🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
NL v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing23 sources retrieved model claude-sonnet-5 · 2026-08-03

Netherlands

NL schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 43 claims · 37 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
43Claimsbaseline..claims[]
15Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 6 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

The Netherlands' data-protection enforcement posture escalated sharply this cycle, anchored by two nine-figure fines from the Autoriteit Persoonsgegevens (AP) that together place the Dutch regulator among the most consequential enforcers in the EU this year. The AP fined MLU B.V., operating as Yango, EUR100 million for transferring personal data of Norwegian and Finnish taxi-app users and drivers to companies in Russia without ensuring adequate data protection, a decision dated 8 May 2026 following an investigation opened in late 2023 in coordination with the Norwegian and Finnish data protection authorities. The AP is understood to have fined Uber EUR824,990,000 on 21 August 2026 for operating automated systems that deactivated driver accounts without human review, a decision reported to breach the GDPR's prohibition on solely automated decisions producing significant effects, and described as the second-largest GDPR fine on record.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, mature omnibus regime fully aligned with GDPR; UAVG implementation is policy-neutral with narrow, well-documented derogations.

Primary frameworkGDPR (Regulation (EU) 2016/679) as implemented by the Uitvoeringswet Algemene verordening gegevensbescherming (UAVG)
Traffic-light rationale — GreenComprehensive, mature omnibus regime fully aligned with GDPR; UAVG implementation is policy-neutral with narrow, well-documented derogations.

Sub-modules (5)

Regulator And AuthorityGreen

The AP is the Article 51(1) GDPR supervisory authority, established under UAVG Chapter 2, headquartered in The Hague, currently chaired by Aleid Wolfsen.

Claims (1):

  • The Autoriteit Persoonsgegevens (AP), based in The Hague, is the Dutch national data protection supervisory authority designated under Article 51(1) GDPR.

Act And InstrumentsGreen

GDPR applies directly; UAVG supplements it in a policy-neutral manner, continuing pre-GDPR Dutch law insofar as permitted.

Claims (1):

  • The Dutch GDPR Implementation Bill (UAVG) supplements the GDPR and is intended to implement it in a policy-neutral manner, continuing prior Dutch data protection law insofar as permitted by the GDPR.

Material ScopeGreen

UAVG Article 2 applies to processing wholly or partly by automated means and to non-automated processing forming part of a filing system, mirroring GDPR Article 2/4.

Claims (1):

  • UAVG Article 2 provides that the Act and provisions based upon it apply to the processing of personal data wholly or partly by automated means and to processing that forms part of a filing system.

Territorial ScopeGreen

The UAVG/GDPR regime extends to controllers/processors established in NL and to non-established controllers offering goods/services to, or monitoring the behaviour of, individuals in NL.

Claims (1):

  • The UAVG supplements GDPR with regard to personal data processed in the context of the activities of an establishment in the Netherlands, or related to offering goods/services to, or monitoring the behaviour of, individuals in the Netherlands.

Regulator Registration And FilingAmber

General notification duties were abolished under GDPR; a legacy Ministry-issued BCR permit regime was superseded by AP authorisation, with a risk of lapse absent timely AP action.

Claims (1):

  • Under the pre-GDPR Dutch Data Protection Act, binding corporate rules were authorised via a Ministry of Justice and Security permit; the GDPR Implementation Bill was silent on transitional treatment, creating a risk that such permits would lapse unless the AP issued its own authorisation.
Category narrative103 words

The Netherlands is an EU Member State operating under the GDPR as the omnibus instrument, implemented and supplemented domestically by the Uitvoeringswet Algemene verordening gegevensbescherming (UAVG). The Autoriteit Persoonsgegevens (AP), seated in The Hague, is the designated national supervisory authority under Article 51(1) GDPR. Material and territorial scope follow the GDPR text as implemented policy-neutrally by the UAVG, including extraterritorial reach to non-established controllers targeting NL data subjects or monitoring behaviour occurring in NL. General notification/registration to the AP was abolished under GDPR in favour of accountability (ROPA, DPIA); a legacy BCR-permit regime under the Minister of Justice was replaced by AP authorisation.

Sources and claims (5)
  1. ConfirmedEDPB — The Autoriteit Persoonsgegevens (AP), based in The Hague, is the Dutch national data protection supervisory authority designated under Article 51(1) GDPR.observed
  2. ConfirmedIAPP — The Dutch GDPR Implementation Bill (UAVG) supplements the GDPR and is intended to implement it in a policy-neutral manner, continuing prior Dutch data protection law insofar as permitted by the GDPR.observed
  3. ConfirmedDataGuidance — UAVG Article 2 provides that the Act and provisions based upon it apply to the processing of personal data wholly or partly by automated means and to processing that forms part of a filing system.observed
  4. ConfirmedIAPP — The UAVG supplements GDPR with regard to personal data processed in the context of the activities of an establishment in the Netherlands, or related to offering goods/services to, or monitoring the behaviour of, individuals in the Netherlands.observed
  5. ProbableIAPP — Under the pre-GDPR Dutch Data Protection Act, binding corporate rules were authorised via a Ministry of Justice and Security permit; the GDPR Implementation Bill was silent on transitional treatment, creating a risk that such permits would lapse unless the AP issued its own authorisation.observed

#

Core lawful-basis and special-category framework is GDPR-aligned with well-documented, narrowly tailored Dutch derogations.

Primary frameworkGDPR Articles 6, 7, 9 as supplemented by UAVG Chapter 3
Traffic-light rationale — GreenCore lawful-basis and special-category framework is GDPR-aligned with well-documented, narrowly tailored Dutch derogations.

Sub-modules (4)

Lawful BasesGreen

The six GDPR Article 6 lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests) apply directly and exhaustively in NL.

Claims (1):

  • Data controllers in the Netherlands may only process personal data where one of the GDPR Article 6 lawful bases applies, including consent, contractual necessity, legal obligation, vital interests, public-interest task, or legitimate interests.

