Deepfakes under Dutch law: which offences apply to fake videos

Deepfakes and Dutch Criminal Law

Deepfakes under Dutch law are not a separate criminal offence. Dutch criminal law reaches deepfakes through the offences that already exist: misuse of sexual imagery under article 254ba of the Dutch Criminal Code (Wetboek van Strafrecht), fraud, doxing, stalking and defamation. Alongside those, portrait rights under the Copyright Act and the GDPR give victims a civil and administrative route. Research published by the WODC, the research centre of the Ministry of Justice and Security, concluded in 2022 that the gap is not in the legislation but in enforcement.

That conclusion still shapes government policy. In 2026 the cabinet again told parliament that it saw no need for a separate deepfake statute and pointed instead to the criminal code, the Copyright Act, the General Data Protection Regulation and the European Digital Services Act. For anyone who has been targeted, that answer is only half comforting: the rules exist, but you usually have to enforce them yourself, quickly, and often against an anonymous account.

A lawyer in a modern office with legal documents and a laptop showing a blurred video, with Dutch flag and law books in the background.

This article sets out how deepfakes under Dutch law are treated: which offences apply to manipulated video, audio and images, which civil claims are open to you, what the platforms must do, and what practical steps preserve your position. Dutch criminal law is the starting point, but in most cases the fastest result comes from a combination of criminal and civil action.

What counts as a deepfake under Dutch law

A deepfake is synthetic audiovisual material in which a real person appears to say or do something they never said or did, generated with machine learning from existing footage, photographs or voice recordings. Dutch legislation does not define the term. It regulates conduct and harm, not the technology, which is why the same clip can be lawful satire in one context and a criminal offence in another.

The technical barrier has collapsed. Producing a convincing face swap or a cloned voice no longer requires a studio, a data set of thousands of images or specialist knowledge; consumer applications do it from a handful of photographs. That is the reason the volume of material has outrun the capacity of the police and the Public Prosecution Service, and it is why prevention and speed of removal matter more than the theoretical availability of a criminal charge.

The WODC study found that more than ninety-five per cent of the deepfakes circulating between private individuals at the time were potentially punishable under existing Dutch law. The overwhelming majority of that material was sexual, made without the consent of the person depicted. Political manipulation, fraudulent voice cloning of company directors and fabricated evidence in litigation are all real, but numerically they remain a small part of the problem.

One consequence of regulating conduct rather than technology deserves emphasis. Creating a deepfake for your own use is, in itself, rarely an offence. Liability generally attaches to what you do with it: distributing it, using it to obtain money, using it to frighten or discredit someone, or possessing it where the law criminalises possession, as it does for sexual material.

Sexual deepfakes: article 254ba and article 252 of the Criminal Code

A person in formal attire holding a digital tablet showing a distorted human face with pixelated effects in a courtroom setting with legal books and a judge's bench.

Since the Wet seksuele misdrijven (Sexual Offences Act) entered into force on 1 July 2024, the misuse of sexual imagery is dealt with in article 254ba of the Criminal Code. The provision covers making, obtaining, possessing and disclosing images of a sexual nature of another person without that person’s consent, and it is not limited to authentic recordings: manipulated and fabricated material falls within its scope. This replaced the earlier stand-alone provision on so-called revenge pornography and placed the offence in the title of the code dealing with sexual offences, alongside the other conduct the Act renewed.

Two points follow for victims. First, you do not have to show that the images are real; you have to show that they depict you in a sexual context and that you never consented. Second, consent given once, for one purpose, is not consent to onward publication. A person who received intimate material lawfully commits an offence by passing it on, and the same applies to a person who feeds that material into a generator and shares the output.

Where the person depicted is a minor, article 252 of the Criminal Code applies. That provision covers sexual images of children, including material that is entirely computer generated and depicts no real child. Nudify applications used on classroom photographs therefore sit squarely in the most serious part of the criminal code, and the fact that the pupil was never photographed unclothed is no defence. Schools that discover this material should treat it as a police matter rather than an internal disciplinary issue.

