EnglishNederlands
Netherlands flag

Netherlands

Netherlands Data Privacy Laws: GDPR, UAVG & AP Guide (2026)

By Recording Law Editorial TeamReviewed May 20, 202627 min read
Netherlands Data Privacy Laws: GDPR, UAVG & AP Guide (2026)

Frequently Asked Questions

Does the GDPR apply directly in the Netherlands, or does Dutch law replace it?

The GDPR applies directly in the Netherlands as EU law and does not require national transposition. The Dutch UAVG supplements the GDPR by exercising the discretions the regulation grants to member states, such as setting the age of digital consent at 16 (higher than the GDPR minimum of 13), imposing statutory-authorisation requirements for BSN processing, and adding safeguards for employee biometric data. Both instruments are enforced simultaneously by the Autoriteit Persoonsgegevens.

What is the AP, and what powers does it have?

The Autoriteit Persoonsgegevens (AP) is the Dutch national data protection supervisory authority, established as an independent body under Article 51 of the GDPR. It investigates complaints, audits organisations on its own initiative, issues warnings, reprimands, and binding compliance orders, and imposes fines of up to EUR 20 million or 4% of global annual turnover. The AP also coordinates algorithmic and AI oversight through its DCA directorate and since February 2025 has enforced the EU AI Act's prohibited practices provisions.

Can a Dutch employer require employees to use fingerprint scanners?

Only under narrow conditions. The UAVG permits employer processing of biometric data only when necessary for authentication or security purposes. If a less invasive alternative exists, such as a badge-based access system, the employer must use that alternative instead. A Dutch court fined a company for requiring fingerprint scanning when badges were available. The employer must also conduct a DPIA and, where applicable, obtain works council consent before implementing biometric systems.

What is the BSN, and who can process it in the Netherlands?

The Burgerservicenummer (BSN) is the Dutch citizen service number used across government, healthcare, tax, and benefits systems. Because it can link records across multiple databases, Dutch law restricts its processing to organisations authorised by a specific statute. Government agencies, healthcare providers, educational institutions, and (since January 2024) digital sales platforms for tax reporting are authorised. Private companies outside these categories may not request or store the BSN even if an individual voluntarily offers it; individual consent cannot substitute for the missing statutory authorisation.

What are the Netherlands data breach notification rules?

Controllers must notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of a personal data breach, unless the breach poses no risk to individuals' rights and freedoms (Article 33 GDPR). If notification occurs after 72 hours, the controller must justify the delay. Where the breach poses a high risk to individuals, those individuals must also be notified directly without undue delay. The AP received 44,374 breach notifications in 2025, one of the highest volumes in the EU. Booking.com was fined EUR 475,000 for reporting a breach 22 days late.

How does the Netherlands regulate cookie consent?

The Telecommunicatiewet (implementing the EU ePrivacy Directive) requires prior informed consent before placing non-essential cookies. Functional cookies and appropriately configured privacy-friendly analytics are exempt. Cookie walls that condition website access on accepting all cookies do not constitute valid consent under AP guidance. The AP monitors approximately 10,000 Dutch websites annually for compliance and warned more than 200 organisations in 2025. Violations can result in fines up to EUR 900,000 or 10% of annual turnover.

What is the EU AI Act's effect on Dutch organisations?

The EU AI Act applies in the Netherlands as directly applicable EU law. Prohibited AI practices have been banned since 2 February 2025. Requirements for general-purpose AI models apply from 2 August 2025. Requirements for high-risk AI systems were originally due from 2 August 2026 but the Digital Omnibus, provisionally agreed in May 2026, proposes deferral to 2 December 2027. The AP hosts the DCA, which coordinates algorithmic and AI oversight across Dutch regulators.

What is the toeslagenaffaire and what did it mean for Dutch data protection?

The toeslagenaffaire is the Dutch childcare benefits scandal in which the Tax Authority used a machine-learning algorithm that flagged individuals with dual nationality as higher fraud risks, causing tens of thousands of families to be wrongly ordered to repay benefits. A parliamentary investigation led the Rutte cabinet to resign in January 2021. The AP fined the Belastingdienst EUR 3.7 million for maintaining an illegal blacklist and EUR 2.75 million for discriminatory nationality-based processing. As of 2026, more than 50 Belastingdienst algorithms remain under AP review.

