AI in Dutch employment law is governed by four sets of rules at once: the EU AI Regulation, which classifies most recruitment and workforce-management systems as high-risk; the GDPR, which limits automated decision-making about individuals; Dutch equal treatment legislation, which makes the employer liable for discriminatory outcomes whoever built the tool; and the Works Councils Act, which gives the works council a say before such a system is introduced. The employer, not the software supplier, answers for the result. This article sets out what each of those regimes requires, when the obligations apply, and what to put in place before an AI tool touches a hiring or performance decision.
How Dutch employers actually use AI

Adoption has moved quickly. According to Statistics Netherlands (CBS), one in six Dutch businesses used artificial intelligence in 2025, roughly seventeen per cent, twice the share recorded in 2023. Among the businesses that use it, thirty-five per cent apply it to marketing or sales, thirty-two per cent to administrative or management tasks and a quarter to research, development and innovation. Use is concentrated in information and communication, financial services and specialised business services, and it is markedly lower among the smallest firms.
In the employment relationship itself, the applications fall into a small number of groups. Applicant tracking systems screen and rank CVs against criteria set in advance, and some platforms go further and score video interviews on speech and language patterns. Performance systems aggregate productivity data, completion rates and customer feedback into ratings that feed into pay and promotion. Workforce planning tools forecast demand and allocate shifts. Access control and time registration increasingly rely on biometric technology. And generative tools are now used for drafting, internal communication and first-line answers to staff questions about terms and conditions.
The legal position does not depend on how the technology is described. What matters is whether the system produces or materially influences a decision about an identifiable person, and how much room a human being genuinely has to reach a different conclusion. That question runs through every section below and through our wider material on AI in the workplace and on algorithmic decision-making.
What the AI Regulation requires, and from when

The EU AI Regulation entered into force in August 2024 and applies in stages. Two points are commonly misstated, and both matter for planning.
First, the prohibitions already apply. AI systems that infer emotions in the workplace are banned except for medical or safety purposes, which covers a good deal of what is marketed as sentiment analysis and engagement monitoring. Social scoring, biometric categorisation that infers sensitive characteristics such as race, political opinion, trade union membership or health, and manipulative techniques that materially distort behaviour are also prohibited outright. The obligations for general-purpose AI models and the transparency duties of article 50, including the duty to disclose that content is artificially generated and that a person is interacting with a machine, are likewise already in effect.
Second, the high-risk regime has been deferred. The digital omnibus package postponed only that part of the timetable: the obligations for the systems in Annex III, which is where recruitment, task allocation, promotion, termination and performance monitoring sit, move to 2 December 2027, and those for the Annex I products move to 2 August 2028. That is time to prepare, not a reason to wait, because the GDPR, equal treatment law and the Works Councils Act apply now and cover much of the same ground.
When the high-risk obligations do bite, the employer is usually the deployer rather than the provider, and the deployer duties are practical ones: use the system in accordance with the instructions, assign human oversight to people who have the competence, training and authority to intervene, ensure the input data is relevant and sufficiently representative, keep the automatically generated logs, inform workers and their representatives before the system is put into use, and inform individuals that they are subject to it. An employer that puts its own name on a system, or modifies it substantially, can become the provider and take on the full conformity assessment and documentation burden. Note also that the proposed AI Liability Directive has been withdrawn, so damage caused by an AI system is dealt with under ordinary Dutch rules on liability and under the product liability regime. Our overview of the legal side of artificial intelligence in the EU follows the timetable in more detail.
Discrimination: the Dutch rules that apply to algorithmic selection

Equal treatment in Dutch employment is governed by national statutes implementing the EU equality directives, and they apply to a decision produced by an algorithm exactly as they apply to one taken by a manager. The General Equal Treatment Act prohibits distinction on grounds including religion, belief, political opinion, race, sex, nationality, sexual orientation and civil status. Separate statutes cover age and disability or chronic illness. The Civil Code prohibits distinction between men and women in the terms of employment and in promotion, and separately prohibits distinction on the basis of working hours and on the basis of a fixed-term as against a permanent contract. Discrimination is also a criminal offence in defined circumstances.
