Metaverse legal frameworks in the Netherlands and the EU

Metaverse legal frameworks digital law

There is no separate metaverse law in the Netherlands. Immersive virtual worlds are governed by ordinary Dutch private law, criminal law and data protection law, layered with directly applicable EU regulations such as the Digital Services Act, the AI Regulation and the GDPR. The practical question is therefore never which metaverse statute applies, but how existing Dutch and European rules attach to avatars, tokens, sensor data and platform terms.

Which European rules already apply to virtual worlds

Every metaverse platform that can be reached from the Netherlands is already regulated, even though none of the instruments involved uses the word metaverse. The Digital Services Act (Regulation (EU) 2022/2065) has applied to all intermediary services since 17 February 2024. It obliges a platform to publish a point of contact, to explain its content moderation in its terms, to operate a notice-and-action mechanism for illegal content and to give reasons whenever it removes content or suspends an account. Very large platforms carry additional risk assessment duties on top of that. In the Netherlands the Authority for Consumers and Markets (Autoriteit Consument en Markt, ACM) acts as Digital Services Coordinator; the implementing act granting it those powers took effect in early 2025, and complaints about providers established here go there. The Digital Markets Act adds interoperability and self-preferencing duties for designated gatekeepers, which matters as soon as a virtual world depends on an app store or an operating system controlled by one of them. Our overview of the EU Digital Services Act (DSA) and Digital Markets Act (DMA) sets out those obligations in more detail.

Diagram illustrating legal gaps in the Metaverse, focusing on property, economy, and safety.

The AI Regulation (Regulation (EU) 2024/1689) is the second pillar, and it bites harder than most operators expect. Its prohibitions on unacceptable AI practices and its AI literacy duty have applied since February 2025 and the rules for general-purpose AI models since August 2025. The transparency duties of Article 50 now apply as well: a person interacting with an AI-driven avatar must be able to tell that they are dealing with a machine, and synthetic image, audio or video content must be marked as artificially generated. The high-risk regime was postponed by the digital omnibus package, to December 2027 for the Annex III use cases and to August 2028 for the Annex I products, so most metaverse operators have breathing space there and none at all on transparency. The separate AI Liability Directive was withdrawn, which means damage caused by an AI system is assessed under ordinary Dutch tort and product liability law.

National implementation lags behind the Regulation itself. Article 57 of the AI Regulation required every Member State to have at least one AI regulatory sandbox operational by 2 August 2026. The Dutch implementing act, which designates supervisors and penalties, went into public consultation on 20 April 2026 and is still working its way through the legislative process; the government has earmarked the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) and the Dutch Authority for Digital Infrastructure (Rijksinspectie Digitale Infrastructuur, RDI) as coordinating supervisors alongside the existing sector regulators. Until that act is in force the Regulation binds you directly, but the national enforcement architecture around it remains provisional. Do not read that as a grace period.

A person places a clear box with a miniature building and an AI logo on sand next to a Dutch flag.

Two further instruments are easy to overlook. The Data Act (Regulation (EU) 2023/2854) has applied since 12 September 2025 and gives the user of a connected product, which includes a VR or AR headset, a right of access to the data the device generates and a right to have it ported to a third party. And where a virtual world issues or trades tokens, the Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114) has applied to crypto-asset service providers since 30 December 2024, with the Dutch Authority for the Financial Markets (Autoriteit Financiele Markten, AFM) responsible for licensing. Genuinely unique non-fungible tokens fall outside that regime, but tokens issued in large series or in fractions can fall squarely inside it.

Who owns virtual land, avatars and digital assets

Under Dutch law you do not own virtual land the way you own a house. Article 3:2 of the Dutch Civil Code (Burgerlijk Wetboek, BW) defines a zaak, a thing capable of ownership, as a tangible object susceptible to human control. A plot in a virtual world is not tangible, so the law of property gives you no title to it. What you acquire is a contractual right against the operator: a licence to use part of its world on the conditions in its terms of service. If the world closes, the rules change or the account is terminated, the remedy lies in contract and not in property. That single point decides most disputes about virtual real estate before they start.

Criminal law reached a different but compatible conclusion. In its judgment of 31 January 2012 in the RuneScape case (ECLI:NL:HR:2012:BQ9251) the Supreme Court held that virtual objects in an online game can be a goed capable of being stolen under Article 310 of the Dutch Criminal Code (Wetboek van Strafrecht, Sr), because the player had factual and exclusive control over them and they represented real value in time and effort. Taking another user’s virtual items by force or deception is therefore theft. That does not convert those items into civil-law property; it shows that the criminal concept of a goed is wider than the civil concept of a zaak.

