Unsolicited commercial messages are tightly regulated in the Netherlands. The starting point is consent in advance: someone who never asked for your newsletter should not, in principle, receive it.
Legal basis
Article 11.7 of the Telecommunications Act contains the prohibition on spam. Using email, text messages and other electronic communications for commercial, charitable or idealistic purposes is permitted only where the recipient has given prior consent. There is one exception: a party that obtained an email address from a customer in the course of a sale may use it for its own similar products, provided every message offers the opportunity to opt out. Telemarketing to consumers is likewise subject to a consent requirement. The Authority for Consumers and Markets supervises and can impose fines. The GDPR applies in parallel, with the absolute right to object to direct marketing in Article 21.
How it works in practice
Consent must be unambiguous and demonstrable. A pre-ticked box does not qualify; a double opt-in with a log file does. Every message must identify the sender clearly and contain a working unsubscribe facility, free of charge and without requiring a login. Unsubscribes must be processed immediately and retained, because that is precisely the evidence the regulator asks for.
Where it goes wrong
Three points recur. First, purchased or rented address lists, where consent was given to someone else and therefore does not carry over. Second, an over-generous reading of similar products. Third, a customer database that moves across in an acquisition without the legal basis being tested again.
Related terms
Direct marketing connects to cookie consent, to data subject rights and to retention periods.
Unsure whether your mailings are lawful? Our IT lawyers test the legal basis and the opt-in flow.