Two features of that framework decide AI cases. The first is that both direct and indirect distinction are caught. Direct distinction, where a protected characteristic is used as a criterion, is unlawful save for the narrow statutory exceptions. Indirect distinction, where an apparently neutral criterion disadvantages a protected group disproportionately, is unlawful unless it is objectively justified by a legitimate aim and the means are appropriate and necessary. Almost every algorithmic discrimination problem is of the second kind: a model trained on historic hiring data reproduces the pattern in that data, and proxies such as postcode, the year of a qualification, a gap in a career history or the language used in a CV do the work that a prohibited criterion would have done.
The second is the burden of proof. Once a person establishes facts from which distinction may be presumed, it is for the employer to prove that it did not occur. An applicant who shows a statistical disparity in the outcomes of an automated selection process has done enough to shift that burden, and an employer that cannot explain the criteria the system applied is not in a position to discharge it. Buying the tool from a supplier does not help: the employer answers to the applicant or the employee. Complaints can be brought before the Netherlands Institute for Human Rights, whose opinions are not binding but carry weight, or before the civil courts.
It is worth being clear about what does not apply. There is no statutory obligation in the Netherlands to operate a documented working method for recruitment and selection: the bill that would have introduced it, and given the Labour Authority a supervisory role, was rejected by the Senate on 26 March 2024, and a later private member’s initiative on the same subject has not been enacted. The absence of that statute changes nothing about liability for the outcome. It simply means the employer chooses its own method and carries the risk of it, which is a reason to document and test the selection criteria rather than a reason not to.
In practice that means three things. Decide in advance which criteria are relevant to the role and can be justified, and configure the tool to those criteria rather than to a general notion of a good candidate. Test outcomes across protected groups at intervals, not only at implementation, and keep the results. And keep the model’s inputs and weightings available in a form that can be explained to a court or to the Institute, because a system nobody can explain is a system nobody can defend. Where the tool comes from outside, build the right to that information and to audit into the contract with the supplier.
Data protection: automated decisions, impact assessments and monitoring
The GDPR is the regime that applies today, and it is the one on which enforcement is most likely in the short term. Three of its rules do most of the work in an employment context.
The first is the rule on automated individual decision-making. A person has the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them, unless one of the narrow exceptions applies, and even then suitable safeguards must be in place, including human intervention, the ability to express a point of view and the right to contest the decision. Rejecting an applicant automatically, or setting a performance rating that determines pay without a human assessment, falls squarely inside this rule. Nominal human involvement does not take a decision outside it: the person reviewing has to have the authority and the information to reach a different conclusion, and to do so in practice rather than in theory.
The second is transparency. Where automated decision-making of that kind takes place, the controller must provide meaningful information about the logic involved and about the significance and envisaged consequences of the processing. That is not a demand for source code, but it does require the employer to be able to say which factors the system weighs and how. Employees and applicants also retain the ordinary rights of access, rectification and objection. Our overview of Dutch data privacy law and our note on the general data protection framework set out those rights in full.
The third is the data protection impact assessment. A DPIA is required where processing is likely to result in a high risk to individuals, and the systematic and extensive evaluation of personal aspects by automated means, as well as the systematic monitoring of people at work, are precisely the cases the Regulation names. Carry it out before the system goes live, involve the data protection officer, and record the alternatives considered and the mitigations chosen; the Dutch Data Protection Authority can ask for it at any time and its absence is itself an infringement.
Two further points are specific to the employment relationship. Consent is rarely a valid basis for processing employee data, because the imbalance between employer and employee means it is seldom freely given; the employer will normally have to rely on the necessity of the processing for the performance of the contract, on a statutory obligation or on a legitimate interest, and a legitimate interest requires a documented balancing against the privacy of the people concerned, on which a privacy lawyer can advise before the system goes live. And monitoring must be proportionate and as limited as possible: covert or blanket surveillance of all staff will not survive that test, the purpose has to be defined in advance, the retention period has to be short, and staff must be informed. Where the AI provider processes the data on your instructions, a processing agreement is compulsory and the allocation of controller and processor roles should be settled before the contract is signed. Where employee data is used to train a model, or shared with a supplier for that purpose, the purpose limitation principle and the rules on data sharing have to be worked through separately; see also our material on data privacy, AI and big data.
The works council comes first
In an organisation with a works council, the council is not a formality to be handled after the contract with the supplier is signed. The Works Councils Act gives it two distinct powers, and both are engaged by workplace AI.