The cabinet has told parliament that it is examining whether the nudify applications themselves can be restricted, nationally and at European level, but has not committed to a proposal. Until it does, the position is that the output is criminal while the tool is not.

Fraud, identity fraud and extortion with synthetic media

Using a deepfake to obtain money or goods is fraud under article 326 of the Criminal Code, which penalises inducing another person to hand over property by adopting a false name or false capacity, or by cunning and a web of untruths. A cloned voice on a telephone call, a fabricated video message from a director authorising a payment, or a synthetic identity used to open an account all fit that description; the technology is simply the means of deception. Where forged documents accompany the deception, forgery provisions apply in addition.

Identity fraud is more awkward than it looks. Article 231b of the Criminal Code penalises the unlawful use of another person’s identifying personal data, but it expressly excludes biometric data. A cloned face or voice is biometric, so the neat label of identity theft does not always deliver a charge under that article. In practice the prosecution is built on fraud, forgery or, where money has moved, money laundering. This is a good illustration of why an accurate legal analysis matters more than the label used in the news coverage of a case.

Threatening to publish a deepfake unless the victim pays or performs is extortion. Where the threat is one of violence, article 317 applies; where the threat is to reveal something damaging, including fabricated intimate imagery, article 318 is the relevant provision. Sextortion cases involving generated material are prosecuted on that basis, and the fact that the material is fake does not weaken the case: the harm lies in the coercion. Our guide on fraud in the Netherlands sets out how these investigations are usually built.

Companies should note the civil consequence as well. A payment made by an employee who was deceived by a cloned voice is rarely recoverable from the bank, and internal authorisation procedures that rely on recognising a voice or a face on a video call no longer offer meaningful protection. Payment controls should require a verification step that a synthetic recording cannot pass.

Defamation, doxing and stalking

A deepfake that presents a person as having said or done something disgraceful can amount to smaad (defamation) under article 261 of the Criminal Code, or laster (calumny) under article 262 where the maker knew the imputation was false. Because a generated clip is by definition untrue and its maker knows it, the aggravated form is often the better fit. A clip that merely insults without imputing a specific fact falls under simple insult in article 266. All three are complaint offences in most circumstances, which means the Public Prosecution Service acts on the victim’s formal complaint rather than on its own initiative.

Publishing a person’s home address, workplace or telephone number alongside manipulated material, in order to intimidate them, is a separate offence. Article 285d of the Criminal Code, in force since the beginning of 2024, penalises obtaining, disseminating or otherwise making available another person’s identifying data with the intention of causing that person fear or serious nuisance. Deepfake campaigns very often combine the two, and charging them together reflects the reality of the harm.

Where the conduct is persistent rather than a single publication, belaging (stalking) under article 285b of the Criminal Code comes into view. It requires a systematic and deliberate intrusion into someone’s private life aimed at forcing them to do or tolerate something, or at instilling fear. It is a complaint offence, so the victim must lodge a formal complaint within the statutory period; letting that period run is one of the more damaging mistakes victims make. The same conduct online can also give rise to criminal liability for the people who amplify the material rather than create it.

Reputation cases are rarely won on the criminal track alone. A conviction can take a year or more, while the material spreads in days. In practice the criminal complaint runs in parallel with civil steps, and our discussion of defamation online and of false statements explains where each route is effective.

Portrait rights and civil claims: the fastest route

Dutch civil law gives you the tools that actually stop distribution. Article 21 of the Auteurswet (Copyright Act) allows a person whose portrait is published without a commission to oppose publication where they have a reasonable interest in doing so. A portrait is not limited to a photograph: any recognisable depiction qualifies, and a synthetic likeness that viewers recognise as you is a portrait for these purposes. Where the material is sexual, degrading or commercially exploitative, the reasonable interest is straightforward to establish. Our overview of portrait rights in a wider context sets out how courts weigh that interest.

