🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
NL · run data-protection-2026-08-03 v13-gdpri-1.0.0
content: ai_generated 23 sources retrieved model claude-sonnet-5 ·

Netherlands

NL schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 43 claims · 23 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
43Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, mature omnibus regime fully aligned with GDPR; UAVG implementation is policy-neutral with narrow, well-documented derogations.

Primary frameworkGDPR (Regulation (EU) 2016/679) as implemented by the Uitvoeringswet Algemene verordening gegevensbescherming (UAVG)
Traffic-light rationale — GreenComprehensive, mature omnibus regime fully aligned with GDPR; UAVG implementation is policy-neutral with narrow, well-documented derogations.

Sub-modules (5)

Regulator And AuthorityGreen

The AP is the Article 51(1) GDPR supervisory authority, established under UAVG Chapter 2, headquartered in The Hague, currently chaired by Aleid Wolfsen.

Claims: CLM-NL-a10f2b3c

Act And InstrumentsGreen

GDPR applies directly; UAVG supplements it in a policy-neutral manner, continuing pre-GDPR Dutch law insofar as permitted.

Claims: CLM-NL-b21e4d5f

Material ScopeGreen

UAVG Article 2 applies to processing wholly or partly by automated means and to non-automated processing forming part of a filing system, mirroring GDPR Article 2/4.

Claims: CLM-NL-c32f5e60

Territorial ScopeGreen

The UAVG/GDPR regime extends to controllers/processors established in NL and to non-established controllers offering goods/services to, or monitoring the behaviour of, individuals in NL.

Claims: CLM-NL-d43a6f71

Regulator Registration And FilingAmber

General notification duties were abolished under GDPR; a legacy Ministry-issued BCR permit regime was superseded by AP authorisation, with a risk of lapse absent timely AP action.

Claims: CLM-NL-e54b7082

Category narrative103 words

The Netherlands is an EU Member State operating under the GDPR as the omnibus instrument, implemented and supplemented domestically by the Uitvoeringswet Algemene verordening gegevensbescherming (UAVG). The Autoriteit Persoonsgegevens (AP), seated in The Hague, is the designated national supervisory authority under Article 51(1) GDPR. Material and territorial scope follow the GDPR text as implemented policy-neutrally by the UAVG, including extraterritorial reach to non-established controllers targeting NL data subjects or monitoring behaviour occurring in NL. General notification/registration to the AP was abolished under GDPR in favour of accountability (ROPA, DPIA); a legacy BCR-permit regime under the Minister of Justice was replaced by AP authorisation.

Sources and claims (5)
  1. ConfirmedEDPBThe Autoriteit Persoonsgegevens (AP), based in The Hague, is the Dutch national data protection supervisory authority designated under Article 51(1) GDPR.
  2. ConfirmedIAPPThe Dutch GDPR Implementation Bill (UAVG) supplements the GDPR and is intended to implement it in a policy-neutral manner, continuing prior Dutch data protection law insofar as permitted by the GDPR.
  3. ConfirmedDataGuidanceUAVG Article 2 provides that the Act and provisions based upon it apply to the processing of personal data wholly or partly by automated means and to processing that forms part of a filing system.
  4. ConfirmedIAPPThe UAVG supplements GDPR with regard to personal data processed in the context of the activities of an establishment in the Netherlands, or related to offering goods/services to, or monitoring the behaviour of, individuals in the Netherlands.
  5. ProbableIAPPUnder the pre-GDPR Dutch Data Protection Act, binding corporate rules were authorised via a Ministry of Justice and Security permit; the GDPR Implementation Bill was silent on transitional treatment, creating a risk that such permits would lapse unless the AP issued its own authorisation.

#

Core lawful-basis and special-category framework is GDPR-aligned with well-documented, narrowly tailored Dutch derogations.

Primary frameworkGDPR Articles 6, 7, 9 as supplemented by UAVG Chapter 3
Traffic-light rationale — GreenCore lawful-basis and special-category framework is GDPR-aligned with well-documented, narrowly tailored Dutch derogations.

Sub-modules (4)

Lawful BasesGreen

The six GDPR Article 6 lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests) apply directly and exhaustively in NL.

