Types of legal compliance for businesses in the Netherlands

The Complete Guide to Types of Legal Compliance in Business

Legal compliance means that your business observes every rule that binds it: Dutch statutes, directly applicable EU regulations, permit and licence conditions, collective labour agreements and the internal policies you have adopted yourself. For a company in the Netherlands those rules fall into a limited number of areas, each with its own supervisor, but you can only manage them once you know which areas apply to you and who enforces them.

The main areas are employment, data protection and cybersecurity, tax and financial reporting, anti-money laundering and sanctions, competition and consumer law, environment and product safety, corporate housekeeping, and sector licences. Below we explain what each area demands, which authority supervises it, what non-compliance costs and how you build a programme that you can prove works.

What is the difference between legal and regulatory compliance?

Legal compliance is the general duty to obey the law that applies to everyone. Regulatory compliance is the narrower set of obligations that a designated supervisor monitors and enforces in a particular sector or on a particular risk.

Legal compliance covers the Dutch Civil Code (Burgerlijk Wetboek, BW), tax legislation, employment law, criminal law and the general rules on the environment and personal data. It sets the minimum standard, and it applies whether or not anyone checks.

Regulatory compliance applies, for example, to a payment institution under the Financial Supervision Act (Wet op het financieel toezicht, Wft), a hospital under the healthcare inspectorate, a company that operates an installation under an environment and planning permit (omgevingsvergunning), or a gambling operator under the Betting and Gaming Act (Wet op de kansspelen). Typical features are a licence or registration, an ongoing duty to report, powers of inspection, and administrative sanctions such as an order subject to a penalty payment (last onder dwangsom) or an administrative fine (bestuurlijke boete).

Why legal compliance should be a priority

Why the distinction matters in practice

The two are enforced through different routes and at a different pace. A breach of general law usually comes to light through a dispute, a claim or a criminal investigation, and a court decides on it. A breach of a regulatory rule comes to light through an inspection or a mandatory report, and is dealt with administratively, often long before a court is involved.

When you list your obligations, note for each one which route applies. That determines whom you must inform, how fast you must respond, and whether you are dealing with a supervisor you will have to keep working with afterwards.

Be careful with frameworks from other jurisdictions. The US Sarbanes-Oxley Act and sector codes written for the American market have no legal force in the Netherlands, however often they appear in compliance software. What binds a Dutch company is Dutch and EU law, plus the contractual standards you have agreed to, such as a payment scheme’s rulebook or a customer’s audit requirements.

Where do your obligations come from: outside or inside?

External compliance covers rules imposed on you from outside; internal compliance covers the rules you set yourself. Both count, because an internal rule, once adopted, becomes the standard against which a court or supervisor measures your conduct.

External rules include legislation, EU regulations, permit conditions, collective labour agreements declared generally binding and the rules of any scheme you have joined. You cannot negotiate them away, and someone else decides the consequences of a breach.

Internal rules include a code of conduct, an approval matrix for expenditure, a gifts and hospitality policy, a supplier code and quality standards above the legal minimum. They are voluntary in origin, but not in effect. Once communicated, an internal rule can become part of the employment relationship, and it is the yardstick for a dismissal for breach of company rules. A policy you do not enforce can be worse than no policy, because it shows you identified a risk and then did nothing.

Dutch and EU law increasingly require that you can show you have organised yourself to comply. Examples are the accountability principle in the GDPR, the duty to maintain sound administrative organisation and internal control in financial supervision, and the risk inventory and evaluation under working conditions law. Documentation is therefore evidence, not bureaucracy. It also explains why compliance needs an owner with defined responsibilities at board level.

What does employment compliance require?

Employment law is mandatory law: you cannot contract out of it to the employee’s disadvantage. Most businesses meet compliance here first, through dismissal rules, working time, the minimum wage and health and safety.

