The GDPR and the Dutch Implementation Act

General Data Protection: Understanding the New Rules

Data protection in the Netherlands rests on two instruments. The General Data Protection Regulation applies directly across the European Union and contains the substantive rules: the principles, the lawful bases, the rights of data subjects and the obligations of controllers and processors. Alongside it, the Dutch GDPR Implementation Act fills in the choices the Regulation left to member states and designates the Dutch Data Protection Authority as supervisory authority.

Because the Regulation is directly applicable, it is the GDPR itself that an organisation must comply with. The Implementation Act matters where a national choice has been made – and it is precisely those points that organisations operating in several member states tend to overlook.

What the Implementation Act adds

The Act sets the age at which a child can consent to information society services, provides for processing of special category data in defined situations including the biometric exception for authentication and security purposes, contains provisions on processing criminal data, and regulates exemptions in areas such as journalism, research and archiving. It also sets out the powers of the Data Protection Authority and the procedures around them.

What it does not do is create a lighter regime. Where the Regulation and the Act are read together, the Regulation sets the standard and the Act determines how a limited number of national questions are answered.

The obligations that matter in practice

Four things account for most of the work. A record of processing activities, which is the document a supervisory authority asks for first and which forces an organisation to know what it actually holds. A lawful basis for each processing operation, chosen deliberately rather than defaulting to consent, which is frequently the weakest basis available. Data processing agreements with every processor, and adequate safeguards where personal data leave the European Economic Area. And a working procedure for data subject rights and for breach notification, which has to be capable of operating within the seventy-two-hour notification period.

Enforcement

The Dutch Data Protection Authority can investigate, order measures, impose processing bans and fine up to the maxima the Regulation sets. Alongside regulatory enforcement, individuals can claim compensation, and collective actions in this field have become a real exposure in the Netherlands following the introduction of the collective damages regime.

Frequently asked questions

Do we need a data protection officer?

Only where the Regulation requires one: public authorities, and organisations whose core activities involve large-scale regular monitoring or large-scale processing of special category data. Many organisations appoint one voluntarily, which brings the statutory position and protections with it.

Is consent the safest basis?

Usually the opposite. Consent must be freely given and can be withdrawn at any time, after which the processing must stop. Legitimate interests or the performance of a contract are often the more robust basis, provided the assessment is documented.

Does the GDPR apply to us if we are outside the EU?

It can. The Regulation applies where goods or services are offered to people in the European Union or their behaviour is monitored there, regardless of where the organisation is established.

Advice on data protection

Compliance work is most effective when it starts from what an organisation actually does with data rather than from a template. We advise on processing records, lawful bases, processor agreements, international transfers, impact assessments and breach response. Please contact Law & More; our privacy lawyers are happy to help.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

An employer that wants to employ someone from outside the EU, the EEA or Switzerland

When may you collect and reuse platform data? Database rights, copyright, contract, art. 138ab Dutch

A negative review is not unlawful because it is negative. A customer is entitled to

On 11 January 2024, the EU Data Act – Regulation (EU) 2023/2854 – entered into

Almost every company with a Dutch-facing website publishes a privacy policy — a privacyverklaring or

Sharing personal data under the GDPR is lawful only where the organisation that discloses the

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.