Traffic-light rationale — GreenComprehensive, mature omnibus regime fully aligned with GDPR; UAVG implementation is policy-neutral with narrow, well-documented derogations.
Sub-modules (5)
Regulator And AuthorityGreen
The AP is the Article 51(1) GDPR supervisory authority, established under UAVG Chapter 2, headquartered in The Hague, currently chaired by Aleid Wolfsen.
Claims: CLM-NL-a10f2b3c
Act And InstrumentsGreen
GDPR applies directly; UAVG supplements it in a policy-neutral manner, continuing pre-GDPR Dutch law insofar as permitted.
Claims: CLM-NL-b21e4d5f
Material ScopeGreen
UAVG Article 2 applies to processing wholly or partly by automated means and to non-automated processing forming part of a filing system, mirroring GDPR Article 2/4.
Claims: CLM-NL-c32f5e60
Territorial ScopeGreen
The UAVG/GDPR regime extends to controllers/processors established in NL and to non-established controllers offering goods/services to, or monitoring the behaviour of, individuals in NL.
Claims: CLM-NL-d43a6f71
Regulator Registration And FilingAmber
General notification duties were abolished under GDPR; a legacy Ministry-issued BCR permit regime was superseded by AP authorisation, with a risk of lapse absent timely AP action.
Claims: CLM-NL-e54b7082
Category narrative103 words
The Netherlands is an EU Member State operating under the GDPR as the omnibus instrument, implemented and supplemented domestically by the Uitvoeringswet Algemene verordening gegevensbescherming (UAVG). The Autoriteit Persoonsgegevens (AP), seated in The Hague, is the designated national supervisory authority under Article 51(1) GDPR. Material and territorial scope follow the GDPR text as implemented policy-neutrally by the UAVG, including extraterritorial reach to non-established controllers targeting NL data subjects or monitoring behaviour occurring in NL. General notification/registration to the AP was abolished under GDPR in favour of accountability (ROPA, DPIA); a legacy BCR-permit regime under the Minister of Justice was replaced by AP authorisation.
Sources and claims (5)
ConfirmedEDPB — The Autoriteit Persoonsgegevens (AP), based in The Hague, is the Dutch national data protection supervisory authority designated under Article 51(1) GDPR.
ConfirmedIAPP — The Dutch GDPR Implementation Bill (UAVG) supplements the GDPR and is intended to implement it in a policy-neutral manner, continuing prior Dutch data protection law insofar as permitted by the GDPR.
ConfirmedDataGuidance — UAVG Article 2 provides that the Act and provisions based upon it apply to the processing of personal data wholly or partly by automated means and to processing that forms part of a filing system.
ConfirmedIAPP — The UAVG supplements GDPR with regard to personal data processed in the context of the activities of an establishment in the Netherlands, or related to offering goods/services to, or monitoring the behaviour of, individuals in the Netherlands.
ProbableIAPP — Under the pre-GDPR Dutch Data Protection Act, binding corporate rules were authorised via a Ministry of Justice and Security permit; the GDPR Implementation Bill was silent on transitional treatment, creating a risk that such permits would lapse unless the AP issued its own authorisation.
Traffic-light rationale — GreenCore lawful-basis and special-category framework is GDPR-aligned with well-documented, narrowly tailored Dutch derogations.
Sub-modules (4)
Lawful BasesGreen
The six GDPR Article 6 lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests) apply directly and exhaustively in NL.
Claims: CLM-NL-f6509311
Consent ThresholdsGreen
Consent must be freely given, specific, informed and unambiguous per Article 7 GDPR; NL sets the digital-consent age of majority at 16.
Claims: CLM-NL-071b4a22, CLM-NL-18ac2b33
Special CategoriesAmber
UAVG Chapter 3 layers additional, sector-specific exceptions onto GDPR Article 9 for controllers such as hospitals, schools and insurers.