Dismissal law is found in Book 7 of the Dutch Civil Code. It is a closed system: an employer needs one of the statutory grounds in Article 7:669 BW and must follow the right route. Dismissal for economic reasons and after two years of illness goes through the Employee Insurance Agency (UWV). Dismissal on personal grounds, such as poor performance, a disrupted working relationship or culpable conduct, goes through the subdistrict court (kantonrechter). Termination by mutual consent is recorded in a settlement agreement (vaststellingsovereenkomst), which the employee may revoke within 14 days under Article 7:670b BW.

Around that core sit three further regimes. The Working Hours Act (Arbeidstijdenwet) limits working and rest times. The Minimum Wage and Minimum Holiday Allowance Act (Wet minimumloon en minimumvakantiebijslag) has set a statutory minimum wage per hour since 1 January 2024, adjusted twice a year. The Working Conditions Act (Arbeidsomstandighedenwet) requires a written risk inventory and evaluation (risico-inventarisatie en -evaluatie, RI&E) with a plan of action. That document is usually the first thing the Netherlands Labour Authority (Nederlandse Arbeidsinspectie) asks for.

If you employ nationals from outside the EEA, the Foreign Nationals Employment Act (Wet arbeid vreemdelingen) applies. You need a work permit or a single permit for work and residence, and you must check and copy the employee’s identity document. The Labour Authority enforces this with administrative fines.

Key regulatory compliance types

Two developments to include in your plan

Employers with 50 or more employees must have an internal reporting procedure that meets the requirements of the Whistleblower Protection Act (Wet bescherming klokkenluiders). The Dutch Whistleblowers Authority (Huis voor Klokkenluiders) is one of the external channels to which employees can turn.

Businesses that make workers available to third parties must prepare for the Act on the admission of labour intermediaries (Wet toelating terbeschikkingstelling van arbeidskrachten, Wtta). The act enters into force on 1 January 2027, and the Netherlands Labour Authority will enforce the admission requirement from 1 January 2028. The new Dutch Labour Market Authority (Nederlandse Autoriteit Uitleenmarkt) assesses applications for admission. Hirers are affected too, because using a supplier that has not been admitted will itself be prohibited.

What do data protection and cybersecurity demand?

If you process personal data, the GDPR applies and you must be able to show that your processing is lawful. If you operate in a sector covered by the Cybersecurity Act (Cyberbeveiligingswet), you also have a duty of care and a duty to report incidents.

The GDPR (in Dutch: Algemene verordening gegevensbescherming, AVG) is supplemented by the Dutch GDPR Implementation Act (Uitvoeringswet AVG). The supervisor is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP). There is no general duty to register with the AP before you process personal data. Instead, the GDPR requires accountability.

In practice this means a lawful basis for each processing operation, a record of processing activities, clear privacy information, workable procedures for access, rectification and erasure requests, and a processing agreement with every processor. You also need a documented assessment of transfers outside the EEA, appropriate security measures, and a data protection impact assessment where the processing is likely to result in a high risk.

Under Article 33 GDPR you must notify a personal data breach to the AP within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals. Under Article 34 GDPR you must also inform the people affected if the risk is high. A failure to notify can be fined up to EUR 10 million or 2% of worldwide annual turnover. The highest GDPR fines, for example for processing without a lawful basis, go up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher.

Cybersecurity under the Cyberbeveiligingswet

The Cybersecurity Act, which implements the EU NIS2 Directive, has applied since 15 August 2026. It covers essential and important entities in designated sectors. They must register with the National Cyber Security Centre (NCSC) and meet a duty of care covering risk management, supply chain security, incident handling and business continuity. Management is responsible for this.

Significant incidents must be reported in two stages: an early warning within 24 hours and a fuller notification within 72 hours. Supervision is divided among sectoral supervisors, with the Dutch Authority for Digital Infrastructure (Rijksinspectie Digitale Infrastructuur, RDI) covering digital infrastructure and digital service providers. Start by checking whether you fall within scope. Size and sector decide this, not your own view of how critical you are.

Artificial intelligence

Under the EU AI Act, the bans on prohibited practices, the obligations for general-purpose AI models and the transparency duties for systems that interact with people or generate synthetic content already apply. The high-risk regime has been postponed by the digital omnibus package: to 2 December 2027 for the systems listed in Annex III and to 2 August 2028 for AI in products covered by Annex I. The proposed AI Liability Directive has been withdrawn, so liability for harm caused by AI is assessed under ordinary Dutch rules on tort, product liability and contract.