Alongside portrait rights, article 6:162 of the Burgerlijk Wetboek (Civil Code) provides the general tort action. Publishing a fabricated depiction of a person breaches both the general duty of care and, in most cases, the right to private life protected by article 8 of the European Convention on Human Rights. The court balances that right against the freedom of expression in article 10 of the Convention, and the balance tips decisively against material that is false and gratuitously harmful. Damages for reputational and emotional harm are available, and a court can order rectification.

The instrument that matters most is the kort geding, the preliminary relief procedure before the voorzieningenrechter. It delivers an enforceable order within weeks, and in urgent cases within days, ordinarily reinforced by a penalty payment for each day of non-compliance. Orders can be directed at the maker, at the person sharing the material, and at the hosting provider or platform. Because a hosting provider that has been given actual knowledge of manifestly unlawful content loses its liability shield, a properly drafted notice frequently produces removal before proceedings are ever issued. That is why the wording and the evidence in the first letter are worth more than the volume of correspondence that follows. Our note on liability under Dutch law explains how those thresholds work.

What the GDPR adds, and what it does not

A courtroom in the Netherlands with legal professionals discussing a blurred video on a screen, representing deepfake videos in a legal setting.

A deepfake of an identifiable person is processing of personal data, so the General Data Protection Regulation applies. Where facial or voice data is processed in order to identify a person uniquely, it is biometric data in the special category of article 9, which is prohibited unless a narrow exception applies. Sexual deepfakes will also reveal, or purport to reveal, data about a person’s sex life, which is separately protected. The practical value of this is the right to erasure in article 17 and the right to rectification of inaccurate data, both of which can be exercised directly against the party publishing the material.

The limit is equally important. The GDPR contains an exemption for processing by a natural person in the course of a purely personal or household activity, so a file kept on a private device may fall outside its reach altogether; and member states must reconcile the Regulation with freedom of expression, which protects journalistic and artistic processing. The Regulation is therefore a strong instrument against platforms, employers, advertisers and websites that host or exploit the material, and a weaker one against an individual acting privately. The wider framework is set out in our guide to GDPR rules in the Netherlands and in our overview of data protection obligations.

The supervisory authority is the Autoriteit Persoonsgegevens, which can investigate, order a controller to stop processing and impose administrative fines. It has published a model letter that a victim can use to demand deletion of personal data, and it has repeatedly warned about synthetic sexual imagery. It does not, however, act as a takedown service for individual cases, and it cannot award you compensation. Damages under article 82 of the Regulation are claimed in the civil court, together with the tort claim.

What the AI Act and the Digital Services Act require

European legislation regulates the supply chain rather than the individual wrongdoer. The AI Act imposes a transparency obligation in article 50: deployers of a system that generates or manipulates image, audio or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated, and providers must mark the output in a machine-readable format. The obligation is narrowed where the material is evidently artistic, satirical or fictional, in which case the disclosure must not spoil the display of the work. Those transparency rules already apply; the postponements agreed in the digital omnibus package concerned the high-risk regime, not article 50.

Transparency is not the same as prohibition. The AI Act does not ban the generation of a person’s likeness, and it does not give the depicted person a right of action. It creates supervisory obligations on providers and deployers, enforced by market surveillance authorities. If you are looking for a remedy, the AI Act is a supporting argument, not the claim itself. The question of who answers for an automated system that causes harm is dealt with separately in our discussion of artificial intelligence and criminal responsibility.

The Digital Services Act is the more useful instrument in day-to-day practice. Every hosting service must operate a notice and action mechanism, must give reasons when it removes or refuses to remove content, and must offer an internal complaint procedure and access to out-of-court dispute settlement. Very large online platforms must assess and mitigate systemic risks, which expressly include gender-based violence and negative effects on physical and mental wellbeing. A refusal to act on a well-documented notice is now a regulatory failure that can be reported to the Dutch digital services coordinator, which is a lever that did not exist a few years ago.

Why enforcement, not legislation, is the bottleneck

The WODC study framed the problem precisely: enforcement only becomes possible once the damage has been done. By the time a victim discovers the material, it has usually been copied, and every copy is a separate publication with a separate host. Removal at the source does not remove the mirrors, and the mirrors are frequently hosted outside the European Union.