Claims: CLM-NL-29bd3c44
Pseudonymisation And AnonymisationAmber
Biometric data processing is restricted under UAVG Article 29 to cases of strict necessity for authentication or security purposes, addressing a gap left by the GDPR's blanket Article 9 prohibition.
Claims: CLM-NL-3ace4d55
Category narrative94 words
Lawful bases and consent standards follow GDPR Articles 6 and 7 directly. The Netherlands set the child consent age threshold for information-society-service consent at 16 (the GDPR default, not exercising the Member-State option to lower it to as little as 13). UAVG Chapter 3 supplies sector-specific exceptions permitting processing of special-category data (health, biometric, criminal) by defined controller categories (hospitals, schools, insurers) for defined purposes, and restricts biometric processing to strict necessity for authentication/security. A pending 'Data Protection Collective Act' bill would adjust several special-data and children's-consent provisions but is not yet in force.
Sources and claims (5)
ConfirmedEDPB — Data controllers in the Netherlands may only process personal data where one of the GDPR Article 6 lawful bases applies, including consent, contractual necessity, legal obligation, vital interests, public-interest task, or legitimate interests.
ConfirmedEUR-Lex — Under GDPR Article 8(1), processing of a child's data based on consent for direct offer of information-society services is lawful where the child is at least 16; below that age, parental/guardian consent is required, with Member States able to lower this to no less than 13.
ConfirmedIAPP — The Dutch GDPR Implementation Bill reiterates age 16 as the applicable threshold for Article 8 GDPR consent, matching the prior Dutch Data Protection Act age limit rather than exercising the option to lower it to 13.
ConfirmedIAPP — UAVG Chapter 3 provides generic exceptions (e.g., explicit consent) alongside specific per-category exceptions allowing defined controllers such as hospitals, schools and insurance companies to process special categories of data for defined purposes (identification, sick-leave management, benefits, pre-employment screening, crime prevention).
ConfirmedAP/EDPB — UAVG Article 29 permits processing of biometric data for unique identification only where strictly necessary for authentication or security purposes, addressing a gap in GDPR Article 9 that otherwise lacked a workable workplace-biometrics exception.
Traffic-light rationale — GreenDirectly-effective GDPR rights regime, actively enforced by the AP against obstructive controller practices.
Sub-modules (5)
Access RightGreen
Access rights follow GDPR Article 15; AP enforcement confirms controllers may not impose disproportionate identity-verification barriers (e.g., mandatory ID-copy uploads) on access/erasure requests.
Claims: CLM-NL-4bdf5e66
Rectification And ErasureGreen
Controllers must notify recipients of any rectification, erasure, or restriction under Article 19 GDPR unless impossible or disproportionate.
Claims: CLM-NL-5cea6f77
Restriction And ObjectionGreen
Restriction and objection rights follow GDPR Articles 18 and 21 directly with no NL-specific derogation identified.
Data PortabilityGreen
Portability follows GDPR Article 20, applying where processing is based on consent or contract and carried out by automated means.
Claims: CLM-NL-6dfb7088
Deadlines And Response WindowsGreen
Controllers must respond to data subject requests without undue delay and within one month, extendable by two further months for complex/numerous requests, per GDPR Article 12(3).
Claims: CLM-NL-7e0c8199
Category narrative48 words
Data subject rights in NL derive directly from GDPR Chapter III (access, rectification, erasure, restriction, objection, portability) with no material Dutch derogation. AP enforcement practice (e.g., the DPG Media Magazines fine) illustrates active supervision of the access/erasure request process, specifically prohibiting disproportionate identity-verification demands that obstruct rights exercise.
Sources and claims (4)
ConfirmedAP/EDPB — The AP fined DPG Media Magazines €525,000 for infringing GDPR Article 12(2) by requiring individuals to upload a copy of their identity document before honouring access or erasure requests, without informing them they could redact data.