Which tax, reporting and anti-money laundering duties apply?

Every business has tax obligations and, as a BV or NV, a duty to file annual accounts. Anti-money laundering duties apply only to designated institutions, but that group is wider than most people think.

Depending on your legal form, you pay corporate income tax or income tax, as well as VAT, and you withhold and pay payroll taxes for your employees. The Tax and Customs Administration (Belastingdienst) administers all of these. The duty is procedural as much as substantive: correct and timely returns, complete records and an administration that can be audited. You must keep business records for seven years, and data relating to immovable property for ten years.

Law & More does not advise on tax structuring. For your substantive tax position you need a tax adviser. A sensible division of work is that the tax adviser determines the position, and a lawyer deals with the consequences if a dispute or investigation follows.

Start with a compliance audit

Annual accounts

A BV or NV must prepare, adopt and file its annual accounts with the Chamber of Commerce (Kamer van Koophandel, KvK), at the latest twelve months after the end of the financial year. Late filing is more than a formality. It is an economic offence, and in a later bankruptcy it means that the directors are deemed to have performed their duties improperly under Article 2:248 BW. The law then presumes that this was an important cause of the bankruptcy, which is how directors can become personally liable for the deficit. Listed companies have additional reporting and disclosure duties, supervised by the Dutch Authority for the Financial Markets (Autoriteit Financiële Markten, AFM).

Anti-money laundering

The Money Laundering and Terrorist Financing (Prevention) Act (Wet ter voorkoming van witwassen en financieren van terrorisme, Wwft) applies to designated institutions. These include banks, insurers and payment institutions, but also accountants, tax advisers, civil-law notaries, lawyers for certain services, estate agents, trust offices, crypto service providers and traders who accept large cash payments.

Their duties are risk-based client due diligence, identifying and verifying the ultimate beneficial owner (holding more than 25%), ongoing monitoring, and reporting unusual transactions to the Financial Intelligence Unit (FIU-Nederland). The Dutch system requires reports of unusual transactions, not only suspicious ones, which is a deliberately lower threshold. Supervision is split between De Nederlandsche Bank (DNB), the AFM, the Wwft supervision office of the tax authorities (Bureau Toezicht Wwft) and the professional bodies.

Money laundering itself is a criminal offence under Articles 420bis to 420quater of the Dutch Criminal Code (Wetboek van Strafrecht, Sr); the Wwft imposes preventive duties only. Our guide to money laundering in the Netherlands explains how the two fit together. If your business handles digital assets, also read our note on cryptocurrency compliance risks.

Sanctions

Sanctions compliance is often confused with anti-money laundering, but it binds every business, not only designated institutions, and there is no risk-based exemption. If you trade across borders, see our guide to sanctions compliance in the Netherlands. It covers screening, the ownership and control test, and the reporting duties under the Sanctions Act 1977 (Sanctiewet 1977).

What do competition, consumer and contract law require?

You may not agree with competitors on prices or markets, and you may not abuse a dominant position. If you sell to consumers, you must also follow the consumer rules in Book 6 and Book 7 of the Dutch Civil Code.

The Competition Act (Mededingingswet) mirrors EU competition law. It prohibits agreements and concerted practices that restrict competition and the abuse of a dominant position. The Authority for Consumers and Markets (Autoriteit Consument en Markt, ACM) enforces both, with powers that include unannounced inspections of business premises and digital data.

Ordinary companies are rarely caught by classic cartels. The real risks are information exchanges within a trade association, price or territory understandings between distributors, no-poach agreements between employers, and resale price maintenance presented as a recommended price. Fines are based on turnover, and directors can be fined personally for instructing or leading the infringement.