An NFT changes little in this analysis. The token is an entry on a distributed ledger pointing at an asset, and what you may do with the underlying image, model or plot depends entirely on the licence granted by whoever minted it. Buying an NFT of an artwork almost never transfers copyright, because Article 2 of the Dutch Copyright Act (Auteurswet) requires a deed for the transfer of author’s rights. Read the licence before assuming you bought more than a receipt with a provenance trail attached.

Consumers do get extra protection. Contracts for the supply of digital content and digital services have their own regime in Book 7 BW, implementing the European digital content directive since 2022. A consumer who pays for a virtual item, whether with money or with personal data, can require conformity with what was promised, and the trader must supply updates for as long as the consumer may reasonably expect. Business-to-business deals fall outside that regime and stand or fall on the contract that was actually signed, which is a good reason to negotiate service levels, continuity and exit rather than accept a click-through.

Trade marks, copyright and user-generated content

A brand owner cannot rely on a physical-world registration to cover virtual goods. Trade mark protection is limited to the goods and services listed in the registration, and downloadable virtual goods and NFT-related services have their own place in the classification: the EU Intellectual Property Office expects an applicant to state what the virtual goods relate to, so a claim to virtual clothing must say so instead of leaning on the class for real clothing. In the Netherlands a national mark is filed with the Benelux Office for Intellectual Property under the Benelux Convention on Intellectual Property (BVIE), while an EU trade mark covers every Member State at once. Extending a portfolio to virtual goods and services is a modest defensive cost compared with litigating over a gap in a specification.

A tablet displaying "The Starry Night" and a glass shield with a copyright symbol in an art gallery.

Copyright is where the day-to-day disputes actually arise. The Auteurswet protects any work with its own original character bearing the personal stamp of its maker, and a three-dimensional model, a texture or a piece of world design qualifies as readily as a drawing does. Building a recognisable replica of a protected work of architecture or reproducing a designer’s pattern on an avatar skin is a reproduction, and no disclaimer in the platform’s terms makes it lawful. Design rights and, for a curated collection of assets, database rights can run alongside copyright.

User-generated content adds a second layer. Most platform terms take a broad, worldwide, royalty-free licence over everything a user uploads. Under Dutch law such a licence is valid in principle, but it remains a licence and not a transfer, precisely because a transfer requires a deed. Creators keep their moral rights, and a clause that purports to sweep up everything without limit can be tested against the rules on general terms and conditions in Articles 6:231 to 6:247 BW, which allow a court to set aside a term that is unreasonably onerous. A business building on someone else’s platform should check whether the licence it grants there is compatible with the rights it has already promised its own clients.

Enforcement is workable rather than hopeless. A rights holder can use the notice-and-action route the Digital Services Act requires, can apply for an ex parte injunction in intellectual property matters under Article 1019e of the Dutch Code of Civil Procedure (Rv), and can seek disclosure of an infringer’s identity from the platform where the balance of interests justifies it. What all of this requires is proof of the right and a clean chain of title, which is why the inventory comes first. Our article on intellectual property enforcement in the Netherlands sets out the routes in more detail.

When an agreement made through avatars is binding

An agreement concluded through avatars binds the parties as soon as the ordinary requirements of Dutch contract law are met. Articles 3:33 and 3:35 BW require an intention matching a declaration, or a declaration the other party could reasonably understand as such; Article 6:217 BW requires offer and acceptance; and the resulting obligation must be sufficiently determinable. Dutch law imposes no form requirement for most contracts, so a click, a chat message or a gesture inside a virtual world can create a binding obligation. The difficulty is almost never validity but evidence: who was behind the avatar, what exactly was agreed, and at what moment.

That is why the platform’s terms matter more than the ceremony. Terms of service are general terms and conditions within the meaning of Article 6:231 BW. The user must have had a reasonable opportunity to take note of them before or at the moment of contracting, and for an online service making them available electronically in a form that can be stored satisfies that requirement. Against consumers the lists in Articles 6:236 and 6:237 BW render a series of familiar clauses void or presumed unreasonable, including unilateral changes to the service and sweeping exclusions of liability. Terms drafted for a United States platform and translated without adaptation routinely fail those tests.

