Data protection in the Netherlands rests on two instruments. The General Data Protection Regulation applies directly across the European Union and contains the substantive rules: the principles, the lawful bases, the rights of data subjects and the obligations of controllers and processors. Alongside it, the Dutch GDPR Implementation Act fills in the choices the Regulation left to member states and designates the Dutch Data Protection Authority as supervisory authority.
Because the Regulation is directly applicable, it is the GDPR itself that an organisation must comply with. The Implementation Act matters where a national choice has been made – and it is precisely those points that organisations operating in several member states tend to overlook.
What the Implementation Act adds
The Act sets the age at which a child can consent to information society services, provides for processing of special category data in defined situations including the biometric exception for authentication and security purposes, contains provisions on processing criminal data, and regulates exemptions in areas such as journalism, research and archiving. It also sets out the powers of the Data Protection Authority and the procedures around them.
What it does not do is create a lighter regime. Where the Regulation and the Act are read together, the Regulation sets the standard and the Act determines how a limited number of national questions are answered.
The obligations that matter in practice
Four things account for most of the work. A record of processing activities, which is the document a supervisory authority asks for first and which forces an organisation to know what it actually holds. A lawful basis for each processing operation, chosen deliberately rather than defaulting to consent, which is frequently the weakest basis available. Data processing agreements with every processor, and adequate safeguards where personal data leave the European Economic Area. And a working procedure for data subject rights and for breach notification, which has to be capable of operating within the seventy-two-hour notification period.
Enforcement
The Dutch Data Protection Authority can investigate, order measures, impose processing bans and fine up to the maxima the Regulation sets. Alongside regulatory enforcement, individuals can claim compensation, and collective actions in this field have become a real exposure in the Netherlands following the introduction of the collective damages regime.
Frequently asked questions
Do we need a data protection officer?
Only where the Regulation requires one: public authorities, and organisations whose core activities involve large-scale regular monitoring or large-scale processing of special category data. Many organisations appoint one voluntarily, which brings the statutory position and protections with it.
Is consent the safest basis?
Usually the opposite. Consent must be freely given and can be withdrawn at any time, after which the processing must stop. Legitimate interests or the performance of a contract are often the more robust basis, provided the assessment is documented.
Does the GDPR apply to us if we are outside the EU?
It can. The Regulation applies where goods or services are offered to people in the European Union or their behaviour is monitored there, regardless of where the organisation is established.
Advice on data protection
Compliance work is most effective when it starts from what an organisation actually does with data rather than from a template. We advise on processing records, lawful bases, processor agreements, international transfers, impact assessments and breach response. Please contact Law & More; our privacy lawyers are happy to help.