The council has an advisory right on important intended decisions, which include the introduction or modification of an important technological facility and important changes in the organisation of the work. The advice must be sought at a moment when it can still influence the decision, and if the employer departs from the advice it must suspend implementation for a month, during which the council can bring the decision before the Enterprise Chamber (Ondernemingskamer) on the ground that the employer could not reasonably have reached it.
The council has a stronger power, a right of consent, over rules governing the appraisal of staff and over facilities intended to observe or monitor the presence, conduct or performance of employees. Nearly every AI performance or monitoring tool falls within one of those categories. Without the council’s consent the arrangement is void, and the employer cannot rely on it; the council can invoke that nullity, and the employer that wants to proceed must ask the sub-district court for substitute consent.
Practically, involve the council at the selection stage, give it the documentation rather than a summary, allow it to obtain independent technical advice at the employer’s expense, and record what was agreed about testing, evaluation and the point at which the arrangement will be reviewed. Our pages on Dutch labour law and on employer obligations under Dutch employment law set out the surrounding consultation duties.
Algorithmic management and platform work
The most intensive form of algorithmic management is found on digital labour platforms, where software allocates the work, sets the rate and decides who keeps access to the app. EU law now regulates that directly. The Platform Work Directive was adopted in October 2024 and must be transposed by the member states by 2 December 2026. It obliges platforms to inform workers and their representatives about automated monitoring and decision-making systems that significantly affect working conditions, to ensure human oversight of those systems and to assess their effect on health and safety, and to give workers a right to an explanation of, and a human review of, significant decisions such as the restriction or suspension of an account. It also prohibits the processing of certain categories of data, including data on emotional and psychological states and on private conversations.
Two consequences follow for employers who are not platforms. The standards in that directive describe what regulators and courts increasingly regard as normal for any employer using algorithmic management, and building them in now costs little. And the same fact pattern raises the question of employment status. Where a person is directed by an algorithm as tightly as an employee is directed by a manager, the relationship can qualify as an employment contract regardless of the label, with wage tax, contributions and dismissal protection following. The Dutch tax authorities ended the enforcement moratorium on false self-employment on 1 January 2025, and a statutory presumption of employment based on an hourly rate has been adopted, with entry into force to be set by royal decree. Cross-border arrangements add a further layer, which we address in our note on working across borders in a digital world.
AI in performance management and dismissal
Dutch dismissal law is a closed system, and no automated output shortens it. An employer that wants to end a permanent contract on personal grounds must persuade the sub-district court that a statutory ground is fully made out, and for underperformance that means the employee was told clearly what was wrong, was given a real opportunity to improve with support, and was considered for redeployment. A productivity score generated by software is evidence, and only evidence. It does not establish that the employee was informed, that the improvement process was fair, or that the measurement reflected the actual job, and it is open to challenge on all three points.
Three failures recur. Measuring output without adjusting for context, so that an employee on adapted duties, on reduced hours or returning from long-term illness is scored against a standard that does not apply to them, which brings the equal treatment rules and the prohibition on termination during illness into play. Relying on a system whose criteria cannot be explained, which makes the evidence difficult to test and easy for the employee to attack. And treating a human review as a signature on the algorithm’s conclusion, which is exactly what the GDPR and the AI Regulation are designed to prevent.
The corresponding discipline is straightforward. Use automated output as an input to a documented human assessment, record the reasoning of the person who took the decision, keep the improvement process on paper, and be able to show what the system measured and over what period. Employers who get this wrong tend to lose on process rather than on substance; our overview of the most common employment law compliance mistakes covers the pattern, and recent labour law changes and duties to inform employees about their conditions are set out separately. Where automation genuinely removes roles, the redundancy route runs through the UWV and the obligation to consider retraining and redeployment applies, as explained in our guide to labour law in the Netherlands.
Who owns what the AI produces
Generative tools raise a separate question that employers meet as soon as staff use them for real work. Dutch copyright protects a work only if it is the author’s own intellectual creation, which requires a human being making creative choices. Output generated with a prompt and no substantive human authorship is therefore unlikely to attract copyright at all, which means competitors are free to copy it. Where an employee makes genuine creative choices with the help of a tool, the work can be protected, and the copyright in works created by an employee in the performance of the employment relationship vests in the employer by operation of law. That rule does not extend to contractors, whose rights must be assigned by deed.