The ACM also enforces consumer law. The rules on distance selling, pre-contractual information, the 14-day right of withdrawal, unfair commercial practices and unreasonably onerous general terms apply to every business that sells to consumers. They are enforced privately, because a consumer can annul an unfair term, and publicly, because the ACM can impose fines. The ACM also supervises the energy, telecommunications, postal and transport markets. Since the Energy Act (Energiewet) entered into force on 1 January 2026, it applies that act instead of the Electricity Act 1998 and the Gas Act.

Contract compliance

Contract compliance is the quiet area that produces most disputes. Under Article 6:234 BW you must provide your general terms and conditions before or when the contract is concluded; otherwise the other party can annul the clauses. Statutory periods run whether or not anyone is watching them. A buyer must complain within a reasonable time after discovering a defect, and a limitation period is only interrupted by a written notice in which you clearly reserve your right to performance.

A diary for contractual and statutory deadlines is therefore a compliance tool, not a legal detail. For the recurring problems in this area, see our overview of common corporate legal issues.

Which environmental and product rules apply to you?

Activities that affect the physical environment fall under the Environment and Planning Act (Omgevingswet), either under general rules or under a permit. Products you place on the EU market must meet EU product legislation.

The Omgevingswet has applied since 1 January 2024. It merged the former planning, building and environmental statutes into one system. Municipalities, provinces and water authorities are the competent authorities, and the regional environmental services (omgevingsdiensten) carry out most inspections and enforcement. If your business handles waste, discharges into water, emits into the air, stores hazardous substances or runs energy-intensive installations, assume you are in scope and check the rules rather than wait for an inspection.

Legal compliance in the Netherlands

Product compliance is largely EU-driven. To place a product on the EU market, it must meet the applicable harmonised legislation, carry CE marking where required, be supported by technical documentation and have a responsible economic operator established in the EU. The Netherlands Food and Consumer Product Safety Authority (Nederlandse Voedsel- en Warenautoriteit, NVWA) supervises food hygiene, labelling and traceability, as well as consumer product safety, toys and certain other products. The Human Environment and Transport Inspectorate (Inspectie Leefomgeving en Transport, ILT) supervises transport, waste shipments, housing and infrastructure.

Sustainability reporting and due diligence

The EU has narrowed the sustainability rules through the Omnibus I package, Directive (EU) 2026/470. The due diligence directive (CSDDD) now applies only to very large companies, from 26 July 2029; member states must transpose it by 26 July 2028. The harmonised EU civil liability regime has been removed and fines are capped at 3% of worldwide net turnover. The scope of sustainability reporting (CSRD) has also been reduced to the largest companies. Dutch implementation is still catching up, so check the current position before relying on an older source.

Which corporate housekeeping duties and licences apply?

Every Dutch legal entity must keep its registration at the Chamber of Commerce current and register its ultimate beneficial owners. If entry to your market requires a licence, the licence conditions are among your most important obligations.

The trade register (Handelsregister) must show your current directors, authorised signatories and registered address. An outdated register allows a former director to be presented to third parties as still authorised. Ultimate beneficial owners must be recorded in the UBO register kept by the Chamber of Commerce. Public access to that register was closed after the judgment of the Court of Justice of the EU of 22 November 2022, but the duty to register is unchanged. Competent authorities, and in defined circumstances Wwft institutions, still have access.

Corporate governance adds a further layer. Under Article 2:239 BW (for the BV) directors must act in the interests of the company and its business. A director with a conflict of interest may not take part in the decision. The large company regime (structuurregime) and the Works Councils Act (Wet op de ondernemingsraden) bring their own consultation and approval requirements. Since 1 January 2025, amended rules apply to shareholder disputes and to access to the inquiry procedure (enquêteprocedure) before the Enterprise Chamber (Ondernemingskamer) of the Amsterdam Court of Appeal.

Sector licences come on top. Financial services require a licence under the Wft from DNB or the AFM. Games of chance require a licence from the Netherlands Gambling Authority (Kansspelautoriteit). Healthcare providers answer to the Health and Youth Care Inspectorate (Inspectie Gezondheidszorg en Jeugd, IGJ) and, for tariffs and market conduct, the Dutch Healthcare Authority (Nederlandse Zorgautoriteit, NZa). Childcare, private security, taxi transport, waste processing and firearms all have their own regimes. Breaching licence conditions puts the licence itself at risk, not only your finances.