Claims: CLM-NL-f6509311

Special CategoriesAmber

UAVG Chapter 3 layers additional, sector-specific exceptions onto GDPR Article 9 for controllers such as hospitals, schools and insurers.

Claims: CLM-NL-29bd3c44

Pseudonymisation And AnonymisationAmber

Biometric data processing is restricted under UAVG Article 29 to cases of strict necessity for authentication or security purposes, addressing a gap left by the GDPR's blanket Article 9 prohibition.

Claims: CLM-NL-3ace4d55

Category narrative94 words

Lawful bases and consent standards follow GDPR Articles 6 and 7 directly. The Netherlands set the child consent age threshold for information-society-service consent at 16 (the GDPR default, not exercising the Member-State option to lower it to as little as 13). UAVG Chapter 3 supplies sector-specific exceptions permitting processing of special-category data (health, biometric, criminal) by defined controller categories (hospitals, schools, insurers) for defined purposes, and restricts biometric processing to strict necessity for authentication/security. A pending 'Data Protection Collective Act' bill would adjust several special-data and children's-consent provisions but is not yet in force.

Sources and claims (5)
  1. ConfirmedEDPBData controllers in the Netherlands may only process personal data where one of the GDPR Article 6 lawful bases applies, including consent, contractual necessity, legal obligation, vital interests, public-interest task, or legitimate interests.
  2. ConfirmedEUR-LexUnder GDPR Article 8(1), processing of a child's data based on consent for direct offer of information-society services is lawful where the child is at least 16; below that age, parental/guardian consent is required, with Member States able to lower this to no less than 13.
  3. ConfirmedIAPPThe Dutch GDPR Implementation Bill reiterates age 16 as the applicable threshold for Article 8 GDPR consent, matching the prior Dutch Data Protection Act age limit rather than exercising the option to lower it to 13.
  4. ConfirmedIAPPUAVG Chapter 3 provides generic exceptions (e.g., explicit consent) alongside specific per-category exceptions allowing defined controllers such as hospitals, schools and insurance companies to process special categories of data for defined purposes (identification, sick-leave management, benefits, pre-employment screening, crime prevention).
  5. ConfirmedAP/EDPBUAVG Article 29 permits processing of biometric data for unique identification only where strictly necessary for authentication or security purposes, addressing a gap in GDPR Article 9 that otherwise lacked a workable workplace-biometrics exception.

#

Directly-effective GDPR rights regime, actively enforced by the AP against obstructive controller practices.

Primary frameworkGDPR Articles 12-22
Traffic-light rationale — GreenDirectly-effective GDPR rights regime, actively enforced by the AP against obstructive controller practices.

Sub-modules (5)

Access RightGreen

Access rights follow GDPR Article 15; AP enforcement confirms controllers may not impose disproportionate identity-verification barriers (e.g., mandatory ID-copy uploads) on access/erasure requests.

Claims: CLM-NL-4bdf5e66

Rectification And ErasureGreen

Controllers must notify recipients of any rectification, erasure, or restriction under Article 19 GDPR unless impossible or disproportionate.

Claims: CLM-NL-5cea6f77

Restriction And ObjectionGreen

Restriction and objection rights follow GDPR Articles 18 and 21 directly with no NL-specific derogation identified.

Data PortabilityGreen

Portability follows GDPR Article 20, applying where processing is based on consent or contract and carried out by automated means.

Claims: CLM-NL-6dfb7088

Deadlines And Response WindowsGreen

Controllers must respond to data subject requests without undue delay and within one month, extendable by two further months for complex/numerous requests, per GDPR Article 12(3).

Claims: CLM-NL-7e0c8199

Category narrative48 words

Data subject rights in NL derive directly from GDPR Chapter III (access, rectification, erasure, restriction, objection, portability) with no material Dutch derogation. AP enforcement practice (e.g., the DPG Media Magazines fine) illustrates active supervision of the access/erasure request process, specifically prohibiting disproportionate identity-verification demands that obstruct rights exercise.