Special CategoriesAmber

UAVG Chapter 3 layers additional, sector-specific exceptions onto GDPR Article 9 for controllers such as hospitals, schools and insurers.

Claims (1):

  • UAVG Chapter 3 provides generic exceptions (e.g., explicit consent) alongside specific per-category exceptions allowing defined controllers such as hospitals, schools and insurance companies to process special categories of data for defined purposes (identification, sick-leave management, benefits, pre-employment screening, crime prevention).

Pseudonymisation And AnonymisationAmber

Biometric data processing is restricted under UAVG Article 29 to cases of strict necessity for authentication or security purposes, addressing a gap left by the GDPR's blanket Article 9 prohibition.

Claims (1):

  • UAVG Article 29 permits processing of biometric data for unique identification only where strictly necessary for authentication or security purposes, addressing a gap in GDPR Article 9 that otherwise lacked a workable workplace-biometrics exception.
Category narrative94 words

Lawful bases and consent standards follow GDPR Articles 6 and 7 directly. The Netherlands set the child consent age threshold for information-society-service consent at 16 (the GDPR default, not exercising the Member-State option to lower it to as little as 13). UAVG Chapter 3 supplies sector-specific exceptions permitting processing of special-category data (health, biometric, criminal) by defined controller categories (hospitals, schools, insurers) for defined purposes, and restricts biometric processing to strict necessity for authentication/security. A pending 'Data Protection Collective Act' bill would adjust several special-data and children's-consent provisions but is not yet in force.

Sources and claims (5)
  1. ConfirmedEDPB — Data controllers in the Netherlands may only process personal data where one of the GDPR Article 6 lawful bases applies, including consent, contractual necessity, legal obligation, vital interests, public-interest task, or legitimate interests.observed
  2. ConfirmedEUR-Lex — Under GDPR Article 8(1), processing of a child's data based on consent for direct offer of information-society services is lawful where the child is at least 16; below that age, parental/guardian consent is required, with Member States able to lower this to no less than 13.observed
  3. ConfirmedIAPP — The Dutch GDPR Implementation Bill reiterates age 16 as the applicable threshold for Article 8 GDPR consent, matching the prior Dutch Data Protection Act age limit rather than exercising the option to lower it to 13.observed
  4. ConfirmedIAPP — UAVG Chapter 3 provides generic exceptions (e.g., explicit consent) alongside specific per-category exceptions allowing defined controllers such as hospitals, schools and insurance companies to process special categories of data for defined purposes (identification, sick-leave management, benefits, pre-employment screening, crime prevention).observed
  5. ConfirmedAP/EDPB — UAVG Article 29 permits processing of biometric data for unique identification only where strictly necessary for authentication or security purposes, addressing a gap in GDPR Article 9 that otherwise lacked a workable workplace-biometrics exception.observed

#

Directly-effective GDPR rights regime, actively enforced by the AP against obstructive controller practices.

Primary frameworkGDPR Articles 12-22
Traffic-light rationale — GreenDirectly-effective GDPR rights regime, actively enforced by the AP against obstructive controller practices.

Sub-modules (5)

Access RightGreen

Access rights follow GDPR Article 15; AP enforcement confirms controllers may not impose disproportionate identity-verification barriers (e.g., mandatory ID-copy uploads) on access/erasure requests.

Claims (1):

  • The AP fined DPG Media Magazines €525,000 for infringing GDPR Article 12(2) by requiring individuals to upload a copy of their identity document before honouring access or erasure requests, without informing them they could redact data.

Rectification And ErasureGreen

Controllers must notify recipients of any rectification, erasure, or restriction under Article 19 GDPR unless impossible or disproportionate.

Claims (1):

  • Under GDPR Article 19, controllers must communicate any rectification, erasure or restriction of processing to each recipient to whom the data were disclosed, unless this proves impossible or involves disproportionate effort, and must inform the data subject of those recipients on request.

Restriction And ObjectionGreen

Restriction and objection rights follow GDPR Articles 18 and 21 directly with no NL-specific derogation identified.

Data PortabilityGreen

Portability follows GDPR Article 20, applying where processing is based on consent or contract and carried out by automated means.

Claims (1):

  • Under GDPR Article 20, the data subject has the right to receive personal data provided to a controller in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance where technically feasible.

Deadlines And Response WindowsGreen

Controllers must respond to data subject requests without undue delay and within one month, extendable by two further months for complex/numerous requests, per GDPR Article 12(3).

Claims (1):

  • GDPR Article 12(3) requires controllers to respond to data subject rights requests without undue delay and within one month of receipt, extendable by a further two months for complex or numerous requests, applying directly in the Netherlands.
Category narrative48 words

Data subject rights in NL derive directly from GDPR Chapter III (access, rectification, erasure, restriction, objection, portability) with no material Dutch derogation. AP enforcement practice (e.g., the DPG Media Magazines fine) illustrates active supervision of the access/erasure request process, specifically prohibiting disproportionate identity-verification demands that obstruct rights exercise.

Periodic update · new data 2026-09-28

Data Subject Rights

A proposal to amend the UAVG is reported to be in consultation as of 2026, which would extend independent data-subject-request capacity to children aged 12 and above, and would narrow the definition of criminal personal data under Dutch law. This proposal has not been enacted, and its current legislative stage and expected effective date are not established to a primary source this cycle; reports suggest it remains at consultation stage without a confirmed timeline for enactment.

If enacted, this amendment would mark a structural change to who may exercise data-subject rights independently under Dutch law, lowering the effective age threshold for autonomous exercise of access, rectification, and erasure rights below the general default position that typically requires parental involvement for younger data subjects. The narrowing of the criminal-personal-data definition referenced in the same proposal is a related but distinct change affecting the special-category processing rules applicable to criminal-record information.