Who enforces what?

Compliance becomes manageable once you can name the authority behind each obligation. The authority determines the sanctions you face, the reports you owe and the tone of the conversation. This is the working map for most businesses:

  • Dutch Data Protection Authority (AP): the GDPR, data breach notifications and complaints from data subjects.
  • Netherlands Labour Authority: working conditions, working hours, the minimum wage, the employment of foreign nationals and labour exploitation.
  • Authority for Consumers and Markets (ACM): competition, consumer protection and the regulated energy, telecoms, postal and transport markets.
  • De Nederlandsche Bank and the AFM: supervision of financial undertakings under the Wft, and Wwft supervision of the institutions allocated to them.
  • Tax and Customs Administration, including Bureau Toezicht Wwft: tax returns and payments, record-keeping, and anti-money laundering supervision of traders and intermediaries.
  • FIU-Nederland: receives reports of unusual transactions and decides which are declared suspicious and passed on to the investigating authorities.
  • NVWA: food safety, product safety, labelling and animal welfare.
  • ILT: transport, waste shipments, water and housing.
  • Municipalities, provinces and environmental services: permits and enforcement under the Omgevingswet.
  • RDI and the sectoral cybersecurity supervisors: the duty of care and incident reporting under the Cyberbeveiligingswet.
  • Customs (Douane) and the Central Import and Export Office (CDIU): customs, export control, dual-use licences and sanctions at the border.
  • Sector regulators: the Kansspelautoriteit, IGJ and NZa, and from 2027 the Nederlandse Autoriteit Uitleenmarkt for labour intermediaries.

Behind all of them stands the criminal route. The Economic Offences Act (Wet op de economische delicten, WED) turns breaches of many regulatory statutes into economic offences. They are investigated by the Fiscal Intelligence and Investigation Service (FIOD) or the inspectorate concerned and prosecuted by the specialised office of the Public Prosecution Service (Functioneel Parket). That is how an administrative problem becomes a criminal one, and why your answer to a supervisor’s first request for information is a legal decision, not an operational one.

What does non-compliance cost?

The fine is the visible cost, but rarely the largest. The loss of a licence, personal liability of directors and commercial damage usually weigh more.

The maximum fines are high: up to EUR 20 million or 4% of worldwide turnover under the GDPR, turnover-based fines in competition law, and fine categories under the WED that increase with the seriousness of the offence.

Types of legal compliance infographic

The second cost is losing permission to operate. A supervisor can suspend or withdraw a licence, impose an order subject to a penalty payment that keeps running until you comply, close premises or ban a product from the market. For a regulated business that can be existential. Lodging an objection or appeal does not suspend such a decision; for that you need to ask the preliminary relief judge (voorzieningenrechter) for a provisional measure.

The third cost is personal. Directors can be liable to the company for improper performance of their duties under Article 2:9 BW, to third parties for unlawful acts, and to the bankrupt estate if the accounts were not filed or the administration was inadequate. Under Article 51 Sr an offence committed by a company can also be prosecuted against the people who gave the instruction or actually led the prohibited conduct. Your compliance file then becomes evidence about individuals as well as the company.

The fourth cost is commercial. Banks review the relationship, insurers raise premiums or withdraw cover, tenders require declarations you can no longer make, customers invoke audit and termination rights, and buyers of your business ask for price reductions or indemnities. Compliance failures also come to light years later in due diligence. As our note on staying ahead of corporate compliance explains, keeping up to date is far cheaper than repairing the damage under supervision.

How do you build a compliance programme you can prove?

Start with a register of your obligations, assess the risks, build controls into your processes and keep evidence that they work. A supervisor looks at what you did, not at what your policy says.

The obligations register is a single list of everything that binds your business, organised by the areas above. For each obligation it records the source, the supervisor, the internal owner and the evidence that shows you comply. Most organisations discover during this exercise that the problem is not disagreement about the rules, but that nobody owns them.