Sources and claims (4)
  1. ConfirmedAP/EDPBThe AP fined DPG Media Magazines €525,000 for infringing GDPR Article 12(2) by requiring individuals to upload a copy of their identity document before honouring access or erasure requests, without informing them they could redact data.
  2. ConfirmedEUR-LexUnder GDPR Article 19, controllers must communicate any rectification, erasure or restriction of processing to each recipient to whom the data were disclosed, unless this proves impossible or involves disproportionate effort, and must inform the data subject of those recipients on request.
  3. ConfirmedEUR-LexUnder GDPR Article 20, the data subject has the right to receive personal data provided to a controller in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance where technically feasible.
  4. ConfirmedEUR-LexGDPR Article 12(3) requires controllers to respond to data subject rights requests without undue delay and within one month of receipt, extendable by a further two months for complex or numerous requests, applying directly in the Netherlands.

#

Full GDPR accountability regime in force, reinforced by an AP-published DPIA trigger list and active enforcement on security/health-data handling.

Primary frameworkGDPR Articles 24-39, UAVG, Works Councils Act (WOR) Article 27
Traffic-light rationale — GreenFull GDPR accountability regime in force, reinforced by an AP-published DPIA trigger list and active enforcement on security/health-data handling.

Sub-modules (7)

Accountability And DpiaGreen

The AP has published a binding national list of processing operations requiring a DPIA, including large-scale/systematic employee monitoring, covert camera surveillance for fraud prevention, and large-scale biometric identification.

Claims: CLM-NL-8f1d9200

Dpo RequirementsGreen

DPO appointment follows GDPR Article 37 thresholds (public authorities, large-scale monitoring, large-scale special-category processing); DPO positioning was the subject of a 2023 EDPB coordinated enforcement action in which the AP participated.

Claims: CLM-NL-9020a311

Ropa RequirementsGreen

Controllers and processors must maintain records of processing activities under GDPR Article 30; no NL-specific derogation identified for the general regime (a separate, distinct ROPA duty exists under the Law Enforcement Directive regime for police data, outside this baseline's GDPR scope).

Joint Controller ArrangementsGreen

Joint-controller arrangements follow GDPR Article 26 directly; no NL-specific overlay identified.

Absence provenance: not recorded. Searched: UAVG joint controller provisions, AP guidance joint controllers.

Security MeasuresAmber

Security-of-processing obligations under GDPR Article 32 are actively enforced; the AP fined an employer for maintaining an internet-accessible sick-leave register without multi-factor authentication.

Claims: CLM-NL-a131b422

Breach NotificationGreen

Breach notification duties follow GDPR Articles 33-34: notify the AP within 72 hours of becoming aware unless unlikely to result in risk, and notify affected individuals without undue delay where high risk is likely.

Claims: CLM-NL-b242c533

Retention And DisposalAmber

Retention limitation follows the GDPR storage-limitation principle (Article 5(1)(e)); no NL-specific statutory retention schedule identified at the omnibus level beyond sectoral rules.

Absence provenance: not recorded. Searched: UAVG retention schedule, AP retention guidance.

Category narrative75 words

Controllers and processors are subject to the full GDPR accountability toolkit. The AP has published a binding national DPIA 'blacklist' identifying processing types requiring a mandatory DPIA (large-scale employee monitoring, covert camera surveillance, large-scale biometric identification). Breach notification follows GDPR Articles 33-34 (72-hour regulator notification; subject notification where high risk). AP enforcement demonstrates active supervision of security-of-processing duties for sensitive employee health data, and Dutch Works Councils hold a statutory co-determination right over personnel-monitoring systems.

Sources and claims (4)
  1. ConfirmedAP/EDPBThe AP's published DPIA list requires a mandatory data protection impact assessment for, among other things, large-scale and/or systematic monitoring of employee activity, covert camera surveillance for theft/fraud prevention, and large-scale processing for unique identification.
  2. ConfirmedIAPPThe EDPB's 2023 Coordinated Enforcement Framework action, in which the AP participates as an EEA supervisory authority, focused specifically on the designation and positioning of Data Protection Officers.
  3. ConfirmedAP/EDPBThe AP fined employer CP&A for security failings after its online sick-leave register, containing health data, was accessible without multi-factor authentication, finding that internet-accessible sick-leave systems require MFA beyond a regular login.
  4. ConfirmedEDPBUnder GDPR Article 33, controllers must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

#

Standard GDPR Chapter V transfer toolkit applies uniformly; no NL-specific localisation mandate identified.