ConfirmedEUR-Lex — Under GDPR Article 19, controllers must communicate any rectification, erasure or restriction of processing to each recipient to whom the data were disclosed, unless this proves impossible or involves disproportionate effort, and must inform the data subject of those recipients on request.
ConfirmedEUR-Lex — Under GDPR Article 20, the data subject has the right to receive personal data provided to a controller in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance where technically feasible.
ConfirmedEUR-Lex — GDPR Article 12(3) requires controllers to respond to data subject rights requests without undue delay and within one month of receipt, extendable by a further two months for complex or numerous requests, applying directly in the Netherlands.
Traffic-light rationale — GreenFull GDPR accountability regime in force, reinforced by an AP-published DPIA trigger list and active enforcement on security/health-data handling.
Sub-modules (7)
Accountability And DpiaGreen
The AP has published a binding national list of processing operations requiring a DPIA, including large-scale/systematic employee monitoring, covert camera surveillance for fraud prevention, and large-scale biometric identification.
Claims: CLM-NL-8f1d9200
Dpo RequirementsGreen
DPO appointment follows GDPR Article 37 thresholds (public authorities, large-scale monitoring, large-scale special-category processing); DPO positioning was the subject of a 2023 EDPB coordinated enforcement action in which the AP participated.
Claims: CLM-NL-9020a311
Ropa RequirementsGreen
Controllers and processors must maintain records of processing activities under GDPR Article 30; no NL-specific derogation identified for the general regime (a separate, distinct ROPA duty exists under the Law Enforcement Directive regime for police data, outside this baseline's GDPR scope).
Absence provenance: not recorded. Searched: UAVG joint controller provisions, AP guidance joint controllers.
Security MeasuresAmber
Security-of-processing obligations under GDPR Article 32 are actively enforced; the AP fined an employer for maintaining an internet-accessible sick-leave register without multi-factor authentication.
Claims: CLM-NL-a131b422
Breach NotificationGreen
Breach notification duties follow GDPR Articles 33-34: notify the AP within 72 hours of becoming aware unless unlikely to result in risk, and notify affected individuals without undue delay where high risk is likely.
Claims: CLM-NL-b242c533
Retention And DisposalAmber
Retention limitation follows the GDPR storage-limitation principle (Article 5(1)(e)); no NL-specific statutory retention schedule identified at the omnibus level beyond sectoral rules.
Absence provenance: not recorded. Searched: UAVG retention schedule, AP retention guidance.
Category narrative75 words
Controllers and processors are subject to the full GDPR accountability toolkit. The AP has published a binding national DPIA 'blacklist' identifying processing types requiring a mandatory DPIA (large-scale employee monitoring, covert camera surveillance, large-scale biometric identification). Breach notification follows GDPR Articles 33-34 (72-hour regulator notification; subject notification where high risk). AP enforcement demonstrates active supervision of security-of-processing duties for sensitive employee health data, and Dutch Works Councils hold a statutory co-determination right over personnel-monitoring systems.
Sources and claims (4)
ConfirmedAP/EDPB — The AP's published DPIA list requires a mandatory data protection impact assessment for, among other things, large-scale and/or systematic monitoring of employee activity, covert camera surveillance for theft/fraud prevention, and large-scale processing for unique identification.
ConfirmedIAPP — The EDPB's 2023 Coordinated Enforcement Framework action, in which the AP participates as an EEA supervisory authority, focused specifically on the designation and positioning of Data Protection Officers.
ConfirmedAP/EDPB — The AP fined employer CP&A for security failings after its online sick-leave register, containing health data, was accessible without multi-factor authentication, finding that internet-accessible sick-leave systems require MFA beyond a regular login.
ConfirmedEDPB — Under GDPR Article 33, controllers must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.
Traffic-light rationale — GreenStandard GDPR Chapter V transfer toolkit applies uniformly; no NL-specific localisation mandate identified.