Smart contracts do not escape this framework. Self-executing code that transfers a token once a condition is met is a means of performance, not a separate legal category, and neither Dutch nor EU law contains a dedicated smart contract statute. Two consequences follow. First, if the parties never reached agreement, because of mistake within the meaning of Article 6:228 BW or because one of them lacked authority, the transfer can be annulled even though the code executed flawlessly. Second, Article 6:258 BW allows a court to amend or set aside a contract on the ground of unforeseen circumstances, which is exactly what immutable code cannot do by itself. Build an off-chain mechanism for reversal, or accept that a court order and a wallet unable to comply with it will sit uncomfortably together.

Harassment, safety and criminal exposure

Conduct in a virtual world is judged by ordinary Dutch criminal law. Persistently pursuing another user across a platform can amount to belaging (stalking) under Article 285b Sr, which is a complaint offence: prosecution requires a complaint from the victim, so the operator cannot set it in motion and the victim has to act. Insult and defamation, threats, fraud and the theft of virtual items all have their existing provisions, and the Sexual Offences Act (Wet seksuele misdrijven), in force since 1 July 2024, extended the criminal law on sexual harassment and image-based abuse to conduct committed online.

The operator’s exposure is different in kind. A platform is in principle not liable for what its users do, provided it plays a neutral and technical role and acts expeditiously once it has actual knowledge of illegal content; that hosting exemption now sits in Article 6 of the Digital Services Act. Lose the neutrality by curating or promoting the material, or ignore a well-founded notice, and the exemption falls away. What remains is the general Dutch law of tort in Article 6:162 BW: an operator aware of a pattern of abuse that does nothing acts unlawfully towards the users it continues to expose. Age assurance, reporting tools that work and a moderation log are the practical answers.

There is also a supervisory track running alongside the civil and criminal one. Complaints about content moderation go to the ACM as Digital Services Coordinator, complaints about the processing of personal data go to the AP, and a user may take either route while a civil claim is pending. For an operator this means a single incident can produce three parallel files, which is an argument for handling the first serious complaint properly rather than quickly.

What VR and AR data mean under the GDPR

Immersive hardware collects far more than a name and an email address. A headset registers head and hand movement, gaze direction, room geometry, voice and sometimes physiological signals. All of that is personal data whenever it can be linked to an individual, and movement patterns are distinctive enough that the link is usually possible. A common misconception is that eye tracking is automatically special category data. Under Article 9 of the GDPR biometric data forms a special category only when it is processed for the purpose of uniquely identifying a natural person: gaze data used to render a scene efficiently is not, while gaze data used as a login is. Data revealing health or sexual orientation, which behavioural and physiological signals can do, is special category data whatever the intention behind the processing.

Practical obligations follow from that. Systematic monitoring of behaviour on a large scale in a publicly accessible space triggers a data protection impact assessment under Article 35 of the GDPR. Processing children’s data, which is unavoidable on the larger social platforms, requires parental consent below the Dutch age limit of sixteen and an interface a child can actually understand. And because most metaverse infrastructure runs on cloud capacity outside the European Union, Chapter V of the GDPR applies to the transfers: an adequacy decision, or standard contractual clauses supported by a transfer impact assessment.

Which court decides and which law applies

Cross-border is the default state of a virtual world, so the conflict rules do real work. For contracts, Regulation (EC) No 593/2008 (Rome I) allows the parties to choose the applicable law, but Article 6 protects consumers: a choice of law may not deprive a consumer of the protection of mandatory rules of the law of their habitual residence. A Dutch consumer therefore keeps Dutch consumer protection even where the terms declare another law applicable. For non-contractual claims such as infringement or harassment, Regulation (EC) No 864/2007 (Rome II) points as a rule to the law of the country in which the damage occurs.

Jurisdiction follows Regulation (EU) No 1215/2012 (Brussels I bis). A business may generally be sued where it is domiciled and, in contractual matters, where the obligation was to be performed. Consumers are in a stronger position: under Articles 17 to 19 a consumer can sue a trader that directs its activities at their Member State in the courts of their own country, and can only be sued there. A forum clause in platform terms that tries to send a Dutch consumer to a court outside the European Union will usually not be enforceable against them. Where the counterparty sits outside the Union, the real obstacle shifts from jurisdiction to enforcement, which is an argument for arbitration, for security up front, or for simply not contracting on those terms. Our article on how to avoid jurisdiction and enforcement issues explains the choices in a contract that make this manageable.