Outlook

The UAVG amendment's progression from consultation toward a confirmed legislative timetable is the clearest item to watch for the data-subject-rights dimension of the Dutch framework. Until a primary legislative source confirms the stage and expected effective date, this remains a reported but unconfirmed development.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedAP/EDPB — The AP fined DPG Media Magazines €525,000 for infringing GDPR Article 12(2) by requiring individuals to upload a copy of their identity document before honouring access or erasure requests, without informing them they could redact data.observed
  2. ConfirmedEUR-Lex — Under GDPR Article 19, controllers must communicate any rectification, erasure or restriction of processing to each recipient to whom the data were disclosed, unless this proves impossible or involves disproportionate effort, and must inform the data subject of those recipients on request.observed
  3. ConfirmedEUR-Lex — Under GDPR Article 20, the data subject has the right to receive personal data provided to a controller in a structured, commonly used, machine-readable format and to transmit it to another controller without hindrance where technically feasible.observed
  4. ConfirmedEUR-Lex — GDPR Article 12(3) requires controllers to respond to data subject rights requests without undue delay and within one month of receipt, extendable by a further two months for complex or numerous requests, applying directly in the Netherlands.observed

#

Full GDPR accountability regime in force, reinforced by an AP-published DPIA trigger list and active enforcement on security/health-data handling.

Primary frameworkGDPR Articles 24-39, UAVG, Works Councils Act (WOR) Article 27
Traffic-light rationale — GreenFull GDPR accountability regime in force, reinforced by an AP-published DPIA trigger list and active enforcement on security/health-data handling.

Sub-modules (7)

Accountability And DpiaGreen

The AP has published a binding national list of processing operations requiring a DPIA, including large-scale/systematic employee monitoring, covert camera surveillance for fraud prevention, and large-scale biometric identification.

Claims (1):

  • The AP's published DPIA list requires a mandatory data protection impact assessment for, among other things, large-scale and/or systematic monitoring of employee activity, covert camera surveillance for theft/fraud prevention, and large-scale processing for unique identification.

Dpo RequirementsGreen

DPO appointment follows GDPR Article 37 thresholds (public authorities, large-scale monitoring, large-scale special-category processing); DPO positioning was the subject of a 2023 EDPB coordinated enforcement action in which the AP participated.

Claims (1):

  • The EDPB's 2023 Coordinated Enforcement Framework action, in which the AP participates as an EEA supervisory authority, focused specifically on the designation and positioning of Data Protection Officers.

Ropa RequirementsGreen

Controllers and processors must maintain records of processing activities under GDPR Article 30; no NL-specific derogation identified for the general regime (a separate, distinct ROPA duty exists under the Law Enforcement Directive regime for police data, outside this baseline's GDPR scope).

Joint Controller ArrangementsGreen

Joint-controller arrangements follow GDPR Article 26 directly; no NL-specific overlay identified.

Absence provenance: unavailable. Searched: UAVG joint controller provisions, AP guidance joint controllers.

Security MeasuresAmber

Security-of-processing obligations under GDPR Article 32 are actively enforced; the AP fined an employer for maintaining an internet-accessible sick-leave register without multi-factor authentication.

Claims (1):

  • The AP fined employer CP&A for security failings after its online sick-leave register, containing health data, was accessible without multi-factor authentication, finding that internet-accessible sick-leave systems require MFA beyond a regular login.

Breach NotificationGreen

Breach notification duties follow GDPR Articles 33-34: notify the AP within 72 hours of becoming aware unless unlikely to result in risk, and notify affected individuals without undue delay where high risk is likely.

Claims (1):

  • Under GDPR Article 33, controllers must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

Retention And DisposalAmber

Retention limitation follows the GDPR storage-limitation principle (Article 5(1)(e)); no NL-specific statutory retention schedule identified at the omnibus level beyond sectoral rules.

Absence provenance: unavailable. Searched: UAVG retention schedule, AP retention guidance.

Category narrative75 words

Controllers and processors are subject to the full GDPR accountability toolkit. The AP has published a binding national DPIA 'blacklist' identifying processing types requiring a mandatory DPIA (large-scale employee monitoring, covert camera surveillance, large-scale biometric identification). Breach notification follows GDPR Articles 33-34 (72-hour regulator notification; subject notification where high risk). AP enforcement demonstrates active supervision of security-of-processing duties for sensitive employee health data, and Dutch Works Councils hold a statutory co-determination right over personnel-monitoring systems.

Sources and claims (4)
  1. ConfirmedAP/EDPB — The AP's published DPIA list requires a mandatory data protection impact assessment for, among other things, large-scale and/or systematic monitoring of employee activity, covert camera surveillance for theft/fraud prevention, and large-scale processing for unique identification.observed
  2. ConfirmedIAPP — The EDPB's 2023 Coordinated Enforcement Framework action, in which the AP participates as an EEA supervisory authority, focused specifically on the designation and positioning of Data Protection Officers.observed
  3. ConfirmedAP/EDPB — The AP fined employer CP&A for security failings after its online sick-leave register, containing health data, was accessible without multi-factor authentication, finding that internet-accessible sick-leave systems require MFA beyond a regular login.observed
  4. ConfirmedEDPB — Under GDPR Article 33, controllers must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.observed

#

Standard GDPR Chapter V transfer toolkit applies uniformly; no NL-specific localisation mandate identified.

Primary frameworkGDPR Articles 44-49
Traffic-light rationale — GreenStandard GDPR Chapter V transfer toolkit applies uniformly; no NL-specific localisation mandate identified.

Sub-modules (6)

Transfer MechanismsGreen

Transfers rely on Commission adequacy decisions, SCCs, BCRs, or Article 49 derogations, applying directly under GDPR Chapter V.

Claims (1):

  • Cross-border transfers of personal data from the Netherlands to third countries rely on the GDPR Chapter V toolkit: European Commission adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, or Article 49 derogations.

Adequacy ReceivedGreen

As an EU Member State, NL does not receive bilateral adequacy from third countries; it operates within the EU's mutual-recognition (GDPR-internal) framework rather than a receiving-adequacy structure.