Attribution is the second obstacle. Most material is uploaded from accounts that carry no verified identity, often through services that retain little data and are established in jurisdictions that do not cooperate readily. Obtaining subscriber data requires a criminal investigation or a court order against the intermediary, and both take time that the victim does not have. Where the trail ends at a payment or an advertising account, it can be picked up again, which is why financial evidence is often more productive than technical evidence.

Detection is the third. As generation improves, the visual artefacts that used to betray a manipulation disappear, and forensic analysis becomes an expert exercise rather than a matter of looking closely. That has a consequence inside the courtroom as well: audiovisual evidence can no longer be assumed to be authentic, and a party relying on a recording should expect to be asked to substantiate its provenance. Anyone facing criminal charges based on a recording should have that provenance tested at the earliest opportunity.

None of this argues for waiting. It argues for acting on the first day, documenting properly, and using the civil route to compel intermediaries while the criminal complaint takes its course. A specialist cybercrime lawyer will normally start both tracks at once.

Where satire ends and liability begins

Freedom of expression under article 10 of the European Convention protects opinion, criticism, caricature and parody, and it protects them most strongly in political debate. Public figures must tolerate more scrutiny and more mockery than private individuals, and a court will take that into account. A clearly recognisable parody of a minister is a different case from a fabricated confession attributed to a private citizen, even if the same tool produced both.

The test Dutch courts apply is a balancing exercise, not a formula. The weight of the interference depends on whether the material states verifiable facts or expresses an opinion, whether it has a basis in the facts, how it was presented, how widely it was distributed, what purpose it served, and how severely it affects the person depicted. Sexual material and material presented as an authentic recording of something that never happened almost always lose that balance, because they contribute nothing to public debate and the harm is severe. The considerations are set out further in our articles on media law and on the boundaries of public debate.

Labelling helps but does not decide. Marking a clip as generated, as the AI Act requires, reduces the risk of deception, and it may be enough to keep a piece of political satire lawful. It does not cure a portrait-right infringement, it does not make sexual imagery lawful, and it is no answer to a defamation claim once the clip has been stripped of its label and reposted. Businesses using synthetic media in campaigns should secure written permission from every person whose likeness or voice is used, and our note on media law and business strategy explains why that permission should be specific about the medium and the term. Where an existing work is used as raw material, the rights in that work also have to be cleared, a point developed in our article on how art law is developing in the Dutch market and in our guide to intellectual property enforcement.

One legislative avenue has been closed off. A proposal to give people a copyright in their own face and voice, following an approach floated elsewhere in Europe, has been rejected by the cabinet on the ground that copyright exists to allow the maker of a work to exploit it, not to give a person ownership of their appearance. Portrait rights, tort and the criminal code remain the route.

What to do if a deepfake of you is circulating

Secure the evidence before anything else. Take full-screen captures that show the web address, the account, the date and the number of views, download the file itself, and record the moment you became aware of it. Do not contact the uploader from your own account and do not comment publicly; both tend to increase distribution and can compromise a later criminal complaint. If the material is sexual, it should not be forwarded further, even to friends who offer to help, because onward distribution is itself the offence.

Then run the two tracks in parallel. Report the matter to the police and, where the offence requires it, lodge a formal complaint within the statutory period, because for stalking and for the defamation offences the prosecution cannot proceed without it. At the same time, send a substantiated notice to the platform under its notice and action mechanism, and a letter to the maker and the distributors demanding removal, a statement of everyone the material was sent to, and destruction of the copies. Where that produces nothing within a few days, preliminary relief proceedings are the appropriate step; a penalty payment attached to the order is what makes it effective.

Keep the compensation claim alive while you do this. Damage to reputation, loss of income, therapy costs and the costs of technical removal services are recoverable, and article 82 of the GDPR provides an additional basis where personal data has been processed unlawfully. Claims are subject to limitation periods, which is a further reason not to let a case drift. Our article on the consequences of false accusations describes how these claims are quantified in practice.