Primary frameworkGDPR Articles 44-49
Traffic-light rationale — GreenStandard GDPR Chapter V transfer toolkit applies uniformly; no NL-specific localisation mandate identified.

Sub-modules (6)

Transfer MechanismsGreen

Transfers rely on Commission adequacy decisions, SCCs, BCRs, or Article 49 derogations, applying directly under GDPR Chapter V.

Claims: CLM-NL-c353d644

Adequacy ReceivedGreen

As an EU Member State, NL does not receive bilateral adequacy from third countries; it operates within the EU's mutual-recognition (GDPR-internal) framework rather than a receiving-adequacy structure.

Absence provenance: not recorded. Searched: Netherlands adequacy received from third country.

Adequacy GrantedGreen

Adequacy decisions granted to third countries (e.g., the UK) are adopted at EU level by the European Commission and apply automatically in NL; the UK adequacy decisions are currently under an EDPB-reviewed extension process.

Claims: CLM-NL-d464e755

Sccs And BcrsAmber

BCR authorisation in NL transitioned from a Ministry of Justice permit system to AP approval under GDPR; legacy permits faced a risk of lapse absent timely AP authorisation.

Claims: CLM-NL-e575f866

Transfer Impact AssessmentAmber

TIA obligations follow the EDPB's general post-Schrems II recommendations, applied by the AP as an EEA authority; no NL-specific TIA methodology beyond EDPB guidance was identified.

Absence provenance: not recorded. Searched: AP transfer impact assessment guidance Netherlands.

Data LocalisationRed

No general data-localisation mandate exists in the Dutch omnibus DP regime.

Absence provenance: not recorded. Searched: Netherlands data localisation requirement GDPR, UAVG data localisation.

Category narrative63 words

As an EU Member State, NL's cross-border transfer regime is governed directly by GDPR Chapter V: adequacy decisions issued by the European Commission apply uniformly across the EU including NL (e.g., ongoing extension of UK adequacy), alongside SCCs, BCRs and Article 49 derogations. The pre-GDPR Ministerial BCR-permit system was replaced by AP authorisation. No general data-localisation mandate exists in the Dutch omnibus regime.

Sources and claims (3)
  1. ConfirmedEUR-LexCross-border transfers of personal data from the Netherlands to third countries rely on the GDPR Chapter V toolkit: European Commission adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, or Article 49 derogations.
  2. ProbableEDPBThe EDPB adopted opinions on the European Commission's draft decisions extending the validity of the UK adequacy decisions under the GDPR and the Law Enforcement Directive, an EU-wide determination that applies automatically in the Netherlands as an EU Member State.
  3. ProbableIAPPBinding Corporate Rules previously authorised under a Ministry of Justice and Security permit faced a risk of becoming null and void from 25 May 2018 unless the AP issued its own GDPR-era authorisation, as the GDPR Implementation Bill did not expressly address transitional treatment.

#

Telecoms/ePrivacy and employment overlays are well documented; credit-scoring and education sub-modules lack NL-specific findings.

Primary frameworkTelecommunicatiewet (transposing ePrivacy Directive 2002/58/EC); UAVG Chapter 3; Works Councils Act (WOR)
Traffic-light rationale — AmberTelecoms/ePrivacy and employment overlays are well documented; credit-scoring and education sub-modules lack NL-specific findings.

Sub-modules (7)

Financial Sector OverlayAmber

No NL-specific financial-sector DP overlay beyond general GDPR/UAVG was surfaced in this run; AFM/DNB prudential rules interact with but do not supplant AP jurisdiction over personal data.

Absence provenance: not recorded. Searched: Netherlands financial sector data protection overlay AFM DNB GDPR.

Health Sector OverlayGreen

UAVG Chapter 3 grants hospitals and other health controllers specific exceptions to process special-category health data for defined purposes.

Claims: CLM-NL-f686007

Telecoms And EprivacyGreen

The Telecommunicatiewet transposes the ePrivacy Directive, including cookie-consent and confidentiality-of-communications rules.

