Microsoft reportedly shared sensitive internal emails from Dutch regulators with the U.S. House of Representatives, highlighting significant concerns regarding digital sovereignty and the reach of foreign legal jurisdictions.
Key Points
- Microsoft allegedly provided the U.S. House of Representatives with unredacted emails, meeting minutes, and contact information belonging to Dutch officials.
- The affected Dutch civil servants were actively involved in enforcing the European Union’s Digital Services Act, which regulates major technology platforms.
- The incident underscores how the U.S. CLOUD Act allows American authorities to compel data disclosure from U.S.-based providers regardless of where the information is physically stored.
- Experts distinguish between data residency, which refers to storage location, and digital sovereignty, which concerns legal control and the authority to grant or deny access.
- The event has prompted calls for public institutions to implement stricter controls over encryption keys, audit trails, and disclosure processes to prevent jurisdictional leakage.