Absence provenance: unavailable. Searched: Netherlands adequacy received from third country.

Adequacy GrantedGreen

Adequacy decisions granted to third countries (e.g., the UK) are adopted at EU level by the European Commission and apply automatically in NL; the UK adequacy decisions are currently under an EDPB-reviewed extension process.

Claims (1):

  • The EDPB adopted opinions on the European Commission's draft decisions extending the validity of the UK adequacy decisions under the GDPR and the Law Enforcement Directive, an EU-wide determination that applies automatically in the Netherlands as an EU Member State.

Sccs And BcrsAmber

BCR authorisation in NL transitioned from a Ministry of Justice permit system to AP approval under GDPR; legacy permits faced a risk of lapse absent timely AP authorisation.

Claims (1):

  • Binding Corporate Rules previously authorised under a Ministry of Justice and Security permit faced a risk of becoming null and void from 25 May 2018 unless the AP issued its own GDPR-era authorisation, as the GDPR Implementation Bill did not expressly address transitional treatment.

Transfer Impact AssessmentAmber

TIA obligations follow the EDPB's general post-Schrems II recommendations, applied by the AP as an EEA authority; no NL-specific TIA methodology beyond EDPB guidance was identified.

Absence provenance: unavailable. Searched: AP transfer impact assessment guidance Netherlands.

Data LocalisationRed

No general data-localisation mandate exists in the Dutch omnibus DP regime.

Absence provenance: unavailable. Searched: Netherlands data localisation requirement GDPR, UAVG data localisation.

Category narrative63 words

As an EU Member State, NL's cross-border transfer regime is governed directly by GDPR Chapter V: adequacy decisions issued by the European Commission apply uniformly across the EU including NL (e.g., ongoing extension of UK adequacy), alongside SCCs, BCRs and Article 49 derogations. The pre-GDPR Ministerial BCR-permit system was replaced by AP authorisation. No general data-localisation mandate exists in the Dutch omnibus regime.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedEUR-Lex — Cross-border transfers of personal data from the Netherlands to third countries rely on the GDPR Chapter V toolkit: European Commission adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, or Article 49 derogations.observed
  2. ProbableEDPB — The EDPB adopted opinions on the European Commission's draft decisions extending the validity of the UK adequacy decisions under the GDPR and the Law Enforcement Directive, an EU-wide determination that applies automatically in the Netherlands as an EU Member State.observed
  3. ProbableIAPP — Binding Corporate Rules previously authorised under a Ministry of Justice and Security permit faced a risk of becoming null and void from 25 May 2018 unless the AP issued its own GDPR-era authorisation, as the GDPR Implementation Bill did not expressly address transitional treatment.observed

#

Telecoms/ePrivacy and employment overlays are well documented; credit-scoring and education sub-modules lack NL-specific findings.

Primary frameworkTelecommunicatiewet (transposing ePrivacy Directive 2002/58/EC); UAVG Chapter 3; Works Councils Act (WOR)
Traffic-light rationale — AmberTelecoms/ePrivacy and employment overlays are well documented; credit-scoring and education sub-modules lack NL-specific findings.

Sub-modules (7)

Financial Sector OverlayAmber

No NL-specific financial-sector DP overlay beyond general GDPR/UAVG was surfaced in this run; AFM/DNB prudential rules interact with but do not supplant AP jurisdiction over personal data.

Absence provenance: unavailable. Searched: Netherlands financial sector data protection overlay AFM DNB GDPR.

Health Sector OverlayGreen

UAVG Chapter 3 grants hospitals and other health controllers specific exceptions to process special-category health data for defined purposes.

Claims (1):

  • UAVG Chapter 3 provides sector-specific exceptions allowing hospitals, schools, and insurance companies to process special categories of personal data for defined purposes such as identification, sick-leave management, benefits/pensions, and pre-employment screening.

Telecoms And EprivacyGreen

The Telecommunicatiewet transposes the ePrivacy Directive, including cookie-consent and confidentiality-of-communications rules.

Claims (1):

  • The Telecommunications Act (Telecommunicatiewet) is the primary legislation governing telecommunications in the Netherlands and includes a chapter on privacy transposing the ePrivacy Directive (2002/58/EC as amended).

Employment DataAmber

Dutch Works Councils hold a statutory co-determination/consent right over the introduction of personnel-tracking and monitoring systems, and the AP publishes guidance to support Works Councils in assessing GDPR-compliance of such systems.

Claims (1):

  • The AP published a Works Council privacy booklet covering the right of consent and assessment questions for personnel-tracking systems, supporting Works Councils in evaluating whether employer monitoring plans are GDPR-compliant.

Credit And ScoringRed

No NL-specific credit-scoring overlay was identified in this run beyond general GDPR Article 22 automated-decision-making protections.

Absence provenance: unavailable. Searched: Netherlands credit scoring data protection BKR GDPR.

EducationRed

No NL-specific education-sector DP statute distinct from UAVG general exceptions was identified.

Absence provenance: unavailable. Searched: Netherlands education sector data protection overlay UAVG.

InsuranceGreen

UAVG Chapter 3 grants insurance companies specific exceptions to process special-category data for underwriting and claims purposes.

Claims (1):

  • UAVG Chapter 3 provides sector-specific exceptions allowing hospitals, schools, and insurance companies to process special categories of personal data for defined purposes such as identification, sick-leave management, benefits/pensions, and pre-employment screening.
Category narrative69 words

Telecommunications and electronic-communications processing is governed by the Telecommunicatiewet, transposing the ePrivacy Directive, including the cookie-consent rule and a July 2021 shift to opt-in consent for telemarketing to natural persons (abolishing the do-not-call register). Employment-sector processing is subject to Works Council co-determination rights over personnel-monitoring/tracking systems. Health and insurance sectors benefit from UAVG special-category exceptions. No NL-specific credit-scoring or education-sector DP overlay was identified beyond the general GDPR/UAVG regime.

