What happened
The Netherlands’ Tax and Customs Administration announced it will abandon a planned migration to Microsoft 365, citing an internal assessment that the cloud service poses unacceptable risks to the control and confidentiality of sensitive government data. The agency will instead rely on on‑premises infrastructure and open‑source alternatives for the affected workloads.
Why it matters for trust and compliance
- This case underscores the need for a robust third‑party risk management program that continuously validates cloud‑provider controls, captures evidence of data‑location safeguards, and provides a defensible audit trail across frameworks such as NIST CSF 2.0.
- Demonstrates the importance of continuous monitoring of third‑party controls to prove data‑sovereignty compliance.
- Provides a concrete example of how documented vendor‑risk evidence supports audit readiness for government regulations.
Who is affected
Government agencies handling confidential citizen data Enterprises evaluating SaaS for critical workloads
Recommended actions
- Review cloud‑service contracts for data‑location and sovereign‑cloud clauses.
- Run a formal vendor‑risk assessment with continuous evidence collection.
- Record assessment results in a centralized Trust Center to streamline future audits.