Kyndryl/Solvinity: implications for FDI screening and competition

21 August 2026

On 25 May 2026, the State Secretary for the Digital Economy and Sovereignty blocked the proposed acquisition of Solvinity by US IT services provider Kyndryl. Although the Netherlands Authority for Consumers and Markets (ACM) had previously determined that the transaction did not raise competition law concerns, the Investment Screening Bureau (BTI) – which assesses the security risks of acquisitions on behalf of the State Secretary – found that the transaction nevertheless posed a risk to the public interest under Chapter 14a of the Telecommunications Act (Telecommunicatiewet).

One of the factors underlying the prohibition was that US legislation with extraterritorial effect may be used to require companies to provide information stored outside the United States. This was relevant because Solvinity, as a provider of critical and non-critical IT services to a large number of government clients, has access to personal and government data that is predominantly highly sensitive in nature.

Solvinity and its shareholder, Host Lux, lodged an objection to the prohibition order and requested the interim relief judge to suspend the order pending the decision on the objection, thus allowing the acquisition to still be completed. Although the interim relief judge rejected their application, he did provide further guidance on a number of key terms in the Telecommunications Act and set out points to note for the objection proceedings.

For companies operating in the fields of digital infrastructure, cloud and IT services, or handling sensitive government and personal data, the Kyndryl/Solvinity case highlights the fact that investment screening has become an independent and potentially deal-breaking factor. Even if a transaction does not raise any competition law concerns, it may still be blocked on national security or public interest grounds. Moreover, the ruling demonstrates that issues relating to digital sovereignty, foreign access to data and potential mitigating measures are increasingly influencing the assessment of acquisitions and investments.

Sector-specific investment screening: an exception to the rule

In the Netherlands, the vast majority of investment screening – more than 95% in 2025 – is carried out under the Investments, Mergers and Acquisitions (Security Screening) Act (Wet veiligheidstoets investeringen, fusies en overnames, Vifo Act). However, there are also a number of sector-specific investment screening regimes, including in Chapter 14a of the Telecommunications Act. The Vifo Act does not apply to investments that are screened under this sector-specific legislation. Furthermore, these regimes are based on a different assessment framework. Under the Telecommunications Act, the BTI assesses whether an investment could give rise to a “threat to the public interest”. Assessment under the Vifo Act, on the other hand, focuses on the question whether acquisition activity could pose a risk to national security.

A threat to the public interest within the meaning of Chapter 14a of the Telecommunications Act can only arise if an investment leads to “relevant influence in the telecommunications sector” and the acquirer also exhibits certain risk characteristics. According to the State Secretary, the latter condition was met in this case, partly because the potential application of US legislation with extraterritorial effect means that Kyndryl has close ties with, or is under the influence of, the United States.

Against this backdrop, it is striking that Solvinity and Kyndryl did not initially intend to notify the transaction. However, they ultimately did so following the BTI’s response to an earlier consultation request. The parties took the view that the transaction would not result in Kyndryl acquiring relevant influence in the telecommunications sector. Their reasoning was that Kyndryl had this influence anyway, since it already provides services to the Ministry of Defence. However, neither the BTI nor the interim relief judge accepted this argument. Although a consortium led by Kyndryl is currently constructing two data centres for the Ministry of Defence, these facilities will become the full property of the Ministry of Defence when completed. Consequently, Kyndryl is acting merely as a contractor in the project in question. In the event of any uncertainty regarding the notification obligation, parties would therefore be well advised to contact the BTI at an early stage, even on an informal basis.

Judicial guidelines for the objection procedure

Despite rejecting Solvinity and Host Lux’s application, the interim relief judge provided the State Secretary with a number of guidance notes which she must take into account in the parallel objection proceedings. In particular, the State Secretary will need to examine the feasibility of imposing a less stringent measure than a complete prohibition of the acquisition. The interim relief judge specifically referred to the possibility of fully encrypting the data and entrusting the key to the government or a third party. Such an arrangement could effectively keep the data beyond the reach of US data requests: after all, a European entity that stores the encrypted data but does not hold the key cannot provide that data to the US authorities in a readable form. Kyndryl, which has so far kept a notably low profile in the proceedings, may therefore need to become involved in the objection proceedings if its cooperation is required for any mitigating measures.

The preliminary relief proceedings once again highlight the growing importance of Dutch digital autonomy, and show that the courts grant the State Secretary a degree of discretion in assessing potential threats to the public interest. For M&A practitioners, the case also confirms that competition law clearance does not guarantee that the outcome of investment screening will be favourable. Companies wishing to minimise the risk of a prohibition would be well advised not only to point out their formal control structures, but also to address potential security risks by proposing concrete solutions at an early stage that are technically and organisationally practicable.