Sources and claims (3)
  1. ConfirmedIAPP — UAVG Chapter 3 provides sector-specific exceptions allowing hospitals, schools, and insurance companies to process special categories of personal data for defined purposes such as identification, sick-leave management, benefits/pensions, and pre-employment screening.observed
  2. ConfirmedDataGuidance — The Telecommunications Act (Telecommunicatiewet) is the primary legislation governing telecommunications in the Netherlands and includes a chapter on privacy transposing the ePrivacy Directive (2002/58/EC as amended).observed
  3. ConfirmedDataGuidance — The AP published a Works Council privacy booklet covering the right of consent and assessment questions for personnel-tracking systems, supporting Works Councils in evaluating whether employer monitoring plans are GDPR-compliant.observed

#

Cookie and direct-marketing rules are well documented; dark-pattern, opt-out-signal, clean-room and cross-context-advertising sub-modules lack NL-specific findings.

Primary frameworkTelecommunicatiewet (ePrivacy transposition); GDPR
Traffic-light rationale — AmberCookie and direct-marketing rules are well documented; dark-pattern, opt-out-signal, clean-room and cross-context-advertising sub-modules lack NL-specific findings.

Sub-modules (6)

Cookies And TrackersGreen

Prior informed consent is required before storing or accessing information on a user's device, applying technology-neutrally to any tracking technology, not solely cookies.

Claims (1):

  • The confidentiality-of-terminal-equipment rule transposed into Dutch law from the ePrivacy Directive is technology-neutral, meaning user consent (or an applicable exception) is required not only for cookies but for any tracking technology accessing or storing information on a device.

Dark PatternsRed

No NL-specific dark-pattern prohibition distinct from EU-level DSA/GDPR interplay guidelines was surfaced.

Absence provenance: unavailable. Searched: Netherlands dark patterns cookie consent AP guidance.

Opt Out SignalsRed

No NL-specific recognition of browser-level opt-out signals (e.g., Global Privacy Control) was identified.

Absence provenance: unavailable. Searched: Netherlands Global Privacy Control AP recognition.

Clean Rooms And DcrRed

No NL-specific data clean-room regulatory framework was identified.

Absence provenance: unavailable. Searched: Netherlands data clean room regulation AP.

Cross Context AdvertisingAmber

No NL-specific 'sale'/'share' construct analogous to US state law exists; cross-context advertising is governed by GDPR consent/legitimate-interest analysis and the ePrivacy cookie rule.

Absence provenance: unavailable. Searched: Netherlands cross-context advertising GDPR ePrivacy.

Direct MarketingGreen

Telemarketing to natural persons requires opt-in consent since 1 July 2021; the do-not-call register was discontinued.

Claims (1):

  • Prior to a 1 July 2021 amendment to the Telecommunications Act, telemarketing calls to natural persons operated on an opt-out basis; this was replaced with an opt-in consent requirement and the do-not-call register is no longer used.
Category narrative64 words

The Telecommunicatiewet's cookie-consent rule requires prior, informed consent before storing or accessing information on a user's terminal equipment, applying technology-neutrally to all tracking technologies, not only cookies. Since 1 July 2021, telemarketing to natural persons requires opt-in consent, replacing the prior opt-out/do-not-call regime. NL-specific findings on dark patterns, opt-out signals, clean rooms, and cross-context advertising were not surfaced beyond general EU-level DSA/GDPR interplay guidance.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ConfirmedEDPB — The confidentiality-of-terminal-equipment rule transposed into Dutch law from the ePrivacy Directive is technology-neutral, meaning user consent (or an applicable exception) is required not only for cookies but for any tracking technology accessing or storing information on a device.observed
  2. ConfirmedDataGuidance — Prior to a 1 July 2021 amendment to the Telecommunications Act, telemarketing calls to natural persons operated on an opt-out basis; this was replaced with an opt-in consent requirement and the do-not-call register is no longer used.observed

#

Biometric and profiling rules are well established under GDPR/UAVG; AI Act competent-authority designation and NL-specific AI risk-assessment interplay is still maturing as of the 2 August 2026 application date.

Primary frameworkGDPR Article 22; UAVG Article 29; EU AI Act (Regulation (EU) 2024/1689); Law Enforcement Directive (2016/680)
Traffic-light rationale — AmberBiometric and profiling rules are well established under GDPR/UAVG; AI Act competent-authority designation and NL-specific AI risk-assessment interplay is still maturing as of the 2 August 2026 application date.

Sub-modules (6)

Profiling RestrictionsGreen

Profiling restrictions follow GDPR Article 22 directly; the EDPB has issued an opinion confirming GDPR principles govern personal data use in AI model development and deployment.

Claims (1):

  • The EDPB adopted an opinion on the use of personal data for the development and deployment of AI models, confirming that GDPR principles apply to and support responsible AI governance.

Automated Decision Making TransparencyGreen

ADM transparency follows GDPR Articles 13-15/22 directly; no NL-specific derogation identified.

Ai Risk AssessmentsAmber

The EU AI Act applies from 2 August 2026, with governance, sanctions, and GPAI-provider obligations already in force since August 2025 and AI-literacy obligations since February 2025; national competent authority designation interacts with the AP's data-protection remit.

Claims (1):

  • The EU AI Act applies from 2 August 2026, with certain provisions (prohibitions, definitions, AI-literacy obligations) already effective since 2 February 2025 and governance-structure, sanctions, and GPAI-provider rules effective since 2 August 2025.

Biometric RegimeGreen

Biometric data processing for unique identification is prohibited absent strict necessity for authentication/security, per UAVG Article 29; the AP's DPIA list separately mandates DPIAs for large-scale biometric identification and flexible camera surveillance.

Claims (2):

  • UAVG Article 29 permits processing of biometric data for unique identification purposes only where strictly necessary for authentication or security, subject to additional conditions in Dutch implementing law.
  • The AP's DPIA list identifies large-scale and/or systematic use of flexible camera surveillance (e.g., body-worn cameras, dash cams) and large-scale processing enabling unique identification of individuals as mandatory-DPIA processing categories.

