{
 "jurisdiction_id": "NL",
 "jurisdiction": "Netherlands",
 "url": "https://dataprotection.gi/jurisdictions/netherlands/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 43,
  "sub_modules": 57,
  "source_register": 23
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/netherlands/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive, mature omnibus regime fully aligned with GDPR; UAVG implementation is policy-neutral with narrow, well-documented derogations.",
   "claims": [
    {
     "statement": "The Autoriteit Persoonsgegevens (AP), based in The Hague, is the Dutch national data protection supervisory authority designated under Article 51(1) GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/about-edpb/our-members_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Dutch GDPR Implementation Bill (UAVG) supplements the GDPR and is intended to implement it in a policy-neutral manner, continuing prior Dutch data protection law insofar as permitted by the GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dutch-government-introduces-gdpr-implementation-bill",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UAVG Article 2 provides that the Act and provisions based upon it apply to the processing of personal data wholly or partly by automated means and to processing that forms part of a filing system.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/dutch_general_general_data_protection_regulation_implemention_act.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The UAVG supplements GDPR with regard to personal data processed in the context of the activities of an establishment in the Netherlands, or related to offering goods/services to, or monitoring the behaviour of, individuals in the Netherlands.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dutch-government-introduces-gdpr-implementation-bill",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the pre-GDPR Dutch Data Protection Act, binding corporate rules were authorised via a Ministry of Justice and Security permit; the GDPR Implementation Bill was silent on transitional treatment, creating a risk that such permits would lapse unless the AP issued its own authorisation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dutch-government-introduces-gdpr-implementation-bill",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/netherlands/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and special-category framework is GDPR-aligned with well-documented, narrowly tailored Dutch derogations.",
   "claims": [
    {
     "statement": "Data controllers in the Netherlands may only process personal data where one of the GDPR Article 6 lawful bases applies, including consent, contractual necessity, legal obligation, vital interests, public-interest task, or legitimate interests.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under GDPR Article 8(1), processing of a child's data based on consent for direct offer of information-society services is lawful where the child is at least 16; below that age, parental/guardian consent is required, with Member States able to lower this to no less than 13.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/NL/TXT/HTML/?uri=CELEX%3A02016R0679-20160504",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Dutch GDPR Implementation Bill reiterates age 16 as the applicable threshold for Article 8 GDPR consent, matching the prior Dutch Data Protection Act age limit rather than exercising the option to lower it to 13.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dutch-government-introduces-gdpr-implementation-bill",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UAVG Chapter 3 provides generic exceptions (e.g., explicit consent) alongside specific per-category exceptions allowing defined controllers such as hospitals, schools and insurance companies to process special categories of data for defined purposes (identification, sick-leave management, benefits, pre-employment screening, crime prevention).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dutch-government-introduces-gdpr-implementation-bill",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UAVG Article 29 permits processing of biometric data for unique identification only where strictly necessary for authentication or security purposes, addressing a gap in GDPR Article 9 that otherwise lacked a workable workplace-biometrics exception.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "AP/EDPB",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/decisions/nl_2020-09-02_-_dpia_list_nl_sa_-_national_decision_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/netherlands/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Directly-effective GDPR rights regime, actively enforced by the AP against obstructive controller practices.",
   "claims": [
    {
     "statement": "The AP fined DPG Media Magazines €525,000 for infringing GDPR Article 12(2) by requiring individuals to upload a copy of their identity document before honouring access or erasure requests, without informing them they could redact data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "AP/EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/dutch-sa-fines-dpg-media-magazines-unnecessarily-requesting-copies-identity_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under GDPR Article 19, controllers must communicate any rectification, erasure or restriction of processing to each recipient to whom the data were disclosed, unless this proves impossible or involves disproportionate effort, and must inform the data subject of those recipients on request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/NL/TXT/HTML/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under GDPR Article 20, the data subject has the right to receive personal data provided to a controller in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance where technically feasible.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/NL/TXT/HTML/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 12(3) requires controllers to respond to data subject rights requests without undue delay and within one month of receipt, extendable by a further two months for complex or numerous requests, applying directly in the Netherlands.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/NL/TXT/HTML/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/netherlands/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Full GDPR accountability regime in force, reinforced by an AP-published DPIA trigger list and active enforcement on security/health-data handling.",
   "claims": [
    {