Sub-modules (6)
Transfer MechanismsGreen
Transfers rely on Commission adequacy decisions, SCCs, BCRs, or Article 49 derogations, applying directly under GDPR Chapter V.
Claims: CLM-NL-c353d644
Adequacy ReceivedGreen
As an EU Member State, NL does not receive bilateral adequacy from third countries; it operates within the EU's mutual-recognition (GDPR-internal) framework rather than a receiving-adequacy structure.
Absence provenance: not recorded. Searched: Netherlands adequacy received from third country.
Adequacy GrantedGreen
Adequacy decisions granted to third countries (e.g., the UK) are adopted at EU level by the European Commission and apply automatically in NL; the UK adequacy decisions are currently under an EDPB-reviewed extension process.
Claims: CLM-NL-d464e755
Sccs And BcrsAmber
BCR authorisation in NL transitioned from a Ministry of Justice permit system to AP approval under GDPR; legacy permits faced a risk of lapse absent timely AP authorisation.
Claims: CLM-NL-e575f866
Transfer Impact AssessmentAmber
TIA obligations follow the EDPB's general post-Schrems II recommendations, applied by the AP as an EEA authority; no NL-specific TIA methodology beyond EDPB guidance was identified.
Absence provenance: not recorded. Searched: AP transfer impact assessment guidance Netherlands.
Data LocalisationRed
No general data-localisation mandate exists in the Dutch omnibus DP regime.
Absence provenance: not recorded. Searched: Netherlands data localisation requirement GDPR, UAVG data localisation.
Category narrative63 words
As an EU Member State, NL's cross-border transfer regime is governed directly by GDPR Chapter V: adequacy decisions issued by the European Commission apply uniformly across the EU including NL (e.g., ongoing extension of UK adequacy), alongside SCCs, BCRs and Article 49 derogations. The pre-GDPR Ministerial BCR-permit system was replaced by AP authorisation. No general data-localisation mandate exists in the Dutch omnibus regime.
Sources and claims (3)
ConfirmedEUR-Lex — Cross-border transfers of personal data from the Netherlands to third countries rely on the GDPR Chapter V toolkit: European Commission adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, or Article 49 derogations.
ProbableEDPB — The EDPB adopted opinions on the European Commission's draft decisions extending the validity of the UK adequacy decisions under the GDPR and the Law Enforcement Directive, an EU-wide determination that applies automatically in the Netherlands as an EU Member State.
ProbableIAPP — Binding Corporate Rules previously authorised under a Ministry of Justice and Security permit faced a risk of becoming null and void from 25 May 2018 unless the AP issued its own GDPR-era authorisation, as the GDPR Implementation Bill did not expressly address transitional treatment.
Traffic-light rationale — AmberTelecoms/ePrivacy and employment overlays are well documented; credit-scoring and education sub-modules lack NL-specific findings.
Sub-modules (7)
Financial Sector OverlayAmber
No NL-specific financial-sector DP overlay beyond general GDPR/UAVG was surfaced in this run; AFM/DNB prudential rules interact with but do not supplant AP jurisdiction over personal data.
Absence provenance: not recorded. Searched: Netherlands financial sector data protection overlay AFM DNB GDPR.
Health Sector OverlayGreen
UAVG Chapter 3 grants hospitals and other health controllers specific exceptions to process special-category health data for defined purposes.
Claims: CLM-NL-f686007
Telecoms And EprivacyGreen
The Telecommunicatiewet transposes the ePrivacy Directive, including cookie-consent and confidentiality-of-communications rules.
Claims: CLM-NL-07971188
Employment DataAmber
Dutch Works Councils hold a statutory co-determination/consent right over the introduction of personnel-tracking and monitoring systems, and the AP publishes guidance to support Works Councils in assessing GDPR-compliance of such systems.
Claims: CLM-NL-18a82299
Credit And ScoringRed
No NL-specific credit-scoring overlay was identified in this run beyond general GDPR Article 22 automated-decision-making protections.