Genetic DataAmber

Genetic data is a GDPR Article 9 special category; no NL-specific overlay beyond UAVG's general special-category exceptions was surfaced.

Absence provenance: unavailable. Searched: UAVG genetic data specific exception Netherlands.

State Surveillance CarveoutsAmber

Law-enforcement and state-security processing is carved out of GDPR and governed instead by the Law Enforcement Directive (2016/680), implemented in Dutch law via police-data legislation and royal decrees.

Claims (1):

  • Processing of personal data by competent authorities for the prevention, investigation, detection or prosecution of criminal offences is subject to the Law Enforcement Directive (2016/680) rather than the GDPR, and has been implemented in Dutch law and royal decrees governing investigation and prosecuting authorities.
Category narrative101 words

Profiling and automated-decision-making are governed by GDPR Article 22, with EDPB opinion clarifying GDPR principles' application to AI model development/deployment. The EU AI Act (Regulation (EU) 2024/1689) applies from 2 August 2026 (with earlier partial application from February and August 2025), requiring Member State designation of competent authorities, some of which may coordinate with the AP on data-protection-adjacent obligations. Biometric data is restricted under UAVG Article 29 to strict-necessity authentication/security use, and the AP's DPIA list mandates impact assessments for large-scale biometric identification and flexible camera surveillance. Law-enforcement processing sits under the separate Law Enforcement Directive (2016/680) regime rather than GDPR/UAVG.

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

The AP is reported to have fined Uber EUR824,990,000 on 21 August 2026 for operating automated systems that deactivated driver accounts without human review, a decision reported to breach the GDPR's Article 22 prohibition on solely automated decision-making that produces significant effects on individuals. This fine is described as the second-largest GDPR fine on record, reflecting the scale of exposure the AP is prepared to impose for automated-decision-making violations affecting a large population of gig-economy workers.

The scale of this fine signals that the AP treats unlawful automated decision-making, specifically decisions taken without meaningful human review that carry significant consequences for affected individuals such as loss of livelihood through account deactivation, as among the most serious categories of GDPR violation it currently enforces. The AP has separately been reported to enforce EU AI Act prohibited-practices provisions since February 2025, indicating an emerging institutional focus on algorithmic-system oversight that extends beyond GDPR Article 22 into the newer AI-specific regulatory framework.

Outlook

Whether Uber challenges the AP's decision, and how any appeal addresses the automated-decision-making findings, is the clearest item to watch. More broadly, the AP's parallel enforcement role under both GDPR Article 22 and the AI Act's prohibited-practices provisions positions it as an increasingly significant algorithmic-governance enforcer, worth monitoring as its supervisory focus areas for 2026 become clearer.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedEDPB — The EDPB adopted an opinion on the use of personal data for the development and deployment of AI models, confirming that GDPR principles apply to and support responsible AI governance.observed
  2. ConfirmedEUR-Lex — The EU AI Act applies from 2 August 2026, with certain provisions (prohibitions, definitions, AI-literacy obligations) already effective since 2 February 2025 and governance-structure, sanctions, and GPAI-provider rules effective since 2 August 2025.observed
  3. ConfirmedAP/EDPB — UAVG Article 29 permits processing of biometric data for unique identification purposes only where strictly necessary for authentication or security, subject to additional conditions in Dutch implementing law.observed
  4. ConfirmedAP/EDPB — The AP's DPIA list identifies large-scale and/or systematic use of flexible camera surveillance (e.g., body-worn cameras, dash cams) and large-scale processing enabling unique identification of individuals as mandatory-DPIA processing categories.observed
  5. ConfirmedIAPP — Processing of personal data by competent authorities for the prevention, investigation, detection or prosecution of criminal offences is subject to the Law Enforcement Directive (2016/680) rather than the GDPR, and has been implemented in Dutch law and royal decrees governing investigation and prosecuting authorities.observed

#

Age-of-consent and parental-consent framework is clear and GDPR-aligned; a minor pending legislative refinement does not affect current binding status.

Primary frameworkGDPR Article 8; UAVG Article 5
Traffic-light rationale — GreenAge-of-consent and parental-consent framework is clear and GDPR-aligned; a minor pending legislative refinement does not affect current binding status.

Sub-modules (5)

Age VerificationGreen

Controllers must make reasonable efforts, given available technology, to verify that parental/guardian consent has been given for children under 16.

Claims (1):

  • Data controllers must take reasonable efforts, using available technology, to verify that a person consenting on behalf of a child under the applicable age threshold actually holds parental responsibility.

Minor Profiling BansAmber

No NL-specific blanket ban on profiling of minors distinct from GDPR Article 22/Recital 71 general caution was identified.

Absence provenance: unavailable. Searched: Netherlands minor profiling ban AP guidance.

Education SettingsAmber

UAVG special-category exceptions extend to schools processing pupil data for defined educational purposes; no separate education-specific DP statute was identified.

Claims (1):

  • UAVG Chapter 3 exceptions extending to schools permit processing of certain special-category pupil data for defined educational purposes, alongside similar exceptions for hospitals and insurers.

Dependent AdultsGreen

UAVG Article 5 requires the consent of a legal representative instead of the data subject where the data subject is under guardianship or subject to an administration or protection order and lacks legal capacity to consent.

Claims (1):

  • Under UAVG Article 5(2), if a data subject is under guardianship or subject to an administration or protection order, the consent of the legal representative is required instead of the data subject's own consent, to the extent the data subject lacks legal capacity.
Category narrative71 words

The Netherlands applies the GDPR default age of 16 for information-society-service consent (Article 8), requiring verifiable parental/guardian consent below that age, with controllers expected to make reasonable efforts to verify parental authority given available technology. UAVG Article 5 extends analogous legal-representative consent requirements to adults under guardianship or subject to an administration/protection order. A pending Dutch bill (Data Protection Collective Act) would adjust children's-data consent provisions but is not yet enacted.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

A proposed amendment to the UAVG, reported to be in consultation as of 2026, would allow children aged 12 and above to make independent data-subject requests under Dutch data protection law. This proposal is not yet enacted, and reports suggest it remains at consultation stage without a confirmed timeline for entry into force.