Claims: CLM-NL-07971188

Employment DataAmber

Dutch Works Councils hold a statutory co-determination/consent right over the introduction of personnel-tracking and monitoring systems, and the AP publishes guidance to support Works Councils in assessing GDPR-compliance of such systems.

Claims: CLM-NL-18a82299

Credit And ScoringRed

No NL-specific credit-scoring overlay was identified in this run beyond general GDPR Article 22 automated-decision-making protections.

Absence provenance: not recorded. Searched: Netherlands credit scoring data protection BKR GDPR.

EducationRed

No NL-specific education-sector DP statute distinct from UAVG general exceptions was identified.

Absence provenance: not recorded. Searched: Netherlands education sector data protection overlay UAVG.

InsuranceGreen

UAVG Chapter 3 grants insurance companies specific exceptions to process special-category data for underwriting and claims purposes.

Claims: CLM-NL-f686007

Category narrative69 words

Telecommunications and electronic-communications processing is governed by the Telecommunicatiewet, transposing the ePrivacy Directive, including the cookie-consent rule and a July 2021 shift to opt-in consent for telemarketing to natural persons (abolishing the do-not-call register). Employment-sector processing is subject to Works Council co-determination rights over personnel-monitoring/tracking systems. Health and insurance sectors benefit from UAVG special-category exceptions. No NL-specific credit-scoring or education-sector DP overlay was identified beyond the general GDPR/UAVG regime.

Sources and claims (3)
  1. ConfirmedIAPPUAVG Chapter 3 provides sector-specific exceptions allowing hospitals, schools, and insurance companies to process special categories of personal data for defined purposes such as identification, sick-leave management, benefits/pensions, and pre-employment screening.
  2. ConfirmedDataGuidanceThe Telecommunications Act (Telecommunicatiewet) is the primary legislation governing telecommunications in the Netherlands and includes a chapter on privacy transposing the ePrivacy Directive (2002/58/EC as amended).
  3. ConfirmedDataGuidanceThe AP published a Works Council privacy booklet covering the right of consent and assessment questions for personnel-tracking systems, supporting Works Councils in evaluating whether employer monitoring plans are GDPR-compliant.

#

Cookie and direct-marketing rules are well documented; dark-pattern, opt-out-signal, clean-room and cross-context-advertising sub-modules lack NL-specific findings.

Primary frameworkTelecommunicatiewet (ePrivacy transposition); GDPR
Traffic-light rationale — AmberCookie and direct-marketing rules are well documented; dark-pattern, opt-out-signal, clean-room and cross-context-advertising sub-modules lack NL-specific findings.

Sub-modules (6)

Cookies And TrackersGreen

Prior informed consent is required before storing or accessing information on a user's device, applying technology-neutrally to any tracking technology, not solely cookies.

Claims: CLM-NL-299a33aa

Dark PatternsRed

No NL-specific dark-pattern prohibition distinct from EU-level DSA/GDPR interplay guidelines was surfaced.

Absence provenance: not recorded. Searched: Netherlands dark patterns cookie consent AP guidance.

Opt Out SignalsRed

No NL-specific recognition of browser-level opt-out signals (e.g., Global Privacy Control) was identified.

Absence provenance: not recorded. Searched: Netherlands Global Privacy Control AP recognition.

Clean Rooms And DcrRed

No NL-specific data clean-room regulatory framework was identified.

Absence provenance: not recorded. Searched: Netherlands data clean room regulation AP.

Cross Context AdvertisingAmber

No NL-specific 'sale'/'share' construct analogous to US state law exists; cross-context advertising is governed by GDPR consent/legitimate-interest analysis and the ePrivacy cookie rule.

Absence provenance: not recorded. Searched: Netherlands cross-context advertising GDPR ePrivacy.

Direct MarketingGreen

Telemarketing to natural persons requires opt-in consent since 1 July 2021; the do-not-call register was discontinued.

