they depend on, and what risks and impact infringements on digital sovereignty can have.