Two practical consequences follow. Material that has to be protected, such as a brand asset or a piece of product documentation, should carry a demonstrable human contribution, and the process should be recorded. And the terms of the AI platform itself have to be read, because they determine what rights the provider claims over inputs and outputs and whether the material submitted is used for training; feeding confidential material or personal data into a public tool can breach both a confidentiality obligation and the GDPR. Patents raise a related point: an AI system cannot be named as an inventor, so a human inventor has to be identified on the application. We discuss these questions further in our articles on chatbots, copyright and compliance and on how creative rights are developing, and in our guide to intellectual property law in the Netherlands. Enforcement options where third parties copy protected material are set out in our page on intellectual property enforcement.
Liability, supervision and enforcement
Exposure comes from several directions at once, and they are cumulative rather than alternative.
Under the AI Regulation the fines are tiered: up to thirty-five million euro or seven per cent of worldwide annual turnover, whichever is higher, for the prohibited practices, and up to fifteen million euro or three per cent for breaches of the high-risk obligations. Supervision in the Netherlands is shared, with the Dutch Data Protection Authority and the Authority for Digital Infrastructure coordinating the national framework and sector regulators covering their own fields; a regulatory sandbox is available for testing before full deployment. Under the GDPR the ceilings are twenty million euro or four per cent of worldwide turnover for the most serious infringements, and individuals can claim compensation for both material and non-material damage.
Alongside the regulators, the ordinary employment routes remain the most likely source of a claim. An employee can challenge a dismissal or a performance decision before the sub-district court. An applicant or employee can bring a discrimination complaint before the Netherlands Institute for Human Rights or the civil courts, with the reversed burden of proof. A works council can attack a decision taken without the required advice or consent. And a supplier contract that leaves the employer without documentation, audit rights or an indemnity converts a supplier’s failure into the employer’s loss. Vendor management is therefore part of the legal work, not a procurement detail: require the technical documentation, evidence of testing for bias, a processing agreement, prompt notification of incidents, audit rights and cooperation with regulators, and treat a supplier that cannot explain how its system works as an unacceptable risk. Our page on types of legal compliance sets out how to organise this alongside your other obligations, and our note on liability for errors made by artificial intelligence covers the civil law position.
What to put in place now
Start with an inventory. List every system in use or under consideration that touches an employment decision, including tools introduced by individual departments without a formal procurement, and record for each what it does, what data it uses, which decision it influences and who reviews the output. Most organisations discover more than they expected, and the inventory is the document every other step depends on.
Then classify. For each system, decide whether it falls within the prohibitions, whether it is likely to be high-risk under Annex III, whether it involves automated decision-making within the meaning of the GDPR, and whether it triggers the works council’s advisory or consent right. That classification determines the sequence: works council first, impact assessment before deployment, and documentation from the outset rather than reconstructed afterwards.
Write the governance down in a single policy that states which decisions always require human assessment, who is authorised to override the system and on what basis, how staff are trained, what is tested and how often, how employees and applicants are informed and how they can contest a decision, and what happens when the system malfunctions. Keep the policy aligned with the rest of the employment documentation rather than as a separate compliance artefact, and review it when the phased obligations of the AI Regulation take effect.
Finally, test and record. Run outcome testing across protected groups, keep the logs the Regulation will require, keep the works council informed of the results, and treat every complaint about an automated decision as a signal about the system rather than only about the individual case. An employer that can produce the inventory, the impact assessment, the works council file, the testing results and a reasoned human decision is in a strong position whichever route a challenge takes.
Law and More advises employers on the introduction of AI and automation in the workplace: classification under the AI Regulation, data protection impact assessments and processing agreements, works council procedures, equal treatment risk in recruitment and assessment, supplier contracts, and the defence of decisions that are challenged before the sub-district court or the Netherlands Institute for Human Rights. If you are introducing such a system, or an employee has contested one, contact our office.
Frequently asked questions
Implementing AI and automation in Dutch workplaces requires careful attention to works council rights, data protection rules, and emerging EU regulations.
Employers must balance technological advancement with legal obligations around employee protection, monitoring practices, and workforce changes.
What are the primary legal considerations for implementing AI and automation in the Dutch workplace?
You must consult your works council before implementing any AI or automation system that affects employees. Under the Works Councils Act the council has an advisory right on the introduction of an important technological facility and a right of consent on rules for staff appraisal and on facilities used to monitor presence, conduct or performance.