Absence provenance: not recorded. Searched: Netherlands credit scoring data protection BKR GDPR.
EducationRed
No NL-specific education-sector DP statute distinct from UAVG general exceptions was identified.
Absence provenance: not recorded. Searched: Netherlands education sector data protection overlay UAVG.
InsuranceGreen
UAVG Chapter 3 grants insurance companies specific exceptions to process special-category data for underwriting and claims purposes.
Claims: CLM-NL-f686007
Category narrative69 words
Telecommunications and electronic-communications processing is governed by the Telecommunicatiewet, transposing the ePrivacy Directive, including the cookie-consent rule and a July 2021 shift to opt-in consent for telemarketing to natural persons (abolishing the do-not-call register). Employment-sector processing is subject to Works Council co-determination rights over personnel-monitoring/tracking systems. Health and insurance sectors benefit from UAVG special-category exceptions. No NL-specific credit-scoring or education-sector DP overlay was identified beyond the general GDPR/UAVG regime.
Sources and claims (3)
ConfirmedIAPP — UAVG Chapter 3 provides sector-specific exceptions allowing hospitals, schools, and insurance companies to process special categories of personal data for defined purposes such as identification, sick-leave management, benefits/pensions, and pre-employment screening.
ConfirmedDataGuidance — The Telecommunications Act (Telecommunicatiewet) is the primary legislation governing telecommunications in the Netherlands and includes a chapter on privacy transposing the ePrivacy Directive (2002/58/EC as amended).
ConfirmedDataGuidance — The AP published a Works Council privacy booklet covering the right of consent and assessment questions for personnel-tracking systems, supporting Works Councils in evaluating whether employer monitoring plans are GDPR-compliant.
Cookie and direct-marketing rules are well documented; dark-pattern, opt-out-signal, clean-room and cross-context-advertising sub-modules lack NL-specific findings.
Traffic-light rationale — AmberCookie and direct-marketing rules are well documented; dark-pattern, opt-out-signal, clean-room and cross-context-advertising sub-modules lack NL-specific findings.
Sub-modules (6)
Cookies And TrackersGreen
Prior informed consent is required before storing or accessing information on a user's device, applying technology-neutrally to any tracking technology, not solely cookies.
Claims: CLM-NL-299a33aa
Dark PatternsRed
No NL-specific dark-pattern prohibition distinct from EU-level DSA/GDPR interplay guidelines was surfaced.
Absence provenance: not recorded. Searched: Netherlands dark patterns cookie consent AP guidance.
Opt Out SignalsRed
No NL-specific recognition of browser-level opt-out signals (e.g., Global Privacy Control) was identified.
Absence provenance: not recorded. Searched: Netherlands Global Privacy Control AP recognition.
Clean Rooms And DcrRed
No NL-specific data clean-room regulatory framework was identified.
Absence provenance: not recorded. Searched: Netherlands data clean room regulation AP.
Cross Context AdvertisingAmber
No NL-specific 'sale'/'share' construct analogous to US state law exists; cross-context advertising is governed by GDPR consent/legitimate-interest analysis and the ePrivacy cookie rule.
Absence provenance: not recorded. Searched: Netherlands cross-context advertising GDPR ePrivacy.
Direct MarketingGreen
Telemarketing to natural persons requires opt-in consent since 1 July 2021; the do-not-call register was discontinued.
Claims: CLM-NL-3aab44bb
Category narrative64 words
The Telecommunicatiewet's cookie-consent rule requires prior, informed consent before storing or accessing information on a user's terminal equipment, applying technology-neutrally to all tracking technologies, not only cookies. Since 1 July 2021, telemarketing to natural persons requires opt-in consent, replacing the prior opt-out/do-not-call regime. NL-specific findings on dark patterns, opt-out signals, clean rooms, and cross-context advertising were not surfaced beyond general EU-level DSA/GDPR interplay guidance.
