Security2 distinct publishers3 min readPublished
Refusing a data demand becomes a criminal matter for Dutch companies and citizens, while the panel that reviews taps in advance shrinks, which changes the disclosure math for anyone hosting or peering in the Netherlands.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Defence minister Yesilgoz-Zegerius made the case in operational terms: Chinese operators run large digital infrastructure and switch servers quickly, and she wants safeguards organised differently so the services can act faster [11]. The change is in where authorisation attaches: it moves from the individual request to the adversary label, and that label covers countries such as China, Iran and Russia as well as organisations judged to undermine national security [7]. Once the label is applied, the specific server is no longer the thing anyone signs off.
The oversight side is countable. The two existing supervisory bodies merge into one College van Toetsing en Toezicht, the CTT [12]. The number of members involved in advance review drops from three to two, and the stated default is that one member reads the substance of a tap or hack request [13]. Three readers down to one is a two-thirds reduction in substantive advance review of the request that opens an operation [14]. Bert Hubert, a technical expert and former supervisor, told Volkskrant that the press material for the bill, to be called the Wet bescherming nationale veiligheid door de inlichtingen- en veiligheidsdiensten [3], sells reduced control as new safeguards from a new college, and that this is not sincere [17].
Reach widens on the other axis as well. The services will work more closely with the police, the armed forces, the tax service and the Dutch Financial Intelligence Unit [19], and they will be able to share data with private parties, a practice already running in the UK and the US and criticised in both for thin oversight [20]. Volkskrant's own reading is that more people end up as subjects of investigation [21].
Volkskrant and Risky Business leave open how the new tapping power treats traffic that crosses Dutch networks without terminating in the Netherlands, and whether collection at exchange points is in scope [23]. For an operator with Dutch peering and no Dutch legal entity, that is the entire question, and it stays unresolved in the published material. The compulsion power is clearer, because it names its subjects: Dutch companies and Dutch citizens [9], with data held by online platforms and financial institutions specified as obtainable [10].
Officials cited the threat of war with Russia and increasing aggressiveness from China and Iran as the reason for the overhaul [2], and the rewrite has company. Ireland passed a new lawful intercept law earlier this year, Germany is a few steps further into the same process, and France's version leans towards internal surveillance rather than foreign targets [22]. Splitting European infrastructure across jurisdictions is converging on one interception posture rather than hedging across several [25].
Ranked by verification strength, evidence, and original report placement.
The Dutch government has put forward a bill that would greatly expand the surveillance powers of AIVD, the domestic security and intelligence service, and MIVD, its military counterpart, with the main changes concerning surveillance and offensive hacking against countries designated as foreign adversaries.
Officials cited the threat of war with Russia and the increasing aggressiveness of countries like China and Iran as the main reason to overhaul the capabilities of AIVD and MIVD.
The bill is to be named the Wet bescherming nationale veiligheid door de inlichtingen- en veiligheidsdiensten.
At present the services must argue and submit for advance review every tap request and every hack.
Under current law, hacking operations require pre-deployment tests to prevent widespread disruptions.
Under the new bill, once an organisation is designated an adversary it can be followed and tapped in all sorts of ways for a period of one year without separate permission being required.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Encrypted DNS in Russia is now a reachability problem, not a privacy win3 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One newsroom read the bill; the other read that newsroom
Everything specific here — the one-year designation, the two unreviewed hacking stages, three reviewers becoming one substantive reader, the staatsnoodrecht carve-out — traces to de Volkskrant's account, with ministers quoted directly and a named former supervisor on the record. Risky Business says plainly that it is working from de Volkskrant and Bert Hubert. Nobody quotes the bill, its explanatory memorandum, or the press release both publishers criticise, so the provisions are well attributed but singly sourced.
Filed, not passed, in a region already legislating
This is a bill at the moment of tabling. There is no reported vote, committee stage or commencement date, no consultation response from a Dutch provider, and no company action anywhere in the coverage. What lifts the figure off the floor is context rather than Dutch progress: Ireland's intercept law is already through and Germany is further along, so the direction is being adopted in the neighbourhood even where this text has not moved.
Sober reporting, one detail widened in the retelling
Slightly overstated, and the overstatement is not the ministers'. de Volkskrant keeps the scope tight — the year of unpermissioned tapping follows a designation aimed at adversary states and organisations — while Risky Business renders it as tapping or following anyone for up to a year. In the other direction, the one claim being oversold by officials is caught in the coverage: Hubert's point that a new college is being marketed as new safeguards while review shrinks is the story's own correction.
Everybody here has a stake in the review question
The pressure behind this bill is documented, not inferred. de Volkskrant notes years of irritation inside the services at a pre-review procedure they considered slow and limiting, and the fix they get is fewer prior-permission situations and a single substantive reader. Ministers arrive with a threat narrative that makes speed the deciding value. The loudest critic is a former supervisor of the very body being merged away, which sharpens his read and also locates his interest. Risky Business carries a disclosed newsletter sponsor unrelated to the bill.
Firm on direction, unverified on wording
We are confident about where this goes — more powers, less advance review, criminal exposure for refusing a demand, an emergency valve with undefined triggers — because two publishers describe it consistently and ministers do not dispute the substance, only its characterisation. Confidence stops short of high because the wording that decides an operator's exposure has not been read by anyone we can point to, the scope of the tapping power differs between the two tellings, and nothing tells us whether this text is what parliament will vote on.