Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
cite UAVG, Art. 29
stage In effect
since 2018-05-25
source wetten.overheid.nl, UAVG Art. 29 (direct fetch, verbatim, confirmed twice)
UAVG Article 29 is a genuine Dutch national addition beyond the General Data Protection Regulation (GDPR) Article 9 baseline, confirmed verbatim by direct fetch: it exercises the GDPR Article 9(2)(g) substantial public-interest derogation to permit processing biometric data for unique identification specifically where necessary for authentication or security purposes.
The provision does not itself enumerate safeguards, a retention limit, or qualifying use cases beyond authentication or security, and no further AP guidance elaborating its boundaries was found. The exception applies equally to a voiceprint and a faceprint; UAVG Article 29's own text does not distinguish by modality, and no AP guidance specifically addressing voiceprint biometrics as distinct from facial biometrics was found.
What it asks of an app →
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34; UAVG, Art. 42
stage In effect
since 2018-05-25
source GDPR Arts. 33-34
A controller must notify the AP within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. UAVG Article 42 adds one national exception to the Article 34 individual-notification duty; this session confirmed the article's existence and heading via the table of contents but did not fetch its full substantive text.
What it asks of an app →
Comprehensive regime
cite Wet van 16 mei 2018, houdende regels ter uitvoering van de Algemene verordening gegevensbescherming (BWBR0040940)
stage In effect
since 2018-05-25
source wetten.overheid.nl, consolidated text (direct fetch, full table of contents and Art. 1)
The Netherlands gives the General Data Protection Regulation (GDPR) domestic effect through the UAVG (GDPR Implementation Act, Wet van 16 mei 2018), in force since 25 May 2018 alongside the GDPR itself. UAVG Chapter 2 (Arts. 6-21a) establishes the Autoriteit Persoonsgegevens (AP) as supervisory authority, and Chapters 3-4 supply national derogations under GDPR Articles 6, 9, 10, and 23.
UAVG Article 1's definitions, confirmed by direct fetch, add only four defined terms and do not redefine any GDPR term including biometric data, so nothing in UAVG narrows a GDPR definition.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)
stage In effect
since 2018-05-25
source GDPR Arts. 44-49, 83(5)
A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Netherlands-specific derogation from this framework was identified in the UAVG.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Arts. 12-23; UAVG, Arts. 40, 41, 43
stage In effect
since 2018-05-25
source wetten.overheid.nl, UAVG Art. 43 (direct fetch, verbatim)
General Data Protection Regulation (GDPR) Articles 12-23 apply directly: access, rectification, erasure, restriction, portability, objection, and Article 22 automated-decision rights. UAVG Article 40 gives GDPR Article 22 its own domestic exceptions (not to be confused with UAVG's own Article 22, the special-categories prohibition, a distinct provision under the same number).
UAVG Article 43, confirmed verbatim by direct fetch, is the significant national narrowing: for processing carried out exclusively for journalistic purposes or academic, artistic, or literary expression, most of GDPR Chapter III's data-subject rights and Chapters IV-VII do not apply, and Articles 9 and 10 are disapplied to the extent the processing serves those purposes.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83; UAVG, Arts. 16-18; Wet Afwikkeling Massaschade in Collectieve Actie (WAMCA)
stage In effect
since 2018-05-25
source GDPR Arts. 82-83
The Autoriteit Persoonsgegevens (AP) is the Dutch supervisory authority, with General Data Protection Regulation (GDPR) Article 83 fines plus UAVG's own administrative powers including a fine specific to unlawful processing of criminal-conviction data (Art. 17) and administrative fines against government bodies (Art. 18).
GDPR Article 82 arms an individual with a direct private right of action, and the Netherlands' WAMCA collective-action regime is a live vehicle for privacy mass claims: a Consumentenbond and Stichting Take Back Your Privacy claim against TikTok, over unauthorized collection of children's personal data, is currently paused pending a Hoge Raad ruling in a related Oracle/Salesforce case expected 4 September 2026.
What it asks of an app →
Sensitive categories
cite UAVG, Arts. 30-33, 46
stage In effect
since 2018-05-25
source wetten.overheid.nl, UAVG Arts. 1, 22, 24-31 (direct fetch)
UAVG Chapter 3 Section 3.1 (Arts. 22-30) implements General Data Protection Regulation (GDPR) Article 9's special-category regime with article-by-article national exceptions, confirmed by direct fetch: research and statistics, racial or ethnic origin, political opinions, religious or philosophical beliefs, and genetic data (Arts. 24-28), a health-data exception for administrative bodies, pension funds, and employers (Art. 30), and rules on criminal-conviction data (Art. 31).
Article 46 restricts processing of the citizen service number (BSN); this session confirmed the article's existence and heading but not its full text before the fetch truncated. The AP's own scraping guidance (published 1 May 2024, described in secondary commentary since the PDF itself returned HTTP 403 to a direct fetch) states that publicly available information does not become lawfully processable merely because the source was public.
What it asks of an app →