Compliance Lawyer
Advice or proceedings? Ask for a free introductory meeting.
As a compliance lawyer in the Netherlands, we help businesses meet the rules on privacy, anti-money laundering, sanctions and sector regulation. We also assist when a regulator starts an investigation or imposes a fine. We work for Dutch and international companies, in English and Dutch. The first step is a short scan of your activities, the data you process and the regulators that apply to you.
Clients rate Law & More 9.6 out of 10 on Klantenvertellen, the Dutch review platform (81 reviews, as of October 2026).
What can we help you with?
- GDPR compliance: privacy statements, records of processing and data processing agreements;
- a data breach and the 72-hour notification to the Dutch Data Protection Authority;
- access requests and other data subject rights;
- Wwft obligations: customer due diligence, UBO identification and unusual transaction reports;
- KYC questions from your bank and registration of your UBOs;
- sanctions screening and contracts with parties in high-risk countries;
- a whistleblowing procedure and internal compliance policies;
- investigations, information requests and fines from a regulator.
What does the GDPR require from your business?
The GDPR requires a legal basis for every processing of personal data, transparency towards the people involved and appropriate security. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) supervises compliance and can impose fines of up to 20 million euros or 4 percent of worldwide annual turnover.
In practice, compliance comes down to a few documents and routines. You need a privacy statement, a record of processing activities (Article 30 GDPR) and a data processing agreement with every processor (Article 28). High-risk processing requires a data protection impact assessment (DPIA, Article 35). Some organisations must also appoint a data protection officer.
A data breach must in principle be reported to the Dutch Data Protection Authority within 72 hours after you become aware of it (Article 33). If the breach is likely to result in a high risk for the people involved, you must also inform them. Access requests must be answered within one month, which can be extended by two months for complex requests. Guidance is available on the website of the Dutch Data Protection Authority. For privacy disputes, see also our privacy lawyer page.
Does the Wwft apply to your business?
The Dutch Anti-Money Laundering and Anti-Terrorist Financing Act (Wwft) applies to specific institutions, such as banks, accountants, tax advisers, real estate agents and traders who accept large cash payments. Other businesses are not bound by the Wwft themselves, but they meet its effects through their bank.
Institutions under the Wwft must carry out customer due diligence: identify the client and its ultimate beneficial owners (UBOs) and understand the purpose of the relationship. They must report unusual transactions to the Financial Intelligence Unit (FIU-Nederland) without delay. Supervision depends on the sector: De Nederlandsche Bank, the Dutch Authority for the Financial Markets (AFM), the Financial Supervision Office (BFT) or the Wwft Supervision Office. An EU anti-money laundering regulation will replace much of these rules from July 2027.
Businesses outside the Wwft still have to register their UBOs with the Netherlands Chamber of Commerce (KVK). Banks ask for detailed information on ownership, activities and the origin of funds. An incomplete answer can lead to a frozen account or termination of the banking relationship. Our KYC obligations guide and our article on anti-money laundering compliance explain what to expect.
Which other compliance rules should your business check?
Which rules apply depends on your sector and size. Common topics are sanctions, whistleblowing, competition law and sector-specific supervision.
Sanctions
EU sanctions regulations apply directly in the Netherlands and are enforced through the Sanctions Act 1977. A breach is a criminal offence. Screen your customers, suppliers and their owners, and include sanctions clauses in contracts with parties in high-risk countries.
Whistleblowing and internal policies
Under the Dutch Whistleblowers Protection Act, employers with 50 or more employees must have an internal reporting procedure. Reporters are protected against retaliation. A code of conduct and clear approval processes help to show that compliance is embedded in the organisation. See our corporate compliance checklist.
Sector supervision
Many sectors have their own regulator, such as the Netherlands Authority for Consumers and Markets (ACM) for competition and consumer law. The Netherlands Food and Consumer Product Safety Authority (NVWA) supervises food and product safety. We help you map which rules and regulators apply.
What should you do when a regulator investigates?
You must cooperate with a regulator's reasonable information requests under Article 5:20 of the General Administrative Law Act. If a fine is under consideration, you have the right not to make statements about the alleged violation (Article 5:10a).