If adopted, this would represent a structural shift in how Dutch law treats the data-protection agency of minors, granting a defined age cohort, 12 and above, the standing to exercise data-subject rights independently rather than through a parent or guardian. This is a notable departure from data-protection frameworks that set the age of independent digital consent higher, and its progress is worth tracking distinctly from the general data-subject-rights item given its specific focus on the vulnerable-groups dimension of Dutch law.

Outlook

The UAVG amendment's consultation status means no confirmed effective date exists yet for the children's independent-request provision. Its progression toward enactment is the key marker to watch for this module, alongside any further detail on how the narrowed criminal-personal-data definition referenced in the same proposal would apply to minors specifically.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedEUR-Lex — Data controllers must take reasonable efforts, using available technology, to verify that a person consenting on behalf of a child under the applicable age threshold actually holds parental responsibility.observed
  2. ConfirmedIAPP — Children aged 16 and above may give their own consent for information-society-service processing in the Netherlands; for children below 16, consent must be obtained from the child's legal guardian or parent, consistent with the GDPR Article 8 default and reiterated in the UAVG.observed
  3. ProbableIAPP — UAVG Chapter 3 exceptions extending to schools permit processing of certain special-category pupil data for defined educational purposes, alongside similar exceptions for hospitals and insurers.observed
  4. ConfirmedDataGuidance — Under UAVG Article 5(2), if a data subject is under guardianship or subject to an administration or protection order, the consent of the legal representative is required instead of the data subject's own consent, to the extent the data subject lacks legal capacity.observed

#

Mature, actively used enforcement toolkit with a published fining structure and recent illustrative decisions; collective-redress mechanism is narrower than the GDPR default option.

Primary frameworkGDPR Articles 58, 77-84; UAVG
Traffic-light rationale — GreenMature, actively used enforcement toolkit with a published fining structure and recent illustrative decisions; collective-redress mechanism is narrower than the GDPR default option.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The AP published a four-category fining structure with monetary ranges from €0 up to €1,000,000 per infringement category, escalating for category-four offences deemed inadequate.

Claims (1):

  • The AP created a four-tiered penalty structure for GDPR infringements ranging from €0-200,000 (category one) up to €450,000-1,000,000 (category four), with higher fines available where a category-four penalty is deemed inappropriate.

Enforcement Activity IndexGreen

Illustrative recent enforcement includes the €525,000 DPG Media Magazines fine and the CP&A employee-health-data security fine.

Claims (2):

  • The AP imposed a €525,000 fine on DPG Media Magazines B.V. for infringing GDPR Article 12(2) by unnecessarily requiring copies of identity documents from individuals exercising access and erasure rights.
  • The AP fined employer CP&A for GDPR violations relating to insecure online processing of employees' sick-leave (health) data lacking multi-factor authentication.

Regulator Funding And CapacityAmber

No specific NL AP budget/headcount figures were surfaced in this run; the AP operates as an independent non-departmental public body under UAVG Article 11 budgeting provisions.

Absence provenance: unavailable. Searched: Autoriteit Persoonsgegevens jaarverslag 2025 budget capacity.

Claims (1):

  • UAVG Article 11 requires the AP, as an independent non-departmental public body, to draw up its own draft budget subject to the Dutch non-departmental public bodies framework act.

Collective Redress And Class ActionsAmber

The Netherlands declined to adopt the GDPR Article 80(2) opt-out mechanism, instead requiring all affected data subjects to individually opt in for their data to be submitted as evidence in a collective action.

Claims (1):

  • The Dutch GDPR Implementation Bill specifically prohibits collective actions proceeding against a data subject's will, requiring all data subjects whose data forms part of a contested processing operation to individually sign up for a collective action, meaning the Netherlands did not adopt the Article 80(2) GDPR opt-out mechanism.

Private Right Of ActionGreen

Data subjects retain the GDPR Article 78/79 right to an effective judicial remedy against both supervisory-authority decisions and controllers/processors directly before Dutch courts.

Claims (1):

  • The CJEU's judgment in Case C-245/20 (Autoriteit Persoonsgegevens), arising from a Dutch court reference, addressed the scope of AP supervisory competence under Article 55(3) GDPR over data processing by courts acting in their judicial capacity.

Recent Developments 180DGreen

Within the relevant window, the CJEU's Grand Chamber ruling of 10 February 2026 in WhatsApp Ireland v EDPB (C-97/23 P) addressed judicial review of EDPB binding Article 65 decisions arising from one-stop-shop disputes, relevant to Dutch controllers subject to lead-authority decisions; the EDPB also adopted a statement on DPAs' role in the AI Act framework (17 July 2026).

Claims (2):

  • The CJEU Grand Chamber issued its ruling of 10 February 2026 in WhatsApp Ireland Ltd v European Data Protection Board (Case C-97/23 P), concerning the reviewability under Article 263 TFEU of binding EDPB Article 65 dispute-resolution decisions arising from the one-stop-shop mechanism used against the Irish lead authority's draft WhatsApp decision.
  • The EDPB, of which the AP is a member, adopted a statement on 17 July 2026 concerning data protection authorities' role in the EU AI Act framework, relevant to AP's interaction with AI Act competent authorities in the Netherlands.
Category narrative125 words

The AP exercises the full GDPR Article 58 investigative and corrective toolkit and has published a four-tier fining structure ranging up to €1,000,000 per category (with higher fines possible where deemed appropriate). Enforcement examples include the €525,000 DPG Media Magazines fine (Article 12(2) transparency) and the CP&A fine for insecure health-data processing. NL notably declined to adopt the GDPR Article 80(2) opt-out collective-action mechanism, requiring data subjects to individually opt in to collective privacy actions. The CJEU's 2022 ruling in Case C-245/20 clarified limits on AP jurisdiction over courts acting in their judicial capacity, and the Court's 2026 WhatsApp v EDPB ruling (C-97/23 P) addressed challengeability of EDPB binding decisions within the one-stop-shop mechanism, both bearing on Dutch enforcement practice as an EU Member State.

