Your software supplier misses its deadline, your SaaS platform is down for days, or you discover a data breach on a Friday evening. Or you want to launch an AI tool and do not know which European rules apply. We act as IT lawyer in the Netherlands on IT contracts, software, data and digital regulation, and on disputes when an IT project fails.

Clients rate Law & More 9.6 out of 10 on Klantenvertellen, the Dutch review platform (81 reviews, as of October 2026).

A lawyer in the Netherlands carries the protected title advocaat and is registered with the Netherlands Bar (NOvA). A Dutch IT lawyer combines that status with knowledge of technology and contract law.

When do you need an IT lawyer in the Netherlands?

You need an IT lawyer in the Netherlands when contracts, rights or obligations around software, data or digital services are at stake. You instruct one to manage risks before signing, or to resolve a dispute with a supplier, customer or regulator.

Companies and technology businesses contact us in situations like these:

  • you are negotiating a SaaS, licence or software development agreement and want to know which liability and exit terms to accept;
  • an IT project overruns, costs far more than budgeted or delivers software that does not work;
  • you want to know who owns custom software, source code or a database;
  • you have a data breach and must decide within 72 hours whether to notify the Dutch Data Protection Authority;
  • you develop or use AI and want to know what the AI Act requires of you;
  • your organisation may fall under NIS2, the Data Act or the Digital Services Act;
  • someone uses your trade mark in a domain name, or your webshop receives a complaint about consumer law.

Which related services can we help you with?

For specific questions within this area of law, these pages go into more detail.

What should IT contracts such as SaaS, licences and SLAs cover?

A sound IT contract states what is delivered, which availability applies, who owns the software and the data, and how you exit. If one of these elements is missing, disputes about what the supplier actually had to do are almost inevitable.

Under a SaaS agreement you use software as a service over the internet. You receive access, not a copy of the software. Terms on availability, security, data location and the return of your data at the end of the contract are therefore essential.

Under a licence you receive a right of use, while the developer keeps the copyright. The licence defines the number of users, locations and permitted purposes. If you exceed those limits, you infringe and the licensor can claim additional fees or damages.

A Service Level Agreement (SLA) sets the agreed service quality in measurable terms. Think of availability of 99.5 per cent per month, response times per priority level and a service credit if the supplier fails to meet them.

Source code escrow protects you if the supplier goes bankrupt or stops maintenance. The source code is deposited with an independent agent and released to you on a defined trigger event, such as bankruptcy.

Under a software development agreement, a supplier builds custom software for you. Record the expected functionality, how acceptance testing works and when the software counts as delivered. A fixed acceptance procedure, for example 10 working days of testing, prevents many disputes later.

Contract elementWhat you agree
Description of servicesFunctionality, specifications and what falls outside scope
SLAAvailability, response and repair times, service credits
Intellectual propertyAssignment or licence, open source components, pre-existing building blocks
Data and privacyData location, security, data processing agreement
LiabilityCap, excluded damage, notice periods for complaints
ExitReturn of data, migration support, escrow, notice period

General terms and conditions of a supplier apply only if they were made available in time. Under Article 6:233 of the Dutch Civil Code an unreasonably onerous clause can be annulled. That protection does not extend to large companies (Article 6:235 of the Dutch Civil Code).

What can you do when an IT project fails?

If a supplier fails to deliver or delivers defective work, you can claim performance, termination or damages. In most cases you must first give the supplier formal written notice and a reasonable period to put things right.

A failure to perform entitles you to damages under Article 6:74 of the Dutch Civil Code, unless the failure cannot be attributed to the supplier. Formal notice of default (ingebrekestelling) is governed by Article 6:82. In it, you set a concrete period, for example 14 days, to remedy the defects.

Termination of the contract is possible under Article 6:265. In an IT project, termination does not always mean you get everything back. Parts already delivered and usable often fall outside the termination.

There is also a duty to complain. Under Article 6:89 you must complain within a reasonable time after discovering a defect, or you may lose your rights. Record defects in writing straight away, with dates, screenshots and ticket numbers.

Suppliers usually cap their liability, for example at 12 months of fees, and exclude consequential loss. Such a cap generally does not protect a supplier that acted intentionally or with deliberate recklessness. Relying on it can also be unacceptable under standards of reasonableness and fairness (Article 6:248(2)). Claims up to 25,000 euros go to the subdistrict court; larger claims to the district court.

Who owns software, source code and databases?

Copyright in software belongs to its creator, unless the law or a written deed provides otherwise. If an external company builds software for you, it keeps the copyright as long as there is no written assignment.

The Dutch Copyright Act (Auteurswet) protects computer programs as works. If an employee writes software in the course of employment, the employer is regarded as the author under Article 7. That rule does not apply to external developers or freelancers. Assignment of copyright requires a deed, meaning a signed written document (Article 2).

Without an assignment, you hold at most a licence. That can become a problem in an acquisition or funding round, where IT law meets corporate law, because a buyer wants to see that you own your core software. An IT lawyer in the Netherlands checks this first in any technology due diligence.

A database can also be protected under the Databases Act (Databankenwet) if the maker made a substantial investment in it. Watch out for open source components as well. Some licences, such as the GPL, require you to release your own source code when you distribute the software.

Who owns AI-generated content?

Copyright protects a work that reflects the author's own intellectual creation, made through free and creative human choices. Output generated by AI without meaningful human creative input is therefore unlikely to be protected by copyright.

In practice, ownership of AI output is regulated mainly by contract and by the terms of the AI provider. Check those terms for rights of use, confidentiality of your input and liability if output infringes third-party rights.

What does the GDPR require of your organisation?

The GDPR requires a legal basis for processing personal data, appropriate security and notification of data breaches within 72 hours. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) supervises compliance and can impose fines of up to 20 million euros or 4 per cent of worldwide annual turnover.

If a supplier processes personal data on your behalf, such as a hosting provider or SaaS vendor, it acts as a processor. Article 28 GDPR then requires a data processing agreement. It covers the purpose of processing, security measures, sub-processors and deletion of data afterwards.

Under Article 33 GDPR you must report a personal data breach to the Dutch Data Protection Authority within 72 hours of becoming aware of it. That does not apply if the breach is unlikely to result in a risk to individuals. If the risk is high, you must also inform the data subjects (Article 34). Document every breach internally, including those you do not report.

For processing with a high privacy risk, such as large-scale profiling, a data protection impact assessment (DPIA) is required in advance (Article 35). For more on privacy and data protection, see our privacy lawyer page.

Which EU technology rules apply to your company?

Besides the GDPR, a growing set of EU rules applies to digital products and services, including the AI Act, NIS2, the Data Act and the Digital Services Act. Which rules apply to you depends on your sector, your size and the services you offer.

What does the AI Act require?

The AI Act (Regulation (EU) 2024/1689) classifies AI systems by risk. Some practices are prohibited, high-risk systems must meet strict requirements and other systems mainly face transparency duties. The regulation entered into force on 1 August 2024 and applies in phases.

DateWhat applies
2 February 2025Ban on prohibited AI practices and the AI literacy duty for staff
2 August 2025Rules for general-purpose AI models and the governance framework
2 August 2026Most remaining obligations, as originally scheduled
2 August 2027Rules for high-risk AI in products already covered by EU product legislation

The EU has discussed postponing the start of the rules for high-risk systems. Check which date currently applies to your specific system before you plan compliance.

What does NIS2 mean for your cybersecurity?

The NIS2 Directive (Directive (EU) 2022/2555) requires medium-sized and large organisations in critical sectors to manage cyber risks and report significant incidents. In the Netherlands, NIS2 is implemented through the Cyber Security Act (Cyberbeveiligingswet).

NIS2 requires an early warning within 24 hours of a significant incident, a notification within 72 hours and a final report within one month. Management is personally responsible for overseeing the measures. Even if NIS2 does not apply to you directly, customers often impose its requirements by contract.

What do the Data Act and the Digital Services Act change?

The Data Act (Regulation (EU) 2023/2854) has applied since 12 September 2025. Users of connected products gain access to the data they generate, and cloud providers must make switching to another provider possible.

The Digital Services Act (Regulation (EU) 2022/2065) has applied in full since 17 February 2024. It sets rules for hosting services, marketplaces and platforms on illegal content. In the Netherlands, the Authority for Consumers and Markets (ACM) supervises compliance.

What applies to domain names and e-commerce?

A domain name that resembles your trade mark or trade name can infringe your rights. A webshop must meet statutory information duties, or it loses rights against consumers.

For .nl domain names, you can bring a dispute under the dispute resolution scheme of SIDN, the .nl registry. It is usually faster and cheaper than court proceedings. For generic domains such as .com, the UDRP procedure is available.

If you sell online to consumers, they generally have a 14-day withdrawal period (Article 6:230o of the Dutch Civil Code). If you fail to inform them of that right, the period is extended by up to 12 months. You must also state your identity, the total price including VAT and delivery costs in advance.

How does working with Law & More work?

As your IT lawyer in the Netherlands, working in English or Dutch, we follow four phases. For each phase we agree in advance what we will do and what it will cost.

  1. Intake. In a free introductory meeting we discuss your situation, the parties involved and any deadlines, such as the 72-hour period for a data breach.
  2. Advice. We review the contract, the general terms and the evidence. You receive written advice on your legal situation, the risks and the cost of each step.
  3. Negotiation. In a dispute we send a notice of default and negotiate with the other side. Where useful, we propose mediation to preserve the business relationship.
  4. Proceedings. If no settlement is reached, we litigate before the court. In urgent cases, such as a threatened shutdown of your systems, summary proceedings (kort geding) are possible.

What does an IT lawyer in the Netherlands cost?

We work on an hourly basis, agreed with you in advance. A lawyer charges 250 to 350 euros per hour and a partner 300 to 400 euros per hour, both excluding VAT.

The introductory meeting is free of charge. A one-off advice meeting without further assistance costs 300 euros including VAT. For defined assignments, such as reviewing a SaaS agreement, we give an estimate of hours in advance. Our law firm is based at Marconilaan 13 in Eindhoven, with a visiting location in Amsterdam, and works for companies throughout the Netherlands.

Who handles your case?

Your case is handled by one of our lawyers. In the introductory meeting you hear who that is and how we approach your case. You can read more about their background on our team page.

Which articles help you further?

The text of the Dutch Copyright Act is available on wetten.overheid.nl.

Frequently asked questions

Who owns software that an external agency builds for me?

The external agency keeps the copyright unless you agree a written assignment. Under Article 2 of the Dutch Copyright Act, an assignment requires a deed. Without it you only have a right of use, whose scope follows from the contract.

Within what period must I report a data breach?

You report a personal data breach to the Dutch Data Protection Authority within 72 hours of becoming aware of it, under Article 33 GDPR. Notification is not required if the breach is unlikely to result in a risk to individuals. You must document every breach internally.

Can my IT supplier fully exclude its liability?

A supplier can limit its liability, for example with a cap or by excluding consequential loss. Such a limitation generally does not apply in case of intent or deliberate recklessness. Relying on it can also be unacceptable under standards of reasonableness and fairness.

Do I need a data processing agreement with my SaaS provider?

Yes, if the provider processes personal data on your behalf, Article 28 GDPR requires a data processing agreement. It covers the purpose, security, sub-processors and deletion of data. Many providers offer a standard version, which you should still check.

Since when does the AI Act apply?

The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in phases. The ban on prohibited AI practices has applied since 2 February 2025 and the rules for general-purpose AI models since 2 August 2025. Later dates apply to high-risk systems, which you should check per system.

IT lawyer in the Netherlands: when should I make contact?

Contact an IT lawyer in the Netherlands before you sign a significant IT contract, and as soon as a project or supplier relationship goes wrong. Early advice protects your position, for example by meeting the duty to complain on time. With a data breach, contact us immediately because of the 72-hour deadline.

In doubt about your position? Tell us about your situation. We will let you know within one working day what your options are. Contact us, call +31 40 369 06 80 or e-mail info@lawandmore.nl.

This page provides general information and does not replace advice on your specific situation.

Latest articles on IT law

Recent articles by Law & More on IT law.

When is an IT supplier liable for damage and delay under Dutch law? Breach, default,
Performance, notice of default, suspension, rescission and damages: the legal route when your IT supplier
Paying for bespoke software does not make you the rightholder. Employer copyright, assignment, licence, source