     "statement": "The AP's published DPIA list requires a mandatory data protection impact assessment for, among other things, large-scale and/or systematic monitoring of employee activity, covert camera surveillance for theft/fraud prevention, and large-scale processing for unique identification.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "AP/EDPB",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/decisions/nl_2020-09-02_-_dpia_list_nl_sa_-_national_decision_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB's 2023 Coordinated Enforcement Framework action, in which the AP participates as an EEA supervisory authority, focused specifically on the designation and positioning of Data Protection Officers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dutch-dpa-publishes-gdpr-fining-structure/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The AP fined employer CP&A for security failings after its online sick-leave register, containing health data, was accessible without multi-factor authentication, finding that internet-accessible sick-leave systems require MFA beyond a regular login.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "AP/EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2021/dutch-dpa-cpa-receives-fine-violating-privacy-sick-employees-0_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under GDPR Article 33, controllers must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/2024-10/edpb_guidelines_202209_personal_data_breach_notification_v2.0_nl.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/netherlands/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Standard GDPR Chapter V transfer toolkit applies uniformly; no NL-specific localisation mandate identified.",
   "claims": [
    {
     "statement": "Cross-border transfers of personal data from the Netherlands to third countries rely on the GDPR Chapter V toolkit: European Commission adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, or Article 49 derogations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/NL/TXT/HTML/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB adopted opinions on the European Commission's draft decisions extending the validity of the UK adequacy decisions under the GDPR and the Law Enforcement Directive, an EU-wide determination that applies automatically in the Netherlands as an EU Member State.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/draft-uk-adequacy-decisions-edpb-adopts-opinions_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Binding Corporate Rules previously authorised under a Ministry of Justice and Security permit faced a risk of becoming null and void from 25 May 2018 unless the AP issued its own GDPR-era authorisation, as the GDPR Implementation Bill did not expressly address transitional treatment.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dutch-government-introduces-gdpr-implementation-bill",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/netherlands/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Telecoms/ePrivacy and employment overlays are well documented; credit-scoring and education sub-modules lack NL-specific findings.",
   "claims": [
    {
     "statement": "UAVG Chapter 3 provides sector-specific exceptions allowing hospitals, schools, and insurance companies to process special categories of personal data for defined purposes such as identification, sick-leave management, benefits/pensions, and pre-employment screening.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dutch-government-introduces-gdpr-implementation-bill",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Telecommunications Act (Telecommunicatiewet) is the primary legislation governing telecommunications in the Netherlands and includes a chapter on privacy transposing the ePrivacy Directive (2002/58/EC as amended).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/telecommunications-act.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The AP published a Works Council privacy booklet covering the right of consent and assessment questions for personnel-tracking systems, supporting Works Councils in evaluating whether employer monitoring plans are GDPR-compliant.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/netherlands-ap-publishes-works-councils-privacy-booklet",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/netherlands/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie and direct-marketing rules are well documented; dark-pattern, opt-out-signal, clean-room and cross-context-advertising sub-modules lack NL-specific findings.",
   "claims": [
    {
     "statement": "The confidentiality-of-terminal-equipment rule transposed into Dutch law from the ePrivacy Directive is technology-neutral, meaning user consent (or an applicable exception) is required not only for cookies but for any tracking technology accessing or storing information on a device.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_statement_on_eprivacy_nl.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Prior to a 1 July 2021 amendment to the Telecommunications Act, telemarketing calls to natural persons operated on an opt-out basis; this was replaced with an opt-in consent requirement and the do-not-call register is no longer used.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/netherlands-amendments-made-dutch-telecommunication",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/netherlands/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric and profiling rules are well established under GDPR/UAVG; AI Act competent-authority designation and NL-specific AI risk-assessment interplay is still maturing as of the 2 August 2026 application date.",
   "claims": [
    {