Claims: CLM-NL-3aab44bb

Category narrative64 words

The Telecommunicatiewet's cookie-consent rule requires prior, informed consent before storing or accessing information on a user's terminal equipment, applying technology-neutrally to all tracking technologies, not only cookies. Since 1 July 2021, telemarketing to natural persons requires opt-in consent, replacing the prior opt-out/do-not-call regime. NL-specific findings on dark patterns, opt-out signals, clean rooms, and cross-context advertising were not surfaced beyond general EU-level DSA/GDPR interplay guidance.

Sources and claims (2)
  1. ConfirmedEDPBThe confidentiality-of-terminal-equipment rule transposed into Dutch law from the ePrivacy Directive is technology-neutral, meaning user consent (or an applicable exception) is required not only for cookies but for any tracking technology accessing or storing information on a device.
  2. ConfirmedDataGuidancePrior to a 1 July 2021 amendment to the Telecommunications Act, telemarketing calls to natural persons operated on an opt-out basis; this was replaced with an opt-in consent requirement and the do-not-call register is no longer used.

#

Biometric and profiling rules are well established under GDPR/UAVG; AI Act competent-authority designation and NL-specific AI risk-assessment interplay is still maturing as of the 2 August 2026 application date.

Primary frameworkGDPR Article 22; UAVG Article 29; EU AI Act (Regulation (EU) 2024/1689); Law Enforcement Directive (2016/680)
Traffic-light rationale — AmberBiometric and profiling rules are well established under GDPR/UAVG; AI Act competent-authority designation and NL-specific AI risk-assessment interplay is still maturing as of the 2 August 2026 application date.

Sub-modules (6)

Profiling RestrictionsGreen

Profiling restrictions follow GDPR Article 22 directly; the EDPB has issued an opinion confirming GDPR principles govern personal data use in AI model development and deployment.

Claims: CLM-NL-4bbc55cc

Automated Decision Making TransparencyGreen

ADM transparency follows GDPR Articles 13-15/22 directly; no NL-specific derogation identified.

Ai Risk AssessmentsAmber

The EU AI Act applies from 2 August 2026, with governance, sanctions, and GPAI-provider obligations already in force since August 2025 and AI-literacy obligations since February 2025; national competent authority designation interacts with the AP's data-protection remit.

Claims: CLM-NL-5ccd66dd

Biometric RegimeGreen

Biometric data processing for unique identification is prohibited absent strict necessity for authentication/security, per UAVG Article 29; the AP's DPIA list separately mandates DPIAs for large-scale biometric identification and flexible camera surveillance.

Claims: CLM-NL-6dde77ee, CLM-NL-7eef88ff

Genetic DataAmber

Genetic data is a GDPR Article 9 special category; no NL-specific overlay beyond UAVG's general special-category exceptions was surfaced.

Absence provenance: not recorded. Searched: UAVG genetic data specific exception Netherlands.

State Surveillance CarveoutsAmber

Law-enforcement and state-security processing is carved out of GDPR and governed instead by the Law Enforcement Directive (2016/680), implemented in Dutch law via police-data legislation and royal decrees.

Claims: CLM-NL-8ff099aa

Category narrative101 words

Profiling and automated-decision-making are governed by GDPR Article 22, with EDPB opinion clarifying GDPR principles' application to AI model development/deployment. The EU AI Act (Regulation (EU) 2024/1689) applies from 2 August 2026 (with earlier partial application from February and August 2025), requiring Member State designation of competent authorities, some of which may coordinate with the AP on data-protection-adjacent obligations. Biometric data is restricted under UAVG Article 29 to strict-necessity authentication/security use, and the AP's DPIA list mandates impact assessments for large-scale biometric identification and flexible camera surveillance. Law-enforcement processing sits under the separate Law Enforcement Directive (2016/680) regime rather than GDPR/UAVG.