Updates

Expanded to full audit-and-evolve refresh: added constitutional basis (Article 10), EU AI Act / DCA section, AP 2025 annual report figures (44,374 breaches; 13,000+ complaints), cookie enforcement campaign detail, UAVG amendment proposal, recent AP fines (A.S. Watson EUR 600K, Coolblue EUR 40K), and Digital Omnibus high-risk delay to December 2027.

Initial publication. Covered GDPR/UAVG framework, Uber EUR 290M fine, Clearview AI EUR 30.5M fine, Netflix EUR 4.75M fine, toeslagenaffaire, BSN protections, employee monitoring, cookie consent, and breach notification.

Sources and References

  1. EUR-Lex -- General Data Protection Regulation (GDPR)(eur-lex.europa.eu).gov
  2. Overheid.nl -- UAVG Full Text(wetten.overheid.nl).gov
  3. Autoriteit Persoonsgegevens -- Privacy Legislation Overview(autoriteitpersoonsgegevens.nl).gov
  4. Autoriteit Persoonsgegevens -- Fines and Other Sanctions(autoriteitpersoonsgegevens.nl).gov
  5. Autoriteit Persoonsgegevens -- Annual Report 2025(autoriteitpersoonsgegevens.nl).gov
  6. Autoriteit Persoonsgegevens -- Clearview AI Fine (EUR 30.5 million, 2024)(autoriteitpersoonsgegevens.nl).gov
  7. Autoriteit Persoonsgegevens -- Uber Fine EUR 290 Million (2024)(autoriteitpersoonsgegevens.nl).gov
  8. EDPB -- Dutch SA Imposes EUR 290 Million Fine on Uber(edpb.europa.eu).gov
  9. Autoriteit Persoonsgegevens -- Netflix Fine EUR 4.75 Million (2024)(autoriteitpersoonsgegevens.nl).gov
  10. EDPB -- Dutch SA Fines Booking.com for Late Breach Reporting(edpb.europa.eu).gov
  11. Autoriteit Persoonsgegevens -- Tax Administration Unlawful and Discriminatory(autoriteitpersoonsgegevens.nl).gov
  12. Autoriteit Persoonsgegevens -- Data Breach Reporting(autoriteitpersoonsgegevens.nl).gov
  13. Autoriteit Persoonsgegevens -- DPO Requirements(autoriteitpersoonsgegevens.nl).gov
  14. Autoriteit Persoonsgegevens -- BSN Requirements(autoriteitpersoonsgegevens.nl).gov
  15. Government of the Netherlands -- Citizen Service Number (BSN)(government.nl).gov
  16. Autoriteit Persoonsgegevens -- Employee Monitoring(autoriteitpersoonsgegevens.nl).gov
  17. Autoriteit Persoonsgegevens -- EU AI Act(autoriteitpersoonsgegevens.nl).gov
  18. Autoriteit Persoonsgegevens -- DCA Department for Algorithmic Oversight(autoriteitpersoonsgegevens.nl).gov
  19. Autoriteit Persoonsgegevens -- First Algorithmic Risks Report Netherlands(autoriteitpersoonsgegevens.nl).gov
  20. Autoriteit Persoonsgegevens -- International Transfers: Standard Contractual Clauses(autoriteitpersoonsgegevens.nl).gov
  21. Library of Congress -- Netherlands: Clearview AI Fined (2024)(loc.gov).gov
  22. Library of Congress -- Netherlands: Uber Fined (2024)(loc.gov).gov
  23. EDPB -- Dutch SA Imposes Fine on Clearview (2024)(edpb.europa.eu).gov
  24. Government of the Netherlands -- Childcare Benefit Scandal(government.nl).gov
  25. NL Times -- Dutch Tax Authority Biggest Privacy Violators 2025 (February 2026)(nltimes.nl)
  26. EU Council -- AI Act Digital Omnibus Agreement (May 2026)(consilium.europa.eu).gov
  27. Autoriteit Persoonsgegevens -- Data Breach Reporting(autoriteitpersoonsgegevens.nl).gov
Share: