Almost every company with a Dutch-facing website publishes a privacy policy — a privacyverklaring or privacy statement. Far fewer publish one that would survive a look from the Autoriteit Persoonsgegevens (the Dutch data protection authority, the AP). The document gets treated as boilerplate, copied from a competitor and left untouched while the business changes underneath it. 2026 is a poor year for that: in March the European Data Protection Board launched a coordinated enforcement action across Europe on exactly this obligation.
Where the obligation comes from
No article of the GDPR is headed “privacy policy”. The statement is simply the ordinary way of discharging an obligation the GDPR frames differently — as the individual’s right to be informed. Transparency is a principle in art. 5 GDPR; arts. 12, 13 and 14 GDPR turn it into a concrete list of things you must tell people, and a standard for how.
The split between art. 13 and art. 14 matters more than most companies realise.
- Art. 13 GDPR applies where you collect personal data from the individual — a contact form, a checkout, a newsletter sign-up. The information must be given at the time the data are obtained: before the form is submitted, not after.
- Art. 14 GDPR applies where the data came from elsewhere — a data broker, a public register, a scraped source, a partner, an employer. You must inform the individual within a reasonable period and at the latest within one month, or at first communication with them, or when the data are first disclosed to another recipient, whichever comes first.
Art. 14 carries a small set of exceptions — the individual already has the information, informing them is impossible or would involve disproportionate effort, the obtaining or disclosure is expressly laid down by law, or the data are subject to professional secrecy. These are narrow. “Inconvenient” is not disproportionate effort, and a company that buys or scrapes contact data and never tells anyone is relying on an exception that does not exist.
Art. 12 GDPR governs the manner: concise, transparent, intelligible, easily accessible, in clear and plain language.
The mandatory content, item by item
This is not a menu. A statement missing one of these items is incomplete as a matter of law.
| Information | Art. 13 (collected from the individual) | Art. 14 (obtained elsewhere) |
|---|---|---|
| Identity and contact details of the controller | Yes | Yes |
| Identity and contact details of the EU representative, where one is required | Yes | Yes |
| Contact details of the data protection officer, where one has been appointed | Yes | Yes |
| Purposes of the processing | Yes | Yes |
| Legal basis for each purpose | Yes | Yes |
| The legitimate interests pursued, where that is the basis relied on | Yes | Yes |
| Categories of personal data concerned | — | Yes |
| Recipients or categories of recipients | Yes | Yes |
| Transfers outside the EEA and the safeguard relied on | Yes | Yes |
| Retention period, or the criteria used to determine it | Yes | Yes |
| Rights of access, rectification, erasure, restriction, objection and portability | Yes | Yes |
| Right to withdraw consent, where consent is the basis | Yes | Yes |
| Right to lodge a complaint with the Autoriteit Persoonsgegevens | Yes | Yes |
| Whether provision is a statutory or contractual requirement, and the consequences of not providing | Yes | — |
| The source of the data, and whether it came from publicly accessible sources | — | Yes |
| Automated decision-making and profiling, with meaningful information about the logic and the envisaged consequences | Yes | Yes |
Three deserve a closer look, because that is where the AP’s attention lands.
Recipients, and the “partners” problem
Art. 13 and art. 14 GDPR allow recipients or categories of recipients. That is a genuine choice, but a category has to mean something. “Our partners” is not a category; it is a refusal to answer. “Our payment service provider, our hosting provider in Germany, our email marketing platform in the United States, and the advertising networks named in our cookie statement” is. If you cannot describe a recipient without vagueness, you probably do not know who has the data — a bigger problem.
Retention where no fixed period is possible
The GDPR accepts that a number of days cannot always be given, which is why art. 13 permits the criteria used to determine the period instead. What it does not permit is the non-answer. In its decision of 11 December 2023 fining Uber Technologies Inc. and Uber B.V. €10,000,000, the AP found exactly that: the statement said data would be kept as long as necessary, which it held too general. A workable criterion reads “for the duration of the contract and seven years after the last transaction, in line with Dutch tax law”.
International transfers
Saying data “may be transferred outside the European Economic Area” tells the reader nothing. The AP’s position in the same Uber decision was that the destination countries should be named and the safeguard identified — adequacy decision, standard contractual clauses, binding corporate rules — with how to obtain a copy. Companies using US analytics, CRM or cloud hosting are transferring; the only question is whether the statement admits it.
The requirements of form
Art. 12 GDPR sets a standard that is easy to state and often failed:
- Concise and transparent — presented efficiently and clearly separated from terms and conditions. Burying it in the general terms does not comply.
- Intelligible — understandable by an average member of the intended audience. A statement written for American lawyers is not intelligible to Dutch consumers, and neither is an English-only statement on a Dutch-language site.
- Easily accessible — the reader should not have to hunt. European guidance treats it as needing to be immediately apparent: a direct link from every page, a contextual link at the point of collection, and in an app a couple of taps away at most.
- Clear and plain language — concrete and definitive rather than abstract. European guidance singles out hedging words such as “may”, “might” and “possible”, and treats “we may use your personal data to develop new services” or “for research purposes” as examples of what not to write.
Where a service is addressed to children, or you know children use it heavily, art. 12 requires vocabulary, tone and style to be adapted so a child can understand it. In the Netherlands this bites early: under art. 5 of the Uitvoeringswet AVG, the age below which parental consent is needed for information society services offered directly to a child is sixteen, the highest the GDPR allows. A statement written for adults on a service used by fourteen-year-olds fails, and the child’s own right to be informed is not discharged by informing the parent.
The layered approach, done properly
Layering is the recommended answer to the tension between completeness and readability, and both the AP and European guidance endorse it. Done properly, the first layer carries the controller’s identity, the purposes, the processing with the greatest impact or capacity to surprise, and how to exercise rights — with the full text one click away as a single document.
Done improperly it becomes a way of hiding things. Layers must not contradict each other, the complete information must remain available in one place, and nothing may be demoted because it is embarrassing. If a processing operation would surprise the reader, that is an argument for the first layer, not the fourth.
Where privacy statements fail
The recurring failures are few, and predictable.
- Vague purposes and undisclosed sharing. “To improve our services” describes nothing, and “we may share your data with selected partners” is the commonest defect of all — it usually conceals ad tech. The test is whether a reader can tell what happens to their data and decide whether they mind.
- A statement that contradicts the site. This turns a paperwork problem into an enforcement problem. The statement says no tracking cookies are placed without consent while the tag manager fires on page load; says data stay in the EU while the support desk runs on a US platform. A regulator does not need to read the statement carefully to find this. It needs to open the network tab.
- The copied statement. A policy taken from a competitor describes the competitor’s processing: it names recipients you do not use, omits the ones you do, and states retention periods you do not observe. It is a set of false statements about your business.
The privacy statement is not a cookie notice
These are two obligations under two instruments, and conflating them is a reliable way to comply with neither.
Cookies and comparable techniques are governed in the Netherlands by art. 11.7a of the Telecommunicatiewet, implementing the ePrivacy Directive. Anyone storing information on, or accessing information stored in, a user’s terminal equipment must give clear and complete information and obtain consent, with narrow exemptions for what is strictly necessary to transmit the communication or deliver the service requested. This governs the act of reading or writing on the device, whether or not personal data are involved. The GDPR governs what you then do with any resulting personal data.
So: the banner is where consent is given or refused; the cookie statement lists the cookies, their purposes and durations; the privacy statement explains the processing of personal data. A privacy statement cannot obtain consent, and a banner cannot discharge arts. 13 and 14. Cross-reference them, and keep them consistent.
The AP has been active here. On 30 April 2025 it announced structural monitoring of Dutch cookie banners and wrote to a first fifty organisations, describing a programme of several hundred a year. On 11 November 2025 it reported that more than 200 websites had been warned, roughly three quarters had adjusted, and it had opened investigations into the rest. Pre-ticked boxes, extra clicks to refuse and hidden options are the patterns it names.
Generate the statement from the register, not from a competitor
Art. 30 GDPR requires most organisations to maintain a register of processing activities — the verwerkingsregister. For each activity it records the purposes, the categories of data subject and of personal data, the recipients including those in third countries, the transfer safeguards and the retention periods.
Compare that with the table above: the overlap is nearly total. The register is the factual inventory; the privacy statement is its public rendering. Built in that order the statement is accurate by construction and stays accurate, because updating the register updates the source. Written the other way round, the two drift apart — and a regulator that asks for the register and reads the website sees the gap.
Keeping it current
A privacy statement describes a live system, so it goes stale whenever the system changes: a new analytics tool, a new CRM, a new processor abroad, a new purpose for data already held.
Two rules follow. A change of processing is a change to the statement, and it should be revised before the change goes live. And a material change must be actively communicated: European guidance is firm that leaving individuals to notice a revised policy themselves is not merely insufficient but unfair. Substantive changes — a new purpose, a change of controller, a change in how rights are exercised — should be brought to people’s attention by email or on-site notice, far enough in advance that they can withdraw consent or object. A typo needs no announcement. A new purpose does.
Version-date the statement and keep previous versions. If you need to show what you told a customer in 2024, an undated live page will not do it.