     "statement": "The EDPB adopted an opinion on the use of personal data for the development and deployment of AI models, confirming that GDPR principles apply to and support responsible AI governance.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/edpb-opinion-on-ai-models-gdpr-principles-support-responsible-ai_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EU AI Act applies from 2 August 2026, with certain provisions (prohibitions, definitions, AI-literacy obligations) already effective since 2 February 2025 and governance-structure, sanctions, and GPAI-provider rules effective since 2 August 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/NL/ALL/?uri=LEGISSUM:4762484",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UAVG Article 29 permits processing of biometric data for unique identification purposes only where strictly necessary for authentication or security, subject to additional conditions in Dutch implementing law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "AP/EDPB",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/decisions/nl_2020-09-02_-_dpia_list_nl_sa_-_national_decision_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The AP's DPIA list identifies large-scale and/or systematic use of flexible camera surveillance (e.g., body-worn cameras, dash cams) and large-scale processing enabling unique identification of individuals as mandatory-DPIA processing categories.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "AP/EDPB",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/decisions/nl_2020-09-02_-_dpia_list_nl_sa_-_national_decision_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Processing of personal data by competent authorities for the prevention, investigation, detection or prosecution of criminal offences is subject to the Law Enforcement Directive (2016/680) rather than the GDPR, and has been implemented in Dutch law and royal decrees governing investigation and prosecuting authorities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2019-global-legislative-predictions",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "green",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/netherlands/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Age-of-consent and parental-consent framework is clear and GDPR-aligned; a minor pending legislative refinement does not affect current binding status.",
   "claims": [
    {
     "statement": "Data controllers must take reasonable efforts, using available technology, to verify that a person consenting on behalf of a child under the applicable age threshold actually holds parental responsibility.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/NL/TXT/HTML/?uri=CELEX%3A02016R0679-20160504",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Children aged 16 and above may give their own consent for information-society-service processing in the Netherlands; for children below 16, consent must be obtained from the child's legal guardian or parent, consistent with the GDPR Article 8 default and reiterated in the UAVG.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dutch-government-introduces-gdpr-implementation-bill",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UAVG Chapter 3 exceptions extending to schools permit processing of certain special-category pupil data for defined educational purposes, alongside similar exceptions for hospitals and insurers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dutch-government-introduces-gdpr-implementation-bill",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under UAVG Article 5(2), if a data subject is under guardianship or subject to an administration or protection order, the consent of the legal representative is required instead of the data subject's own consent, to the extent the data subject lacks legal capacity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/dutch_general_general_data_protection_regulation_implemention_act.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/netherlands/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Mature, actively used enforcement toolkit with a published fining structure and recent illustrative decisions; collective-redress mechanism is narrower than the GDPR default option.",
   "claims": [
    {
     "statement": "The AP created a four-tiered penalty structure for GDPR infringements ranging from €0-200,000 (category one) up to €450,000-1,000,000 (category four), with higher fines available where a category-four penalty is deemed inappropriate.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dutch-dpa-publishes-gdpr-fining-structure/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The AP imposed a €525,000 fine on DPG Media Magazines B.V. for infringing GDPR Article 12(2) by unnecessarily requiring copies of identity documents from individuals exercising access and erasure rights.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "AP/EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/dutch-sa-fines-dpg-media-magazines-unnecessarily-requesting-copies-identity_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The AP fined employer CP&A for GDPR violations relating to insecure online processing of employees' sick-leave (health) data lacking multi-factor authentication.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "AP/EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2021/dutch-dpa-cpa-receives-fine-violating-privacy-sick-employees-0_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UAVG Article 11 requires the AP, as an independent non-departmental public body, to draw up its own draft budget subject to the Dutch non-departmental public bodies framework act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/dutch_general_general_data_protection_regulation_implemention_act.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Dutch GDPR Implementation Bill specifically prohibits collective actions proceeding against a data subject's will, requiring all data subjects whose data forms part of a contested processing operation to individually sign up for a collective action, meaning the Netherlands did not adopt the Article 80(2) GDPR opt-out mechanism.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dutch-government-introduces-gdpr-implementation-bill",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CJEU's judgment in Case C-245/20 (Autoriteit Persoonsgegevens), arising from a Dutch court reference, addressed the scope of AP supervisory competence under Article 55(3) GDPR over data processing by courts acting in their judicial capacity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:62020CC0245",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CJEU Grand Chamber issued its ruling of 10 February 2026 in WhatsApp Ireland Ltd v European Data Protection Board (Case C-97/23 P), concerning the reviewability under Article 263 TFEU of binding EDPB Article 65 dispute-resolution decisions arising from the one-stop-shop mechanism used against the Irish lead authority's draft WhatsApp decision.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62023CJ0097",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB, of which the AP is a member, adopted a statement on 17 July 2026 concerning data protection authorities' role in the EU AI Act framework, relevant to AP's interaction with AI Act competent authorities in the Netherlands.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/edpb-adopts-statement-on-dpas-role-in-ai-act-framework-eu-us-data-privacy-framework-faq-and_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}