What to arrange before you launch a virtual presence

Begin with an inventory. List the trade marks, copyrights, designs and databases you intend to use, and check whether the registrations actually cover virtual goods and services. Record who created what and under which contract: copyright in works made by an employee in the course of their duties vests in the employer under Article 7 Auteurswet, while a freelance developer keeps it unless a deed says otherwise. Gaps in the chain of title are cheap to close before launch and expensive to close during a dispute.

Then redraft the paperwork instead of translating it. Terms of service need to state what the user acquires, a licence rather than property, how the world may change, what happens to purchased items if the service ends, how content is moderated and reported, and which law and forum apply, all in a form that survives Articles 6:231 to 6:247 BW. The privacy statement has to describe sensor data honestly and name a legal basis for each purpose, not a generic reference to legitimate interests. If AI-driven characters are part of the experience, add the Article 50 disclosure and keep a record showing when and how it is given.

Finally, decide in advance who answers a notice. The Digital Services Act requires a single point of contact, a working notice-and-action channel and reasoned decisions, and a platform that improvises its first takedown request tends to get it wrong in both directions at once: too slow towards the rights holder and too blunt towards the user. Written procedures, a named owner and a retention period for moderation records turn a legal duty into an operational routine. Involving an IT lawyer at the design stage is considerably cheaper than doing so during a supervisory investigation.

Frequently asked questions about metaverse law

The questions below come up most often from businesses building a presence in a virtual world, and the answers are grounded in Dutch and EU law as it currently stands.

What is the legal status of virtual land?

Currently, "virtual land" does not have the same legal standing as physical real estate under Dutch law. When you buy a plot in a metaverse, you are acquiring a licence—a contractual right to use a specific part of that virtual world, governed by the platform's terms of service. While ownership is often represented by an NFT, the legal strength of these rights is still being tested. It is best to view it as a contractual asset, not real property.

Are businesses liable for AI-controlled avatars?

Yes, a business can be held liable for the actions of its AI-controlled avatars (NPCs). If a corporate NPC provides misleading information causing financial loss or makes defamatory comments, the company that deployed the AI could be held responsible. Liability could arise from Dutch contract law (for misrepresentation) or tort law (for causing harm). Because the transparency duty in Article 50 of the AI Regulation now applies, the business must also make clear to users that they are dealing with an AI system and not a person.

How are cross-border disputes handled?

Resolving cross-border disputes is a major challenge. If a user in Germany has an issue with a Dutch company on a platform hosted in Ireland, which country's laws apply? The answer is usually found in the platform's terms of service, which specify the governing law and jurisdiction. EU regulations like the Brussels I Regulation (Recast) may allow a consumer to sue in their home country. However, enforcement remains complex, making clear contract terms and arbitration clauses vital.

Does GDPR apply to VR and AR data?

Absolutely. The General Data Protection Regulation (GDPR) applies to personal data collected from people in the EU, including in the metaverse. VR and AR headsets can gather sensitive biometric data like eye movements and emotional responses. Under the GDPR, gaze and emotion tracking count as "special category data" only when they are processed in order to identify a person uniquely. In every other case they are ordinary personal data, which still requires a legal basis, transparency and, given the scale of monitoring involved, a data protection impact assessment. Companies must be transparent about what data they collect, why, and how it is secured, as failure to comply can lead to massive fines.


At Law & More, our team combines deep technological insight with robust legal expertise to help you navigate the complexities of metaverse law. Whether you are drafting terms of service, protecting your intellectual property, or ensuring data privacy compliance, we provide the clear, actionable guidance your business needs to thrive in this new digital frontier. Contact us if you would like a virtual-world project reviewed before launch.

Law & More advises businesses and creators on virtual worlds and digital assets: platform terms and licences, intellectual property, data protection, AI compliance and the contracts that sit underneath a virtual presence. If you are preparing a launch or facing a dispute over a digital asset, please contact us to discuss your position.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

Email is personal data processing, and the GDPR applies to it in full. Three obligations

Can a company simply amend its general terms and conditions? The short answer: not always.

Data breaches happen every day in the Netherlands. When they do, someone must take responsibility.

A photo of you online without permission can be removed under Dutch law by two

EU Regulation 261/2004 gives air passengers a right to assistance, to a refund or re-routing,

Facing a conviction can impact family and divorce. Discover your appeal options in the Netherlands

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.