Employers, schools and boards face a parallel question: what do you owe the person depicted. A duty of care generally requires an organisation to stop internal circulation, to preserve the evidence, to report the matter where the material involves a minor, and to refrain from acting on an unverified recording in a disciplinary process. Dismissing an employee on the strength of a video that turns out to be generated is an expensive mistake.

How Law and More can help

Law and More advises on deepfakes under Dutch law and acts for people and organisations confronted with manipulated video, audio and imagery. We assess which offences apply, lodge the criminal complaint, send the notices that make a platform lose its liability shield, and, where removal does not follow, bring preliminary relief proceedings with a penalty payment. Alongside that we pursue compensation and advise organisations on the verification procedures and consent arrangements that prevent these cases in the first place. Our lawyers work in criminal law, privacy and media law, so a case is handled on all three tracks at once. Please contact us if you would like to discuss your situation.

Frequently asked questions

What legal consequences do creators of deepfake content face under Dutch criminal law?

Creators of deepfakes face prosecution under several existing criminal statutes in the Netherlands. Since 1 July 2024, article 254ba of the Dutch Criminal Code covers images of a sexual nature made, possessed or shared without consent, including manipulated and fabricated material; article 252 applies where a minor is depicted. Deepfakes used to obtain money fall under fraud, and material that presents someone as having done something disgraceful can amount to defamation. The penalty depends on which offence is committed.

How does the law in the Netherlands address the distribution of misleading videos?

Dutch law addresses misleading video distribution through multiple legal frameworks. The distribution of deepfakes can constitute fraud or deception, which are already prohibited under existing criminal statutes. Distributors can be held criminally liable for spreading manipulated content that causes harm or deceives others. Civil law also provides victims with grounds to demand that distributors remove deepfake content from online platforms.

Are there specific regulations pertaining to the use of deepfakes in cyberbullying or harassment?

Dutch criminal law has no deepfake-specific rules for cyberbullying. Stalking under article 285b of the Criminal Code applies to a systematic campaign, and publishing someone else identifying details in order to frighten them is doxing under article 285d. Sexual deepfakes fall under article 254ba. Victims can pursue criminal charges against perpetrators who create or distribute intimate deepfakes without consent.

What are the privacy implications of deepfakes for individuals in the context of Dutch law?

Deepfakes violate privacy rights under Dutch data protection law and the GDPR. The Dutch Data Protection Authority considers deepfakes a form of incorrect personal data that individuals can request to have removed. You have the right to demand removal of deepfakes featuring your image. The GDPR requires that portrayed persons be informed when they appear in deepfakes, though enforcement remains challenging.

How does Dutch criminal law differentiate between satire and harmful deepfake content?

Dutch criminal law does not currently provide clear guidelines for distinguishing satirical deepfakes from harmful ones. The determination depends on the context, intent, and potential harm caused by the manipulated content. Courts consider whether the deepfake deceives viewers or causes damage to the subject. Satirical content may receive more protection, but this remains a grey area requiring case-by-case evaluation.

What measures can victims of deepfake-related crimes take according to the legal system in the Netherlands?

You can file a criminal complaint with Dutch police if a deepfake violates criminal law. This includes cases involving fraud, identity theft, or revenge porn. Under civil law, you can summon the creators and distributors of deepfakes to remove the content. You can use the removal request letter provided by the Dutch Data Protection Authority to demand deletion of your personal data. Legal experts can help you pursue enforcement action against websites hosting deepfake material.

Looking for something else? Our index of Dutch criminal law guides lists everything we have written on this subject, ordered by topic.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

A traffic offence in the Netherlands can lead to two entirely separate responses at the

Organised crime reaches ordinary citizens through three bodies of law at once, and the one

Driving under the influence of drugs is an offence under Article 8 of the Road

Learn about Cross‑Border Criminal Investigations: Your Rights and Defence in the Netherlands. Clear guidance for

If you are a suspect in the Netherlands, two rights determine the outcome of your

Bullying is a repeated pattern of behaviour in which one person or group deliberately harms

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.