European Security — 2026-05-24
Microsoft and Meta Shared Names of Dutch Civil Servants and Scientists With US Senate Committee Investigating Tech Regulation
BLUFFormal action against Microsoft or Meta is very unlikely within three months of the May disclosure, but the lasting damage is Dutch regulators retreating to anonymized communications that will erode DSA enforcement transparency.
Vrij Nederland reported on May 22 that Microsoft and Meta shared names of Dutch civil servants and academics with a US congressional committee investigating "tech censorship" 1NOS" data-url="https://nos.nl/l/2615391" data-otype="broadcaster">23. Dutch-language primary sources, including Villamedia, NOS, and Binnenlands Bestuur, consistently identify the receiving body as the US House of Representatives ("Huis van Afgevaardigden"), lending stronger weight to NL Times' identification over the "Senate" framing used by English-language outlets such as DutchNews.nl, though the discrepancy remains formally unresolved 4. Named individuals include employees of the ACM and the Dutch Data Protection Authority who implement the Digital Services Act, as well as disinformation researcher Claes de Vreese; NOS reported the names surfaced in event invitations and meeting documents that the companies were legally required to share under the US Cloud Act 234. State Secretary Willemijn Aerdts said she raised the matter directly with US Ambassador Joe Popolo and called the sharing "extremely undesirable" 234.
AnalysisA formal investigation specifically naming either company is
very unlikely within approximately three months, as both plausibly acted under Cloud Act legal compulsion. Low confidence reflects a single reporting chain, Vrij Nederland as sole primary source with NOS and NL Times providing secondary amplification without independent origination, and the unavailability of the underlying legal documents. If the transferred documents were publicly available event invitations, no protected personal data changed hands under GDPR, further narrowing legal exposure. ACM and Dutch Data Protection Authority staff are already shifting to anonymized communications, degrading the transparency DSA enforcement requires regardless of legal outcome. Whether any proceeding opens, EU institutions face a choice between pursuing GDPR-based remedies against Cloud Act compulsion or accelerating digital sovereignty investments.
4 sources
- Microsoft deelde namen van Nederlandse ambtenaren met Amerikaanse overheid - Vrij Nederland
- Microsoft and Meta shared names of Dutch officials with US Senate committee - NOS
- US tech firms share Dutch regulator officials' names with senate - DutchNews.nl
- Microsoft accused of leaking Dutch civil servants' names to U.S. government - NL Times
View in full brief →