Microsoft and Meta Shared Dutch Data With US Congress
The companies provided personal details of Dutch civil servants to a US Congressional committee without notification.
Updated on Sept. 30, 2026 in Cybersecurity

Live Poll
Do you trust foreign technology companies to protect the privacy of your country's civil servants?
Microsoft and Meta transferred the personal information of Dutch civil servants to the US Congress judiciary committee. The affected employees were not notified that their data had been shared with American lawmakers.
Why it matters
The unauthorized transfer of state employee data raises significant questions regarding international data privacy and the oversight of cross-border information sharing. This incident has prompted direct diplomatic engagement between Dutch officials and American representatives.
The incident involved the direct transfer of personal data sets from tech giants to a foreign legislative body. The extent of the information shared remains under internal investigation as officials address the lack of transparency.
The players
Microsoft
Microsoft is a global technology corporation that provides software, services, and hardware solutions.
Meta
Meta is a technology conglomerate that owns and operates major social media platforms and digital communication services.
US Congress
The US Congress is the bicameral legislative branch of the federal government responsible for national policy and oversight.
The details
Microsoft and Meta facilitated the movement of personal data to the US Congress judiciary committee. The Netherlands-based civil servants involved in the incident received no prior notification or warning that their private information would be disclosed to international lawmakers.
Timeline
In August 2026, the Dutch state secretary met with the US ambassador regarding the matter.
A meeting with Meta representatives is planned for autumn 2026.
The Tech Race
The transfer of data by Microsoft and Meta highlights potential friction with the General Data Protection Regulation regarding the handling of European citizens' personal information by non-EU entities. This event marks a potential challenge to the data privacy protections established by that framework.
This incident underscores the risks inherent in how tech platforms manage and share user data across national jurisdictions. Users and employees should remain vigilant about their data privacy settings, as personal information can move across borders without direct user notification.
The takeaway
Maintaining awareness of data privacy policies is essential as personal information remains subject to various international oversight frameworks. Individuals should regularly review their digital footprint on platforms that interact with global legislative bodies.
What happens next
The Dutch state secretary is scheduled to hold a meeting with representatives from Meta during the autumn of 2026 to discuss the unauthorized data transfer.
Further reading
For more information on the evolving landscape of digital privacy, visit our Cybersecurity section.
Source note: This article includes information reported by Telecompaper.
Live Poll
Do you trust foreign technology companies to protect the privacy of your country's civil servants?







