Dutch Tax Agency Reverses Microsoft 365 Cloud Migration Over Data Risks

The Dutch Tax and Customs Administration is reversing a planned Microsoft 365 cloud migration as officials seek greater control over sensitive government data.

Escrito por
Joseph Ofonagoro
Joseph Ofonagoro
Oct 7, 2026
Dutch Tax Agency Reverses Microsoft 365 Cloud Migration Over Data Risks

An internal government assessment says Microsoft 365 poses unacceptable risks to the Dutch Tax and Customs Administration. Image: Windows/Unsplash

We may earn from vendors via affiliate links or sponsorships. This might affect product placement on our site, but not the content of our reviews. See our Terms of Use for details.

The Netherlands’ Tax and Customs Administration is backing away from a planned Microsoft 365 cloud migration after an ICT review raised concerns about control over sensitive government data.

The agency now plans to rely more heavily on government-controlled infrastructure and alternative software rather than move the affected services into Microsoft’s cloud.

The decision reflects a broader concern facing governments and enterprises alike: how much control organizations give up when critical data and services depend on infrastructure operated by an outside provider.

Tax agency reverses its Microsoft 365 migration

According to a letter shared with the Dutch House of Representatives, and seen by Tweakers, the Dutch Tax and Customs Administration wants to end its reliance on Microsoft 365 software and move to open-source alternatives.

Importantly, the agency had previously chosen Microsoft 365 because suitable alternatives appeared unavailable. However, expanded data center capacity has since made an on-premises approach likely to work, giving officials a route away from the original cloud model.

The Microsoft 365 rollout had already been paused before the latest decision, according to Tweakers. The change therefore formalizes a shift away from the planned cloud deployment rather than representing a sudden removal of Microsoft software across the Dutch government.

Part of a bigger shift toward homegrown alternatives

While the Dutch government’s decision appears independent, it fits nicely into a broader shift to reduce reliance on foreign third-party providers.

That risk became more visible in June when Anthropic was temporarily forced to suspend access to its Fable 5 and Mythos AI models for non-U.S. citizens. Anthropic restored access after lifting the restrictions. Still, the episode clearly showed how a technology service used by organizations outside its territory can suddenly be affected by a foreign government’s decision.

Singapore took a different route in July, saying that export controls and geopolitics could shape access to frontier AI and announcing a strategy to diversify across multiple providers rather than depend on one.

Closely related to the Dutch migration plans and connected to data sovereignty is a September plan from Switzerland to ditch Microsoft 365 across over 3,000 government PCs.

Advertisement

Together, the moves show governments putting more emphasis on reducing dependence on foreign technology providers.

What happens next

The transition will take several years. The Dutch government plans to begin moving email and calendar services to government-controlled servers in 2027, followed by storage and collaboration services through 2028.

The bigger test will be whether the replacement systems can match the reliability, security, and scale of the existing setup.

That makes the transition a test of whether the government can regain control of its infrastructure without sacrificing the performance and services employees depend on.

Must-read security coverage

What enterprises can learn from the Dutch decision

The Dutch decision may be worth watching for enterprises that have built critical operations around a small number of technology providers.

Dependency can become a business risk when control of the underlying infrastructure sits elsewhere. A provider’s legal obligations, geopolitical position, or ability to change access to its services can suddenly affect an organization thousands of miles away.

That makes data portability, independent, reliable backups, and data transparency more than technical housekeeping. They can determine how much leverage a company has when a supplier changes its terms, suffers an outage, faces government restrictions, or simply stops meeting the organization’s needs.

Other news: South Korean President Lee Jae Myung ordered an investigation into a series of financial-sector data breaches affecting tens of thousands of customers, as regulators examine whether AI-assisted tools played a role in the attacks.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.