Published on · Last updated

Dutch Privacy Law

background-2

Privacy law in the Netherlands is set by the European General Data Protection Regulation (Regulation (EU) 2016/679, the GDPR) and the Dutch implementation act, the UAVG. It applies to every organisation that processes personal data of people in the Netherlands. This page explains which legal basis you need, when a processing agreement is required, what to do after a data breach, and the fines you risk.

What law governs privacy in the Netherlands?

Dutch privacy law rests on two sources: the GDPR, which applies directly across the European Union, and the Dutch UAVG, which fills in the national choices the GDPR leaves open. The Autoriteit Persoonsgegevens (the Dutch Data Protection Authority) supervises compliance and can impose fines.

When may you process personal data?

You may process personal data only if you have a legal basis for it. Article 6 of the GDPR sets out six bases: consent, performance of a contract, a legal obligation, vital interests, a public task, and legitimate interests.

Most business processing relies on consent, a contract or a legitimate interest, and you must record which one applies before you start.

What is a processing agreement and when do you need one?

A processing agreement (verwerkersovereenkomst) is a contract between a controller and a processor that handles personal data on the controller’s behalf.

Article 28 of the GDPR makes such an agreement mandatory whenever you outsource processing, for example to a cloud provider, a payroll service or an IT supplier. Because a processing agreement is a contract, the same care applies as to any commercial contract under Dutch law.

What must you do after a data breach?

If a data breach is likely to risk people’s rights, you must report it to the Autoriteit Persoonsgegevens without undue delay and, where feasible, within 72 hours of becoming aware of it, as Article 33 of the GDPR requires.

Where the risk to the people affected is high, you must also inform them directly.

What are the fines for breaching the GDPR?

The GDPR sets two fine tiers. The higher tier, under Article 83, reaches up to 20 million euro or 4% of total worldwide annual turnover, whichever is greater.

The Dutch Data Protection Authority has used these powers in practice, so non-compliance is a real financial risk rather than a theoretical one.

Not sure whether your consent forms, processing agreements or breach procedure meet the GDPR? Our Dutch privacy lawyers review your current setup and tell you where the gaps are before the supervisor does.

A practical example: a webshop outside the EU

Consider a webshop based outside the European Union that sells to Dutch consumers and stores their names, addresses and payment data. Because it offers goods to people in the Netherlands, the GDPR applies regardless of where the company sits.

It needs a legal basis under Article 6, a processing agreement with its hosting provider under Article 28, and a breach procedure under Article 33. The absence of any one of these is what turns a routine check by the Autoriteit Persoonsgegevens into a fine.

Speak to a Dutch privacy lawyer

Whether you need a processing agreement, a compliant privacy policy or advice after a data breach, getting it right avoids fines and protects the trust of your customers.

Our Dutch privacy lawyers map your data flows, set the correct legal basis and draft the agreements you need. This work sits within our broader practice in the Dutch law of obligations. Contact us to review your privacy compliance.

Frequently asked questions about Dutch privacy law

Does the GDPR apply to companies outside the Netherlands?

Yes. The GDPR applies to any organisation that offers goods or services to, or monitors the behaviour of, people in the Netherlands, wherever that organisation is itself established.

Do you always need consent to process personal data?

No. Consent is only one of the six legal bases in Article 6 of the GDPR. Processing can also be lawful on the basis of a contract, a legal obligation or a legitimate interest, among others.

How quickly must a data breach be reported?

A notifiable data breach must be reported to the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, under Article 33 of the GDPR. The people affected must also be told where the risk to them is high.

Who enforces privacy law in the Netherlands?

The Autoriteit Persoonsgegevens supervises compliance with the GDPR and the UAVG. It can investigate, order changes and impose fines of up to 20 million euro or 4% of worldwide annual turnover under Article 83.

Blogs

Why work with our Dutch privacy lawyers?

Our Dutch privacy lawyers in the Netherlands have a great deal of experience with the General Data Protection Regulation and closely follow developments in the field of privacy law. If you are doing business internationally and personal data is automatically processed, it is good that you are advised by a lawyer. Together, we map out the data flows and determine the basis for the processing. Permission may have been granted by an individual, but there may also be a legitimate interest in processing personal data.

If personal data is processed on behalf of your organisation, but you determine the purpose and means, you remain responsible for the processing of these data. Or the party processing personal data on behalf of your organisation will be identified by our Dutch lawyers in the Netherlands. If that is the case, it is important that you have a processing agreement for these operations. Amongst other things, we will arrange agreements of the steps to be taken in the event of a data breach. Our lawyers will be happy to guide you further in the field privacy law.

“Maak has a great team
that helped
us very well and
are really
thinking with you on
what
is possible. Would for sure
chose
them again in the future.”

P. Evers.

News & Insights
Which topics would you like to receive updates on?
Which industry or sector do you operate in? (Optional)