Companies established outside the EU
A company with no EU establishment is caught by art. 3 GDPR if it offers goods or services to people in the EU or monitors their behaviour there. Mere accessibility of a website is not enough; what counts is evidence of targeting — a Dutch-language version, euro pricing, delivery to the Netherlands, a .nl domain, Dutch advertising. Behavioural monitoring of EU visitors is an independent trigger.
If art. 3 applies, art. 27 GDPR generally requires a representative in the Union, established in a member state where the relevant data subjects are, whose identity and contact details belong in the privacy statement. The exemption is narrow: processing that is occasional, does not involve large-scale special category data, and is unlikely to result in a risk. A webshop selling continuously into the Dutch market is not occasional.
The AP has enforced this in isolation, fining Locatefamily.com €525,000 for failing to designate an EU representative. The decision is dated 10 December 2020 and was published by the AP on 12 May 2021; alongside the fine it imposed an order subject to a penalty payment requiring the representative to be designated. The breach was of art. 27 read with art. 3 GDPR. The site had no EU establishment and its place of establishment was never firmly identified, which did not prevent the fine — a signal for any non-EU operator assuming distance equals immunity.
Enforcement
Under art. 6 of the Uitvoeringswet AVG the Autoriteit Persoonsgegevens is the Dutch supervisory authority. Its powers come from art. 58 GDPR — warnings, reprimands, orders, restrictions on processing — and art. 83 GDPR places breaches of arts. 12, 13 and 14 in the higher fining tier: up to €20 million or 4% of total worldwide annual turnover, whichever is higher.
The AP treats the information obligation as a standalone breach, not a footnote. The €10,000,000 fine on Uber of 11 December 2023 rested on arts. 12 and 13 GDPR — retention information too general, transfer destinations not named, the right to data portability not mentioned as such. The AP declared Uber’s objection to that fine unfounded on 8 May 2026, and Uber has taken the matter to court, so the decision stands for now without being finally settled. That is a fine for what a privacy statement did not say. Separately, on 22 July 2024 the AP fined Uber €290,000,000 for transferring drivers’ data to the United States without a valid transfer tool, announced on 26 August 2024.
The near-term risk is higher than usual. On 14 October 2025 the European Data Protection Board selected transparency and information obligations as the topic of its fifth coordinated enforcement action, and launched it on 19 March 2026 with twenty-five data protection authorities taking part, aimed squarely at arts. 12, 13 and 14 GDPR. Those authorities approach controllers across sectors either through enforcement action or through fact-finding exercises, with follow-up where the findings warrant it; results are shared and aggregated in the second half of 2026 and consolidated in a report for adoption by the Board. Participation is voluntary and the Board has not published which authorities joined, so no assumption should be made either way about the Autoriteit Persoonsgegevens. The point holds regardless: transparency is the enforcement theme of the year across Europe, and if you have been meaning to look at your privacy statement, this is the year the question gets asked.
Is a privacy statement legally compulsory in the Netherlands?
The obligation in arts. 12, 13 and 14 GDPR is to inform individuals, not specifically to publish a document. But if you process personal data through a website, a published privacy statement is the only practical way to meet it. Without one you cannot show you informed anyone, and the burden of proving compliance sits with you. Treat it as compulsory.
Does it have to be in Dutch?
The GDPR requires information intelligible to the intended audience. If you address the Dutch market in Dutch, the privacy statement should be available in Dutch; an English-only statement on a Dutch-language webshop is hard to defend. A business-to-business service operating entirely in English can reasonably publish in English. Where you offer both, the versions must say the same thing.
Can I use a generator or a competitor’s policy?
A generator can give you a structure. It cannot know your processors, your retention periods, your transfers or your legal bases, and a competitor’s policy describes their processing rather than yours. Both routes produce a document that is inaccurate about your own business, which is worse than a short accurate one. Build it from your register of processing activities.
Is the cookie banner part of the privacy statement?
No. The banner obtains consent under art. 11.7a of the Telecommunicatiewet for placing and reading cookies and similar techniques on the visitor’s device. The privacy statement discharges the GDPR duty to inform about processing of personal data. They are separate documents with separate legal bases, and they must be consistent with each other and with what the site actually does.
What if we cannot give a retention period?
Art. 13 GDPR allows the criteria used to determine the period instead. The criteria must be genuinely usable by the reader: tie retention to the life of the contract, to a statutory obligation, or to a defined event plus a defined term. “As long as necessary” has already been held by the Autoriteit Persoonsgegevens to be too general to satisfy the obligation.
We are a US company with a Dutch webshop. Do we need an EU representative?
Probably yes. If you target Dutch customers — Dutch language, euro pricing, delivery to the Netherlands — art. 3 GDPR applies to you, and art. 27 then requires a representative in the Union unless your processing is genuinely occasional and low-risk. Continuous webshop operations are not occasional. The representative’s details must appear in your privacy statement.