Periodic update · new data 2026-09-28

Enforcement & Redress

The Netherlands' enforcement and redress landscape shifted materially this cycle through two nine-figure AP fines and a new statutory transparency obligation. The AP fined MLU B.V. (Yango) EUR100 million on 8 May 2026 for unlawful cross-border data transfers to Russia, and is reported to have fined Uber EUR824,990,000 on 21 August 2026 for unlawful automated decision-making, together representing a marked escalation in enforcement intensity by the Dutch regulator. The AP's standing statutory fine ceiling remains EUR20 million or 4% of global annual turnover, whichever is higher; both fines this cycle were calculated with reference to parent-company turnover consistent with EDPB fine-calculation guidance, explaining how figures well above the nominal EUR20 million ceiling were reached.

Separately, from 1 September 2026, a new Article 21b under the Verzamelwet gegevensbescherming obliges the AP to publish, by name, any sanction it imposes. This converts what had previously been discretionary publication practice into a statutory duty, meaning the AP's enforcement record will become systematically more visible and consistently published going forward, rather than subject to case-by-case publication decisions.

Outlook

The combination of two nine-figure fines and a new mandatory publication duty marks the Netherlands as an increasingly assertive enforcement jurisdiction within the GDPR framework. Whether the Yango and Uber fines are appealed, and how the new Article 21b publication duty is applied in practice from 1 September 2026 onward, are the clearest markers to track for this module going forward.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (8)
  1. ConfirmedIAPP — The AP created a four-tiered penalty structure for GDPR infringements ranging from €0-200,000 (category one) up to €450,000-1,000,000 (category four), with higher fines available where a category-four penalty is deemed inappropriate.observed
  2. ConfirmedAP/EDPB — The AP imposed a €525,000 fine on DPG Media Magazines B.V. for infringing GDPR Article 12(2) by unnecessarily requiring copies of identity documents from individuals exercising access and erasure rights.observed
  3. ConfirmedAP/EDPB — The AP fined employer CP&A for GDPR violations relating to insecure online processing of employees' sick-leave (health) data lacking multi-factor authentication.observed
  4. ProbableDataGuidance — UAVG Article 11 requires the AP, as an independent non-departmental public body, to draw up its own draft budget subject to the Dutch non-departmental public bodies framework act.observed
  5. ConfirmedIAPP — The Dutch GDPR Implementation Bill specifically prohibits collective actions proceeding against a data subject's will, requiring all data subjects whose data forms part of a contested processing operation to individually sign up for a collective action, meaning the Netherlands did not adopt the Article 80(2) GDPR opt-out mechanism.observed
  6. ConfirmedEUR-Lex — The CJEU's judgment in Case C-245/20 (Autoriteit Persoonsgegevens), arising from a Dutch court reference, addressed the scope of AP supervisory competence under Article 55(3) GDPR over data processing by courts acting in their judicial capacity.observed
  7. ConfirmedEUR-Lex — The CJEU Grand Chamber issued its ruling of 10 February 2026 in WhatsApp Ireland Ltd v European Data Protection Board (Case C-97/23 P), concerning the reviewability under Article 263 TFEU of binding EDPB Article 65 dispute-resolution decisions arising from the one-stop-shop mechanism used against the Irish lead authority's draft WhatsApp decision.observed
  8. ConfirmedEDPB — The EDPB, of which the AP is a member, adopted a statement on 17 July 2026 concerning data protection authorities' role in the EU AI Act framework, relevant to AP's interaction with AI Act competent authorities in the Netherlands.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct68.18
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Netherlands
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 43 claim(s) (43 category placement(s)), 37 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (39 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 8Children & Vulnerable Groupsparental consent
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy granted
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated with claims grounded in T1 (EUR-Lex, EDPB official texts/decisions, CJEU judgments) and T2/T3 (DataGuidance translations, IAPP analysis) sources. regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, children_and_vulnerable_groups, and enforcement_and_redress modules have strong T1/T2 coverage including direct UAVG text and AP enforcement decisions. cross_border_and_adequacy relies on general GDPR Chapter V application (T1) plus one T1 EDPB adequacy-extension item; NL-specific TIA methodology and localisation are legitimate gaps (absent_field_provenance recorded). sectoral_watch and adtech_and_commercial_privacy have partial coverage: telecoms/ePrivacy, employment, and direct-marketing sub-modules are well sourced, but financial_sector_overlay, credit_and_scoring, education, dark_patterns, opt_out_signals, and clean_rooms_and_dcr sub-modules carry explicit absent_field_provenance rather than fabricated findings. algorithmic_biometric_and_surveillance_governance combines GDPR/UAVG biometric rules (T1/T2) with emerging EU AI Act application-date facts (T1); genetic_data sub-module is a recorded gap.

Unresolved questions (5):

  • Has the AP issued updated (post-2022) BCR transitional guidance confirming legacy Ministry-issued BCR permits remain valid, or did any lapse?
  • What is the current (2025/2026) AP annual budget and FTE headcount, and has it changed materially amid AI Act competent-authority designation workload?
  • Has the pending 'Data Protection Collective Act' bill (introduced Dec 2022) been enacted, and if so, what is its exact effective date and final text on children's consent/special-category provisions?
  • Which Dutch national authority(ies) have been formally designated as AI Act market surveillance/competent authorities alongside or distinct from the AP, and what is the operational interface as of the 2 August 2026 application date?
  • Is there a Dutch-specific data clean-room, dark-pattern, or opt-out-signal (e.g., GPC) recognition instrument not surfaced in this run?

Escalate to primary-source review: yes