Sources and claims (5)
  1. ConfirmedEDPBThe EDPB adopted an opinion on the use of personal data for the development and deployment of AI models, confirming that GDPR principles apply to and support responsible AI governance.
  2. ConfirmedEUR-LexThe EU AI Act applies from 2 August 2026, with certain provisions (prohibitions, definitions, AI-literacy obligations) already effective since 2 February 2025 and governance-structure, sanctions, and GPAI-provider rules effective since 2 August 2025.
  3. ConfirmedAP/EDPBUAVG Article 29 permits processing of biometric data for unique identification purposes only where strictly necessary for authentication or security, subject to additional conditions in Dutch implementing law.
  4. ConfirmedAP/EDPBThe AP's DPIA list identifies large-scale and/or systematic use of flexible camera surveillance (e.g., body-worn cameras, dash cams) and large-scale processing enabling unique identification of individuals as mandatory-DPIA processing categories.
  5. ConfirmedIAPPProcessing of personal data by competent authorities for the prevention, investigation, detection or prosecution of criminal offences is subject to the Law Enforcement Directive (2016/680) rather than the GDPR, and has been implemented in Dutch law and royal decrees governing investigation and prosecuting authorities.

#

Age-of-consent and parental-consent framework is clear and GDPR-aligned; a minor pending legislative refinement does not affect current binding status.

Primary frameworkGDPR Article 8; UAVG Article 5
Traffic-light rationale — GreenAge-of-consent and parental-consent framework is clear and GDPR-aligned; a minor pending legislative refinement does not affect current binding status.

Sub-modules (5)

Age VerificationGreen

Controllers must make reasonable efforts, given available technology, to verify that parental/guardian consent has been given for children under 16.

Claims: CLM-NL-9001aabb

Minor Profiling BansAmber

No NL-specific blanket ban on profiling of minors distinct from GDPR Article 22/Recital 71 general caution was identified.

Absence provenance: not recorded. Searched: Netherlands minor profiling ban AP guidance.

Education SettingsAmber

UAVG special-category exceptions extend to schools processing pupil data for defined educational purposes; no separate education-specific DP statute was identified.

Claims: CLM-NL-b223ccdd

Dependent AdultsGreen

UAVG Article 5 requires the consent of a legal representative instead of the data subject where the data subject is under guardianship or subject to an administration or protection order and lacks legal capacity to consent.

Claims: CLM-NL-c334ddee

Category narrative71 words

The Netherlands applies the GDPR default age of 16 for information-society-service consent (Article 8), requiring verifiable parental/guardian consent below that age, with controllers expected to make reasonable efforts to verify parental authority given available technology. UAVG Article 5 extends analogous legal-representative consent requirements to adults under guardianship or subject to an administration/protection order. A pending Dutch bill (Data Protection Collective Act) would adjust children's-data consent provisions but is not yet enacted.

Sources and claims (4)
  1. ConfirmedEUR-LexData controllers must take reasonable efforts, using available technology, to verify that a person consenting on behalf of a child under the applicable age threshold actually holds parental responsibility.
  2. ConfirmedIAPPChildren aged 16 and above may give their own consent for information-society-service processing in the Netherlands; for children below 16, consent must be obtained from the child's legal guardian or parent, consistent with the GDPR Article 8 default and reiterated in the UAVG.
  3. ProbableIAPPUAVG Chapter 3 exceptions extending to schools permit processing of certain special-category pupil data for defined educational purposes, alongside similar exceptions for hospitals and insurers.
  4. ConfirmedDataGuidanceUnder UAVG Article 5(2), if a data subject is under guardianship or subject to an administration or protection order, the consent of the legal representative is required instead of the data subject's own consent, to the extent the data subject lacks legal capacity.

#

Mature, actively used enforcement toolkit with a published fining structure and recent illustrative decisions; collective-redress mechanism is narrower than the GDPR default option.

Primary frameworkGDPR Articles 58, 77-84; UAVG
Traffic-light rationale — GreenMature, actively used enforcement toolkit with a published fining structure and recent illustrative decisions; collective-redress mechanism is narrower than the GDPR default option.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The AP published a four-category fining structure with monetary ranges from €0 up to €1,000,000 per infringement category, escalating for category-four offences deemed inadequate.

Claims: CLM-NL-d445eeff

Enforcement Activity IndexGreen

Illustrative recent enforcement includes the €525,000 DPG Media Magazines fine and the CP&A employee-health-data security fine.

Claims: CLM-NL-e556ff00, CLM-NL-f6670011

Regulator Funding And CapacityAmber

No specific NL AP budget/headcount figures were surfaced in this run; the AP operates as an independent non-departmental public body under UAVG Article 11 budgeting provisions.