Sources and claims (2)
ConfirmedEDPB — The confidentiality-of-terminal-equipment rule transposed into Dutch law from the ePrivacy Directive is technology-neutral, meaning user consent (or an applicable exception) is required not only for cookies but for any tracking technology accessing or storing information on a device.
ConfirmedDataGuidance — Prior to a 1 July 2021 amendment to the Telecommunications Act, telemarketing calls to natural persons operated on an opt-out basis; this was replaced with an opt-in consent requirement and the do-not-call register is no longer used.
Biometric and profiling rules are well established under GDPR/UAVG; AI Act competent-authority designation and NL-specific AI risk-assessment interplay is still maturing as of the 2 August 2026 application date.
Primary frameworkGDPR Article 22; UAVG Article 29; EU AI Act (Regulation (EU) 2024/1689); Law Enforcement Directive (2016/680)
Traffic-light rationale — AmberBiometric and profiling rules are well established under GDPR/UAVG; AI Act competent-authority designation and NL-specific AI risk-assessment interplay is still maturing as of the 2 August 2026 application date.
Sub-modules (6)
Profiling RestrictionsGreen
Profiling restrictions follow GDPR Article 22 directly; the EDPB has issued an opinion confirming GDPR principles govern personal data use in AI model development and deployment.
The EU AI Act applies from 2 August 2026, with governance, sanctions, and GPAI-provider obligations already in force since August 2025 and AI-literacy obligations since February 2025; national competent authority designation interacts with the AP's data-protection remit.
Claims: CLM-NL-5ccd66dd
Biometric RegimeGreen
Biometric data processing for unique identification is prohibited absent strict necessity for authentication/security, per UAVG Article 29; the AP's DPIA list separately mandates DPIAs for large-scale biometric identification and flexible camera surveillance.
Claims: CLM-NL-6dde77ee, CLM-NL-7eef88ff
Genetic DataAmber
Genetic data is a GDPR Article 9 special category; no NL-specific overlay beyond UAVG's general special-category exceptions was surfaced.
Absence provenance: not recorded. Searched: UAVG genetic data specific exception Netherlands.
State Surveillance CarveoutsAmber
Law-enforcement and state-security processing is carved out of GDPR and governed instead by the Law Enforcement Directive (2016/680), implemented in Dutch law via police-data legislation and royal decrees.
Claims: CLM-NL-8ff099aa
Category narrative101 words
Profiling and automated-decision-making are governed by GDPR Article 22, with EDPB opinion clarifying GDPR principles' application to AI model development/deployment. The EU AI Act (Regulation (EU) 2024/1689) applies from 2 August 2026 (with earlier partial application from February and August 2025), requiring Member State designation of competent authorities, some of which may coordinate with the AP on data-protection-adjacent obligations. Biometric data is restricted under UAVG Article 29 to strict-necessity authentication/security use, and the AP's DPIA list mandates impact assessments for large-scale biometric identification and flexible camera surveillance. Law-enforcement processing sits under the separate Law Enforcement Directive (2016/680) regime rather than GDPR/UAVG.
Sources and claims (5)
ConfirmedEDPB — The EDPB adopted an opinion on the use of personal data for the development and deployment of AI models, confirming that GDPR principles apply to and support responsible AI governance.
ConfirmedEUR-Lex — The EU AI Act applies from 2 August 2026, with certain provisions (prohibitions, definitions, AI-literacy obligations) already effective since 2 February 2025 and governance-structure, sanctions, and GPAI-provider rules effective since 2 August 2025.
ConfirmedAP/EDPB — UAVG Article 29 permits processing of biometric data for unique identification purposes only where strictly necessary for authentication or security, subject to additional conditions in Dutch implementing law.
ConfirmedAP/EDPB — The AP's DPIA list identifies large-scale and/or systematic use of flexible camera surveillance (e.g., body-worn cameras, dash cams) and large-scale processing enabling unique identification of individuals as mandatory-DPIA processing categories.
