Microsoft and Meta Shared Dutch Data With US Congress

The unauthorized transfer of Dutch civil servant records raises international questions regarding privacy and cross-border oversight.

Updated on Sept. 30, 2026 in Cybersecurity

Microsoft and Meta Shared Dutch Data With US Congress

Live Poll

Do you trust foreign technology companies to protect the privacy of your country's civil servants?

In August 2026, Microsoft and Meta transferred the personal data of Dutch civil servants to the US Congress judiciary committee. The affected public employees were not notified that their information had been shared with the foreign legislative body.

Why it matters

This incident highlights the friction between national data privacy standards in the Netherlands and the broad subpoena or information-gathering powers exercised by the US Congress. It underscores the challenges organizations face when balancing legal requests for data against the protection of sensitive personal records held by governments.

Microsoft and Meta facilitated the transfer of sensitive personal records to the US Congress judiciary committee without prior disclosure to the subjects. The event represents a direct bridge between private cloud or social data silos and foreign legislative oversight mechanisms.

The players

Microsoft

A multinational technology corporation providing cloud services and operating extensive global data infrastructure.

Meta

A technology company operating social media platforms and holding large-scale repositories of user data.

US Congress

The legislative branch of the United States government responsible for drafting laws and conducting oversight through its various committees.

The details

The companies transferred personal information directly to the US Congress judiciary committee, bypassing the data subjects who were never notified of the disclosure. This process utilized the internal mechanisms of these corporations to fulfill information requests, effectively moving private data from Dutch government-associated accounts into a foreign legislative repository. The action demonstrates the vulnerability of public sector records when managed by large, multinational technology platforms subject to external jurisdictional demands.

Timeline

  1. In August 2026, the Dutch state secretary met with the US ambassador to discuss the disclosures.

  2. A meeting with Meta representatives is scheduled to take place in autumn 2026.

The Tech Race

This disclosure highlights the fragility of existing protocols under the EU-US Data Privacy Framework. It follows a pattern where multinational tech platforms must navigate conflicting international legal standards for data sovereignty versus legislative authority.

Civil servants in the Netherlands whose data is hosted on platforms provided by major US tech companies face heightened exposure to foreign legal requests. There is currently no known path for these individuals to verify if their specific records were included in the transfer or to pursue independent remediation.

The takeaway

This event serves as a reminder that administrative data held by private firms is subject to complex, often opaque, cross-border legal obligations. Future policy updates regarding international data sharing agreements and the upcoming autumn 2026 meeting with Meta will be critical indicators of whether these practices face new restrictions.

Further reading

For broader trends on jurisdictional data disputes, visit the Cybersecurity section.

Source note: This article includes information reported by Telecompaper.

Live Poll

Do you trust foreign technology companies to protect the privacy of your country's civil servants?