Absence provenance: not recorded. Searched: Autoriteit Persoonsgegevens jaarverslag 2025 budget capacity.

Claims: CLM-NL-0778a022

Collective Redress And Class ActionsAmber

The Netherlands declined to adopt the GDPR Article 80(2) opt-out mechanism, instead requiring all affected data subjects to individually opt in for their data to be submitted as evidence in a collective action.

Claims: CLM-NL-1889b133

Private Right Of ActionGreen

Data subjects retain the GDPR Article 78/79 right to an effective judicial remedy against both supervisory-authority decisions and controllers/processors directly before Dutch courts.

Claims: CLM-NL-299ac244

Recent Developments 180DGreen

Within the relevant window, the CJEU's Grand Chamber ruling of 10 February 2026 in WhatsApp Ireland v EDPB (C-97/23 P) addressed judicial review of EDPB binding Article 65 decisions arising from one-stop-shop disputes, relevant to Dutch controllers subject to lead-authority decisions; the EDPB also adopted a statement on DPAs' role in the AI Act framework (17 July 2026).

Claims: CLM-NL-3aabd355, CLM-NL-4bbce466

Category narrative125 words

The AP exercises the full GDPR Article 58 investigative and corrective toolkit and has published a four-tier fining structure ranging up to €1,000,000 per category (with higher fines possible where deemed appropriate). Enforcement examples include the €525,000 DPG Media Magazines fine (Article 12(2) transparency) and the CP&A fine for insecure health-data processing. NL notably declined to adopt the GDPR Article 80(2) opt-out collective-action mechanism, requiring data subjects to individually opt in to collective privacy actions. The CJEU's 2022 ruling in Case C-245/20 clarified limits on AP jurisdiction over courts acting in their judicial capacity, and the Court's 2026 WhatsApp v EDPB ruling (C-97/23 P) addressed challengeability of EDPB binding decisions within the one-stop-shop mechanism, both bearing on Dutch enforcement practice as an EU Member State.

Sources and claims (8)
  1. ConfirmedIAPPThe AP created a four-tiered penalty structure for GDPR infringements ranging from €0-200,000 (category one) up to €450,000-1,000,000 (category four), with higher fines available where a category-four penalty is deemed inappropriate.
  2. ConfirmedAP/EDPBThe AP imposed a €525,000 fine on DPG Media Magazines B.V. for infringing GDPR Article 12(2) by unnecessarily requiring copies of identity documents from individuals exercising access and erasure rights.
  3. ConfirmedAP/EDPBThe AP fined employer CP&A for GDPR violations relating to insecure online processing of employees' sick-leave (health) data lacking multi-factor authentication.
  4. ProbableDataGuidanceUAVG Article 11 requires the AP, as an independent non-departmental public body, to draw up its own draft budget subject to the Dutch non-departmental public bodies framework act.
  5. ConfirmedIAPPThe Dutch GDPR Implementation Bill specifically prohibits collective actions proceeding against a data subject's will, requiring all data subjects whose data forms part of a contested processing operation to individually sign up for a collective action, meaning the Netherlands did not adopt the Article 80(2) GDPR opt-out mechanism.
  6. ConfirmedEUR-LexThe CJEU's judgment in Case C-245/20 (Autoriteit Persoonsgegevens), arising from a Dutch court reference, addressed the scope of AP supervisory competence under Article 55(3) GDPR over data processing by courts acting in their judicial capacity.
  7. ConfirmedEUR-LexThe CJEU Grand Chamber issued its ruling of 10 February 2026 in WhatsApp Ireland Ltd v European Data Protection Board (Case C-97/23 P), concerning the reviewability under Article 263 TFEU of binding EDPB Article 65 dispute-resolution decisions arising from the one-stop-shop mechanism used against the Irish lead authority's draft WhatsApp decision.
  8. ConfirmedEDPBThe EDPB, of which the AP is a member, adopted a statement on 17 July 2026 concerning data protection authorities' role in the EU AI Act framework, relevant to AP's interaction with AI Act competent authorities in the Netherlands.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Netherlands
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 43 claim(s), 23 source(s) in the cumulative register.