The GDPR and the Dutch Implementation Act

General Data Protection: Understanding the New Rules

Data protection in the Netherlands rests on two instruments. The General Data Protection Regulation (GDPR) applies directly across the European Union and sets the substantive rules: the principles, the lawful bases, the rights of data subjects and the obligations of controllers and processors. Alongside it, the Dutch GDPR Implementation Act (Uitvoeringswet AVG, UAVG) fills in the choices the Regulation left to member states and designates the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) as supervisory authority.

Because the Regulation is directly applicable, it is the GDPR itself that an organisation must comply with. The Implementation Act matters where a national choice has been made – and it is precisely those points that organisations operating in several member states tend to overlook.

What does the Implementation Act add?

The UAVG fills in a limited number of national choices. Under article 5 UAVG, a child under sixteen needs a parent’s or guardian’s consent before information society services may rely on consent as the lawful basis; from sixteen the child can consent alone.

The Act also provides for processing of special category data in defined situations. Article 29 UAVG allows biometric data to be processed for unique identification where this is necessary for authentication or security purposes, an exception organisations use for access control and login systems. The UAVG further contains provisions on processing criminal data and regulates exemptions in areas such as journalism, research and archiving, and it sets out the powers of the Data Protection Authority and the procedures around them.

What it does not do is create a lighter regime. Where the Regulation and the Act are read together, the Regulation sets the standard and the Act determines how a limited number of national questions are answered.

Which obligations matter in practice?

Four things account for most of the work. A record of processing activities under article 30 GDPR, which is the document a supervisory authority asks for first and which forces an organisation to know what it actually holds. A lawful basis for each processing operation, chosen deliberately rather than defaulting to consent, which is frequently the weakest basis available because it must be freely given and can be withdrawn at any time.

Data processing agreements with every processor under article 28 GDPR, and adequate safeguards where personal data leave the European Economic Area. And a working procedure for data subject rights and for breach notification, which has to be capable of operating within the seventy-two-hour notification period of article 33 GDPR.

How is the GDPR enforced?

The Dutch Data Protection Authority can investigate, order measures, impose processing bans and fine organisations. Under article 83 GDPR, fines run up to €10 million or 2% of total worldwide annual turnover for breaches of administrative obligations, and up to €20 million or 4% of turnover, whichever is higher, for breaches of the core principles, data subject rights or international transfer rules.

Alongside regulatory enforcement, individuals can claim compensation, and collective actions in this field have become a real exposure in the Netherlands since the introduction of the collective damages regime (WAMCA) in 2020.

In summary

  • The GDPR sets the substantive rules directly; the UAVG only fills in the national choices the Regulation leaves open.
  • Under article 5 UAVG, a child needs parental consent for information society services until the age of sixteen.
  • Article 29 UAVG allows biometric data to be used for authentication or security purposes as an exception to the general prohibition.
  • A record of processing activities, a lawful basis per processing operation, processor agreements and a breach procedure covering the seventy-two-hour notification period account for most compliance work.
  • Fines under article 83 GDPR run up to €20 million or 4% of worldwide turnover, and individuals and groups can claim compensation separately.

Frequently asked questions

Do we need a data protection officer?

Only where the Regulation requires one: public authorities, and organisations whose core activities involve large-scale regular monitoring or large-scale processing of special category data. Many organisations appoint one voluntarily, which brings the statutory position and protections with it.

Is consent the safest basis?

Usually the opposite. Consent must be freely given and can be withdrawn at any time, after which the processing must stop. Legitimate interests or the performance of a contract are often the more robust basis, provided the assessment is documented.

Does the GDPR apply to us if we are outside the EU?

It can. The Regulation applies where goods or services are offered to people in the European Union or their behaviour is monitored there, regardless of where the organisation is established.

Advice on data protection

Compliance work is most effective when it starts from what an organisation actually does with data rather than from a template. We advise on processing records, lawful bases, processor agreements, international transfers, impact assessments and breach response.

Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.

How Law & More can help you with this is explained on our IT lawyer page.

Tom Meevis
Tom Meevis is an attorney-at-law at Law & More in Eindhoven and Amsterdam. He handles general practice and is the negotiator and litigator of the firm.

Need Legal Assistance?

Have you received a letter, a writ of summons or a judgment? Send us the documents. We will check which deadlines apply and what your options are.

This article provides general information and is not a substitute for advice on your specific situation.

Related articles

An electronic signature has the same legal effect as a handwritten one in the Netherlands,

Algorithmic management, the use of AI systems to monitor, score and steer employees, is permitted

Explore the general data protection law in the Netherlands for a clear understanding of its
Agile development calls for different contractual arrangements: best-efforts or results obligation, acceptance criteria, deadlines and

High-risk AI systems are the focal point of the European AI Regulation (Regulation (EU) 2024/1689),

The EU AI Act (Regulation (EU) 2024/1689) does not literally require a document called an

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.