This applies to AI systems used in hiring, performance evaluation, or workforce planning. The EU AI Regulation entered into force in August 2024 and classifies most workplace AI systems as high-risk, although those obligations are phased in later than the prohibitions, which already apply.
You need to ensure your AI systems meet strict requirements for risk management, data quality, transparency, and human oversight. Systems used for harmful manipulation, unjust social scoring, or emotion recognition in work settings are completely banned.
Your AI systems must comply with GDPR rules on automated decision-making. You cannot make significant employment decisions based solely on algorithms without human involvement.
This includes dismissals, promotions, and performance reviews.
How can Dutch employers ensure compliance with employment laws when introducing automation?
You should start by informing your works council about any planned automation or AI implementation. The works council has the right to receive detailed information about how the technology works, what data it collects, and how it affects employees.
You cannot proceed without their advice. You must conduct a data protection impact assessment if your AI system processes employee personal data on a large scale.
This assessment should identify risks to employee privacy and outline measures to reduce those risks. The Dutch Data Protection Authority can request this documentation at any time.
Keep detailed records of how your AI systems make decisions. The AI Act requires you to maintain logs that show how algorithms reach conclusions about employees.
You need to be able to explain these decisions to employees and regulators when asked.
What rights do employees in the Netherlands have when facing displacement due to AI and automation?
Your employees have the right to information about technological changes that affect their jobs. Under the statutory duty to inform employees about the essential aspects of their work, you must tell them about changes that significantly affect their employment conditions.
Employees can request explanations for automated decisions that affect them. If your AI system recommends dismissal, reassignment, or changes to working conditions, you must provide a clear explanation of how that decision was made.
The decision cannot be based solely on algorithmic output. Works council members can demand technical details about AI systems on behalf of all employees.
They have the right to bring in external experts to assess whether the technology complies with Dutch law and protects employee interests.
What are the obligations of employers in the Netherlands to retrain or redeploy workers affected by AI and automation?
You have a duty to explore alternatives before dismissing employees whose roles become automated. Dutch employment law requires you to investigate whether affected employees can be retrained for other positions within your organisation.
This applies even when automation makes certain roles obsolete. You must offer reasonable retraining opportunities to employees at risk of displacement.
The focus should be on skills that allow workers to adapt to technological changes or move into different roles. Simply offering automation as a reason for dismissal without exploring these options can make dismissals unlawful.
Your works council must advise on any restructuring plans related to automation. This includes decisions about which employees receive retraining, how redeployment happens, and what support you provide during transitions.
How does the Dutch data protection Authority (autoriteit persoonsgegevens) view the use of AI and employee monitoring?
The Authority considers employee monitoring through AI a high-risk processing activity under GDPR. You need a clear legal basis for any monitoring, which in an employment relationship is normally a legitimate interest that outweighs the privacy of the staff rather than consent, because consent given by an employee is seldom freely given.
You cannot use AI to process sensitive employee data without meeting strict conditions. The EU AI Act specifically prohibits platforms from processing personal information about workers’ emotional states, beliefs, or psychological data.
This ban extends to workplace monitoring systems that attempt to infer these characteristics. The Authority expects you to implement privacy by design principles in all AI systems.
This means building privacy protections into the technology from the start rather than adding them later. You must use the least intrusive monitoring methods available to achieve your business goals.
What potential liabilities could Dutch employers face with the misuse of AI and automation in employment decisions?
You face significant financial penalties for non-compliance with the AI Act. Prohibited AI practices can result in fines up to €35 million or 7% of global annual turnover, whichever is higher.
High-risk AI systems that fail to meet requirements can lead to fines up to €15 million or 3% of global turnover.
Employees can challenge unfair dismissals resulting from automated decisions. Courts have ruled that directors and employers must maintain human oversight of workplace safety and employment decisions.
Relying entirely on automated output without a genuine human assessment makes a dismissal considerably harder to justify before the sub-district court.
You risk retroactive classification issues if you misuse AI in determining worker status. From January 2025, the Dutch Tax Authority resumed enforcement against sham self-employment.
If your AI systems classify workers incorrectly, you could face corrections going back several years. Penalties for intentional misclassification may also apply.
Data protection violations can lead to claims from individual employees and investigations by the Dutch Data Protection Authority.
Employees whose personal data is mishandled through AI systems can seek compensation for damages. The Authority can impose corrective measures and fines based on the severity and scope of violations.