ConfirmedIAPP — Processing of personal data by competent authorities for the prevention, investigation, detection or prosecution of criminal offences is subject to the Law Enforcement Directive (2016/680) rather than the GDPR, and has been implemented in Dutch law and royal decrees governing investigation and prosecuting authorities.
Age-of-consent and parental-consent framework is clear and GDPR-aligned; a minor pending legislative refinement does not affect current binding status.
Traffic-light rationale — GreenAge-of-consent and parental-consent framework is clear and GDPR-aligned; a minor pending legislative refinement does not affect current binding status.
Sub-modules (5)
Age VerificationGreen
Controllers must make reasonable efforts, given available technology, to verify that parental/guardian consent has been given for children under 16.
Claims: CLM-NL-9001aabb
Parental ConsentGreen
Below age 16, consent for information-society-service processing must be given or authorised by the holder of parental responsibility.
Claims: CLM-NL-a112bbcc
Minor Profiling BansAmber
No NL-specific blanket ban on profiling of minors distinct from GDPR Article 22/Recital 71 general caution was identified.
Absence provenance: not recorded. Searched: Netherlands minor profiling ban AP guidance.
Education SettingsAmber
UAVG special-category exceptions extend to schools processing pupil data for defined educational purposes; no separate education-specific DP statute was identified.
Claims: CLM-NL-b223ccdd
Dependent AdultsGreen
UAVG Article 5 requires the consent of a legal representative instead of the data subject where the data subject is under guardianship or subject to an administration or protection order and lacks legal capacity to consent.
Claims: CLM-NL-c334ddee
Category narrative71 words
The Netherlands applies the GDPR default age of 16 for information-society-service consent (Article 8), requiring verifiable parental/guardian consent below that age, with controllers expected to make reasonable efforts to verify parental authority given available technology. UAVG Article 5 extends analogous legal-representative consent requirements to adults under guardianship or subject to an administration/protection order. A pending Dutch bill (Data Protection Collective Act) would adjust children's-data consent provisions but is not yet enacted.
Sources and claims (4)
ConfirmedEUR-Lex — Data controllers must take reasonable efforts, using available technology, to verify that a person consenting on behalf of a child under the applicable age threshold actually holds parental responsibility.
ConfirmedIAPP — Children aged 16 and above may give their own consent for information-society-service processing in the Netherlands; for children below 16, consent must be obtained from the child's legal guardian or parent, consistent with the GDPR Article 8 default and reiterated in the UAVG.
ProbableIAPP — UAVG Chapter 3 exceptions extending to schools permit processing of certain special-category pupil data for defined educational purposes, alongside similar exceptions for hospitals and insurers.
ConfirmedDataGuidance — Under UAVG Article 5(2), if a data subject is under guardianship or subject to an administration or protection order, the consent of the legal representative is required instead of the data subject's own consent, to the extent the data subject lacks legal capacity.
Mature, actively used enforcement toolkit with a published fining structure and recent illustrative decisions; collective-redress mechanism is narrower than the GDPR default option.
Traffic-light rationale — GreenMature, actively used enforcement toolkit with a published fining structure and recent illustrative decisions; collective-redress mechanism is narrower than the GDPR default option.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The AP published a four-category fining structure with monetary ranges from €0 up to €1,000,000 per infringement category, escalating for category-four offences deemed inadequate.
Claims: CLM-NL-d445eeff
Enforcement Activity IndexGreen
Illustrative recent enforcement includes the €525,000 DPG Media Magazines fine and the CP&A employee-health-data security fine.
Claims: CLM-NL-e556ff00, CLM-NL-f6670011
Regulator Funding And CapacityAmber
No specific NL AP budget/headcount figures were surfaced in this run; the AP operates as an independent non-departmental public body under UAVG Article 11 budgeting provisions.