Coordinate all contacts with the regulator through one point of contact, and keep a copy of everything you provide. Before a fine is imposed, you can usually give your view in writing or orally. Against a fine decision you can lodge an objection within six weeks, and then appeal to the administrative court. Early legal assistance helps to limit the scope of the investigation and the risk of a fine.
How does working with Law & More work?
- Introductory meeting: we discuss your activities, your question and any deadline, such as a 72-hour breach notification.
- Advice and cost estimate: we identify the rules that apply and the gaps, with a budget for the work.
- Approach and negotiation: we draft the documents and policies, or deal with the bank or regulator on your behalf.
- Proceedings or completion: we finalise the compliance set-up or conduct objection and appeal proceedings.
What does a compliance lawyer cost?
Our hourly rate is 250 to 350 euros excluding VAT for a lawyer and 300 to 400 euros excluding VAT for a partner. We agree the rate in advance and can give a budget for a defined project, such as a GDPR review.
The introductory meeting is free of charge. A one-off advice meeting without further assistance costs 300 euros including VAT. Court fees (griffierecht) in appeal proceedings are charged separately. Legal aid via the Legal Aid Board (Raad voor Rechtsbijstand) exists, but we do not work on that basis. We do not give tax advice.
Who handles your case?
Privacy and GDPR matters are handled by Aylin Acar. Anti-money laundering, KYC and corporate compliance are handled by our corporate lawyers Tom Meevis, founder and managing partner, and Ruby van Kersbergen. You can meet the whole team on our team page.
Frequently asked questions
When does a business need a compliance lawyer?
Typically when you start processing personal data at scale, enter a regulated sector or expand into new countries. A compliance lawyer is also useful when your bank asks difficult KYC questions or a regulator sends an information request. Advice at an early stage is usually cheaper than repairing a problem after a complaint, data breach or investigation.
How quickly must a data breach be reported?
A data breach must in principle be reported to the Dutch Data Protection Authority within 72 hours after you become aware of it. No notification is needed if the breach is unlikely to result in a risk to people's rights and freedoms. Record every breach internally, also when you do not report it. High-risk breaches must also be reported to the people affected.
Does every company need a data protection officer?
No. A data protection officer is mandatory for public authorities and for organisations whose core activities involve large-scale monitoring of individuals or large-scale processing of sensitive data. Other businesses may appoint one voluntarily. Even without a data protection officer, someone in the organisation should be responsible for privacy compliance.
My bank is asking for KYC information. Do I have to answer?
The bank is legally required to know its customers and their UBOs, and may end the relationship if it cannot complete that review. It is generally wise to answer completely and consistently. If the questions are unclear or disproportionate, ask the bank which information it needs and why. We can help prepare the answers and the supporting documents.
What are the fines for GDPR violations?
The GDPR allows fines of up to 20 million euros or 4 percent of worldwide annual turnover, whichever is higher. The Dutch Data Protection Authority sets the fine by reference to the seriousness of the violation and the circumstances. In addition, people whose rights were infringed can claim damages. Most investigations start after a complaint or a reported data breach.
Must my company have a whistleblowing procedure?
Yes, if you employ 50 or more people. The Dutch Whistleblowers Protection Act then requires an internal procedure for reporting suspected wrongdoing. The procedure must explain how reports are made, handled and protected. If you have a works council, its consent is required for the procedure. Smaller employers may still benefit from a simple reporting route.
In doubt about your position? Tell us about your situation. We will let you know within one working day what your options are. Use our contact form, call +31 40 369 06 80 or e-mail info@lawandmore.nl.
Law & More, Marconilaan 13, 5612 HM Eindhoven (+31 40 369 06 80) and visiting location Pietersbergweg 291, 1105 BM Amsterdam (+31 20 369 71 21). Available Monday to Friday 08:00-22:00, Saturday and Sunday 09:00-17:00.
This page provides general information and does not replace advice on your specific situation.
Latest articles on corporate law
Recent articles by Law & More on corporate law.
- Reading time: 6 min
- Reading time: 6 min
Under Dutch law you may, as a rule, break off negotiations without paying anything. Liability
- Reading time: 8 min