Office compliance audit meeting

Assess the risks

Score each obligation on the likelihood of a failure and the seriousness of its consequences. Seriousness is not only financial: a permit at risk ranks higher than a larger fine. Focus your controls where the score is highest, and record your reasoning. A supervisor will accept a deliberate prioritisation far more readily than a checklist that nobody completed.

Build controls into your processes

Controls work best when they operate without anyone having to remember them. Examples are a sanctions screening step in order intake, a mandatory field for the lawful basis in your marketing tool, four-eyes approval for payments above a set amount and an automatic reminder for permit renewal dates. Give each control an owner with the authority and budget to make it work, reporting to a board member who is accountable for the whole.

Train the right people

Training belongs with the people who take the relevant decisions: sales and purchasing for competition and sanctions, marketing and IT for data protection, HR for employment, and finance for tax and payments. Keep it concrete and short, repeat it and record attendance. Add a reporting channel that meets the whistleblower legislation and that people actually trust, and investigate reports properly.

Monitor and keep evidence

Set a schedule for internal checks, trace a sample of transactions from start to finish at least once a year, log incidents and near misses, and follow up until each issue is fixed. Report to the board on a fixed schedule, not only after something goes wrong. Keep your policies under version control, record when each was last reviewed and keep the evidence for at least the statutory retention period.

If an issue turns out to be a breach, get advice early on whether voluntary disclosure improves your position. Under several regimes it does, but only if you come forward before the supervisor finds out another way. A compliance lawyer and your business lawyer can help you decide quickly.

In summary

  • Legal compliance covers all rules that bind your business; regulatory compliance is the part a designated supervisor enforces.
  • The main areas are employment, data protection and cybersecurity, tax and reporting, anti-money laundering and sanctions, competition and consumer law, environment and products, and corporate housekeeping.
  • Each area has its own supervisor, and the WED can turn a regulatory breach into a criminal case.
  • Non-compliance can cost you your licence and lead to personal liability for directors, not only fines.
  • A programme only works if it has owners, controls built into your processes and evidence that they work.

Frequently asked questions

What is a corporate compliance checklist?

It is a working list of the legal obligations that bind your business, grouped by area. For each obligation it records the source, the supervisor, the person responsible and the evidence that you comply. It helps you spot gaps before a supervisor does.

Why is corporate compliance important for businesses?

Because non-compliance can lead to fines, loss of a licence and personal liability for directors. It also affects your relationships with banks, insurers, customers and future buyers of your business.

What are the key components of an effective compliance checklist?

An effective checklist covers employment, data protection and cybersecurity, tax and annual accounts, anti-money laundering and sanctions, competition and consumer law, environment and products, corporate housekeeping and any sector licence.

How does corporate compliance work in practice?

You list your obligations, assess the risks, build controls into your processes, train the people who take the relevant decisions and keep evidence. A board member is accountable, and the programme is reviewed on a fixed schedule.

Law & More advises businesses in the Netherlands on employment, data protection, competition, anti-money laundering, permits and directors’ liability, and assists when a supervisor or the Public Prosecution Service (Openbaar Ministerie, OM) becomes involved. The Dutch Data Protection Authority and the Authority for Consumers and Markets publish their own guidance for businesses. Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.

Ruby van Kersbergen
Ruby van Kersbergen is an attorney-at-law at Law & More in Eindhoven and Amsterdam. She specialises in contract law, corporate law and corporate legal services, and also works in migration law.

Need Legal Assistance?

Have you received a letter, a writ of summons or a judgment? Send us the documents. We will check which deadlines apply and what your options are.

This article provides general information and is not a substitute for advice on your specific situation.

Related articles

This page is part of Law & More guide to handling business disputes in Dutch

Franchising in the Netherlands is regulated by the Wet franchise, the Dutch Franchise Act, which

What you buy in a Dutch doorstart, who decides, where the workforce risk sits and

Director liability in the Netherlands means that a director of a BV or NV can

The statutory two-tier company (structuurvennootschap) is a Dutch NV or BV that must install a

You can have a conservatory attachment (conservatoir beslag) lifted by starting summary proceedings (kort geding).

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.