The Netherlands declined to adopt the GDPR Article 80(2) opt-out mechanism, instead requiring all affected data subjects to individually opt in for their data to be submitted as evidence in a collective action.
Claims: CLM-NL-1889b133
Private Right Of ActionGreen
Data subjects retain the GDPR Article 78/79 right to an effective judicial remedy against both supervisory-authority decisions and controllers/processors directly before Dutch courts.
Claims: CLM-NL-299ac244
Recent Developments 180DGreen
Within the relevant window, the CJEU's Grand Chamber ruling of 10 February 2026 in WhatsApp Ireland v EDPB (C-97/23 P) addressed judicial review of EDPB binding Article 65 decisions arising from one-stop-shop disputes, relevant to Dutch controllers subject to lead-authority decisions; the EDPB also adopted a statement on DPAs' role in the AI Act framework (17 July 2026).
Claims: CLM-NL-3aabd355, CLM-NL-4bbce466
Category narrative125 words
The AP exercises the full GDPR Article 58 investigative and corrective toolkit and has published a four-tier fining structure ranging up to €1,000,000 per category (with higher fines possible where deemed appropriate). Enforcement examples include the €525,000 DPG Media Magazines fine (Article 12(2) transparency) and the CP&A fine for insecure health-data processing. NL notably declined to adopt the GDPR Article 80(2) opt-out collective-action mechanism, requiring data subjects to individually opt in to collective privacy actions. The CJEU's 2022 ruling in Case C-245/20 clarified limits on AP jurisdiction over courts acting in their judicial capacity, and the Court's 2026 WhatsApp v EDPB ruling (C-97/23 P) addressed challengeability of EDPB binding decisions within the one-stop-shop mechanism, both bearing on Dutch enforcement practice as an EU Member State.
Sources and claims (8)
ConfirmedIAPP — The AP created a four-tiered penalty structure for GDPR infringements ranging from €0-200,000 (category one) up to €450,000-1,000,000 (category four), with higher fines available where a category-four penalty is deemed inappropriate.
ConfirmedAP/EDPB — The AP imposed a €525,000 fine on DPG Media Magazines B.V. for infringing GDPR Article 12(2) by unnecessarily requiring copies of identity documents from individuals exercising access and erasure rights.
ConfirmedAP/EDPB — The AP fined employer CP&A for GDPR violations relating to insecure online processing of employees' sick-leave (health) data lacking multi-factor authentication.
ProbableDataGuidance — UAVG Article 11 requires the AP, as an independent non-departmental public body, to draw up its own draft budget subject to the Dutch non-departmental public bodies framework act.
ConfirmedIAPP — The Dutch GDPR Implementation Bill specifically prohibits collective actions proceeding against a data subject's will, requiring all data subjects whose data forms part of a contested processing operation to individually sign up for a collective action, meaning the Netherlands did not adopt the Article 80(2) GDPR opt-out mechanism.
ConfirmedEUR-Lex — The CJEU's judgment in Case C-245/20 (Autoriteit Persoonsgegevens), arising from a Dutch court reference, addressed the scope of AP supervisory competence under Article 55(3) GDPR over data processing by courts acting in their judicial capacity.
ConfirmedEUR-Lex — The CJEU Grand Chamber issued its ruling of 10 February 2026 in WhatsApp Ireland Ltd v European Data Protection Board (Case C-97/23 P), concerning the reviewability under Article 263 TFEU of binding EDPB Article 65 dispute-resolution decisions arising from the one-stop-shop mechanism used against the Irish lead authority's draft WhatsApp decision.
ConfirmedEDPB — The EDPB, of which the AP is a member, adopted a statement on 17 July 2026 concerning data protection authorities' role in the EU AI Act framework, relevant to AP's interaction with AI Act competent authorities in the Netherlands.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Netherlands
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 43 claim(s), 23 source(s) in the cumulative register.