World Watch/Netherlands/Data & Privacy

Data & Privacy · Netherlands

Data & Privacy - Netherlands

Comprehensive lawEU General Data Protection Regulation (GDPR / 'AVG', Regulation 2016/679), directly applicable since 25 May 2018, supplemented nationally by the Dutch GDPR Implementation Act (Uitvoeringswet Algemene verordening gegevensbescherming, UAVG). Supervised and enforced by the Autoriteit Persoonsgegevens (AP).

As an EU member state, the Netherlands has a comprehensive personal-data protection regime based on the directly applicable GDPR, supplemented by the national UAVG which entered into force on 25 May 2018. The independent supervisory authority is the Autoriteit Persoonsgegevens (AP), which enforces the GDPR, the UAVG and ePrivacy/cookie rules and can impose administrative fines up to the GDPR maximum of €20 million or 4% of global annual turnover.

Comprehensive GDPR-based regime

The GDPR applies directly and is supplemented by the UAVG (BWBR0040940), which entered into force on 25 May 2018, replacing the former Wet bescherming persoonsgegevens (Wbp). The UAVG sets national specifics, exceptions and elaborations and establishes the supervisory authority's powers.

Supervisory authority (AP)

The Autoriteit Persoonsgegevens (AP), the independent Dutch Data Protection Authority (formerly the College bescherming persoonsgegevens), supervises and enforces the GDPR and UAVG, handles complaints, conducts investigations and issues guidance.

Core obligations and rights

Processing must rest on one of the six GDPR legal bases (consent, contract, legal obligation, vital interests, public task, legitimate interests). Controllers must meet the accountability principle, and data subjects hold rights of access, rectification, erasure, data portability and objection.

Cookies and ePrivacy

Cookie placement is governed by Article 11.7a of the Telecommunicatiewet (the Dutch implementation of the EU ePrivacy Directive), while the GDPR governs use of the resulting data. Non-essential cookies require prior, freely given consent; cookie walls are prohibited, and the AP enforces these rules.

National derogation: age of digital consent

Using the GDPR's margin for member states, the UAVG sets the age of valid digital consent for information-society services at 16, the maximum permitted; below that age parental/guardian consent is required.

Enforcement and sanctions

The AP can impose administrative fines up to €20 million or 4% of worldwide annual turnover. Recent actions include a €290 million fine against Uber in 2024 over EU-to-US driver-data transfers and a 2025 enforcement campaign warning 200+ websites over non-compliant cookie banners.

Machine-assisted translation · verified 5/23/2026 · orientation, not legal advice. English version →