We help businesses and organisations in the Netherlands comply with the GDPR and act quickly when something goes wrong. As privacy lawyer we draft privacy policies and processing agreements, advise on data breaches and assist in contact with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). We work in English and Dutch; the first step is a free introductory meeting in which we map your data flows and risks.

Clients rate Law & More 9.6 out of 10 on Klantenvertellen, the Dutch review platform (81 reviews, as of October 2026).

What can we help you with?

  • you need a privacy statement for your website, app or employees;
  • a supplier or customer asks you to sign a data processing agreement;
  • you have a data breach and must decide within 72 hours whether to notify;
  • a customer or employee submits an access or erasure request;
  • you want to share data with a partner or transfer data outside the European Economic Area;
  • you plan camera surveillance, biometric access control or employee monitoring;
  • the Dutch Data Protection Authority has started an investigation or imposed a fine.

What does the GDPR require of your business?

The GDPR requires you to process personal data only for a specific purpose and on a valid legal basis, and to be able to prove compliance. It applies to every organisation in the EU that processes personal data, regardless of size.

The General Data Protection Regulation (GDPR, in Dutch: AVG) has applied since 25 May 2018. In the Netherlands it is supplemented by the GDPR Implementation Act (UAVG). Article 6 lists six legal bases, such as consent, performance of a contract and legitimate interest. Article 5 adds principles such as data minimisation and storage limitation.

In practice, most businesses need at least these documents:

  • a privacy statement informing people about your processing (Articles 13 and 14);
  • a record of processing activities (Article 30), which is mandatory for most organisations with employees;
  • processing agreements with suppliers that handle personal data for you (Article 28);
  • a data protection impact assessment (DPIA) for high-risk processing (Article 35);
  • an internal procedure for data breaches and data subject requests.

A data protection officer is mandatory for public bodies and for organisations whose core activities involve large-scale monitoring or special categories of data (Article 37).

When do you need a data processing agreement?

You need a data processing agreement whenever a supplier processes personal data on your behalf. Examples are a payroll provider, cloud host or SaaS platform. Article 28 GDPR sets out what the agreement must at least contain.

The agreement records the subject, duration, nature and purpose of the processing, the types of data and the security measures. It also covers sub-processors, assistance with data subject requests and deletion or return of data at the end. Many suppliers offer a standard version. Check it, because liability and audit rights are often drafted in the supplier's favour.

Not every supplier is a processor. A party that determines its own purposes, such as an accountant or a bank, is often a separate controller. Our article on controller and processor roles explains the difference.

What must you do after a data breach?

You must notify the Dutch Data Protection Authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals. If the risk is high, you must also inform the people affected without undue delay.

These duties follow from Articles 33 and 34 GDPR. A breach is broader than a hack: an e-mail to the wrong recipient, a lost laptop or ransomware all count. Notify through the online form of the Autoriteit Persoonsgegevens. If you do not yet have all the facts, notify on time and supplement later.

StepDeadline
Contain the breach and secure evidenceImmediately
Assess the risk to individualsWithin hours
Notify the Dutch Data Protection AuthorityWithin 72 hours of awareness
Inform affected individuals if the risk is highWithout undue delay
Record the breach in your internal registerAlways, also if you do not notify

A processor must inform you of a breach without undue delay. Agree a concrete period in the processing agreement, for example 24 or 48 hours.

How do you deal with the Dutch Data Protection Authority?

The Autoriteit Persoonsgegevens supervises GDPR compliance in the Netherlands and can impose orders and administrative fines. Fines can reach 20 million euros or 4 per cent of worldwide annual turnover, whichever is higher (Article 83 GDPR).

An investigation usually starts with a written request for information. Answer accurately and on time, and keep the documentation you provide consistent. Before a fine, you get the opportunity to give your view. Against a fine you can lodge an objection with the authority and then appeal to the district court. Our page on administrative law explains objection and appeal.

Individuals can also hold you liable for damage caused by a GDPR breach (Article 82). They can complain to the authority about you as well.

How does working with Law & More work?

  1. Introductory meeting: you explain your organisation or incident, and we identify the urgent points.
  2. Advice and cost estimate: we assess your data flows, documents and risks, and give a cost estimate.
  3. Approach and negotiation: we draft or review policies and agreements, and handle contact with suppliers, data subjects or the authority.
  4. Proceedings or completion: we conclude with a compliance file, or assist in objection and appeal against a decision.

What does a privacy lawyer cost?

Our hourly rate is 250 to 350 euros excluding VAT for a lawyer and 300 to 400 euros excluding VAT for a partner. We discuss the rate and an estimate in advance. The introductory meeting is free of charge. A one-off advice meeting without further assistance costs 300 euros including VAT.

External costs, such as court fees, are charged separately. Legal aid exists via the Legal Aid Board (Raad voor Rechtsbijstand), but we do not work on that basis.

Who handles your case?

Privacy and GDPR matters are handled by Aylin Acar. You can see the whole team on our team page. For IT contracts and cybersecurity, see also our IT lawyer page.

Frequently asked questions

Within what period must I report a data breach?

You must report a personal data breach to the Dutch Data Protection Authority within 72 hours of becoming aware of it, under Article 33 GDPR. No notification is needed if the breach is unlikely to result in a risk to individuals. Every breach must be recorded internally, including those you do not report.

Does a small business also need to comply with the GDPR?

Yes. The GDPR applies to every business that processes personal data, including sole traders. Some obligations are lighter for small organisations, such as the record of processing activities in limited cases. A privacy statement, processing agreements and a breach procedure are needed regardless of size.

How quickly must I answer an access request?

You must respond without undue delay and within one month of receipt, under Article 12 GDPR. For complex or numerous requests, you can extend this by two further months, provided you inform the person within the first month. The access itself is generally free of charge.

When should I contact a privacy lawyer?

Contact a privacy lawyer before you start high-risk processing, such as employee monitoring or biometrics, and when you sign important processing agreements. With a data breach, contact us immediately, because the 72-hour period runs from the moment you become aware. Early advice is usually cheaper than repairing a breach later.

Can I transfer personal data to a supplier outside the EU?

Only with a valid transfer mechanism. That can be an adequacy decision of the European Commission, or standard contractual clauses combined with a transfer impact assessment. For certified US companies, the EU-US Data Privacy Framework can serve as the basis. Check this before you sign, not afterwards.

Can employees claim compensation for a GDPR breach?

Yes. Under Article 82 GDPR, anyone who suffers damage from a breach can claim compensation from the controller or processor. This includes non-material damage, but the person must show actual damage. Dutch courts have awarded mostly modest amounts to individuals. Foundations can also bring collective actions on behalf of a large group of people, which increases the financial risk for organisations.

In doubt about your position? Tell us about your situation. We will let you know within one working day what your options are. Contact us, call +31 40 369 06 80 or e-mail info@lawandmore.nl.

Law & More, Marconilaan 13, 5612 HM Eindhoven (+31 40 369 06 80) and visiting location Pietersbergweg 291, 1105 BM Amsterdam (+31 20 369 71 21). Available Monday to Friday 08:00-22:00, Saturday and Sunday 09:00-17:00.

This page provides general information and does not replace advice on your specific situation.

Latest articles on IT law

Recent articles by Law & More on IT law.

When is an IT supplier liable for damage and delay under Dutch law? Breach, default,
Performance, notice of default, suspension, rescission and damages: the legal route when your IT supplier
Paying for bespoke software does not make you the rightholder. Employer copyright, assignment, licence, source