Skip to the content
Global Data RulesData governance rules, country by country

Netherlands

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in the Netherlands — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Aggressive

For most businesses, data can leave the Netherlands once you have the right paperwork. The Netherlands follows the ordinary European rules. Two areas are much harder. Online gambling firms must keep their regulator-facing database physically in the Netherlands. Central government must keep all its information inside Europe. The Dutch privacy regulator hands out some of the largest fines in Europe for sending data abroad wrongly.

Data governance in the Netherlands

The eight things that decide how you handle data about people in the Netherlands. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The rules apply even if you have no office in the Netherlands. Europe's privacy law, the General Data Protection Regulation, covers any company anywhere that sells goods or services to people in the Netherlands. It also covers you if you track what they do online. There is no minimum size or revenue. The new Dutch cybersecurity law adds a rule. Are you a cloud provider, data centre, managed service provider, online marketplace, search engine or social network? If you are based outside Europe and sell into the Netherlands, you must appoint a representative inside the European Union.

What you have to do here:
Appoint a representative

Where the data is allowed to live

In general yes, with paperwork. The Netherlands is an EU country, so European rules cover sending data abroad. Three Dutch rules override that. An online gambling licence holder must physically place its regulator-facing control database in the Netherlands. Central government must keep all its information inside the European Economic Area plus Switzerland. A healthcare provider, bank or insurer can put data abroad only if the supervisor can still see and audit it.

What you have to do here:
Keep the data in the country

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Europe runs this, not the Netherlands. You may send personal data outside Europe in one of three ways. The destination country has an official decision saying it is safe enough. Or you sign Europe's standard contract with whoever receives the data. Or you use approved group-wide rules. The approved country list is full and active. The Netherlands adds no national approval step, and it bans no countries of its own.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Dutch Data Protection Authority enforces the rules, and it is willing to fine. It has a full three-person board. A new chair, Geert Potjewijd, took office on 1 August 2026. It has issued two of the largest fines in Europe for sending data abroad. They are 290 million euros against Uber in 2024, and 100 million euros against a taxi app in May 2026. Cybersecurity is enforced separately, by sector ministries and inspectorates. That machinery is only now being assembled.

How long you must keep it — and when to delete it

There is a firm floor and a soft ceiling. You must keep your books and tax records for seven years. You must keep money-laundering records for five years after the relationship or transaction ends. Privacy law says you must delete personal data once you no longer need it. It gives no fixed number. When the two clash, the duty to keep wins for as long as it lasts. Delete straight after that.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count three clocks, not one. For a personal data breach you have 72 hours to tell the Dutch Data Protection Authority. The new cybersecurity law started on 15 August 2026. If it covers you, you must raise an early warning within 24 hours. You then file a full report within 72 hours and a final report within one month. Telecom operators have a fourth clock and must tell the privacy regulator without delay.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things. Your works council can block an HR or monitoring system. Breaking a professional secrecy duty is a crime, not a fine. The telecom data retention duty printed in the law cannot be enforced. Children need a parent's permission until they turn sixteen. And the new cybersecurity law started on 15 August 2026, with a phased exception for universities that most checklists miss.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability

What's changing next

Three dated changes. On 1 September 2026 an amendment act tidies up the Dutch privacy law. It also adds new rules for handing over health files. One part of it has deliberately been left switched off. Registration and incident duties under the cybersecurity law that started on 15 August 2026 are being phased in now. By 12 January 2027 every cloud provider must drop switching and data export charges to zero across Europe.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 12 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Online gaming data must stay in the country

Official name: Besluit kansspelen op afstand, artikel 4.42, tweede lid · Decree of 26 January 2021; consolidated text in force from 15 July 2022 · Directly binding regulation

In forceNo — it stays put

This is the strictest storage rule in Dutch law. An online gambling licence holder must physically place its regulator-facing control database in the Netherlands. It may not place it anywhere the regulator's inspectors cannot reach immediately in person. There is no paperwork route around it.

In force since 1 April 2021Enforced from 1 October 2021

Enforced by Netherlands Gambling Authority

How this country controls where data goes: Not allowed

Government

Government data must stay in the country

Official name: Herziening rijksbreed cloudbeleid 2026 · Policy of 3 July 2026, issued under the Coördinatiebesluit organisatie, bedrijfsvoering en informatiesystemen rijksdienst and the Besluit CIO-stelsel Rijksdienst 2026; tabled in Parliament as blg-1264434 · Government policy document

In forceNo — it stays put

Central government's own cloud rule, tightened on 3 July 2026. All central government information must be stored and used inside the European Economic Area and Switzerland. Email and documents are pushed out of public cloud unless a minister signs off. Suppliers from countries running an active cyber programme against Dutch interests are excluded outright.

In force since 3 July 2026In force now, but not enforced until 3 July 2030

That is a long gap: the duty is real law today, but no penalty can follow until 3 July 2030. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Chief Information Officer of Central Government

How this country controls where data goes: Not allowed

Health and social care

Health data rules

Official name: Besluit elektronische gegevensverwerking door zorgaanbieders · Consolidated text in force from 1 October 2020; Articles 3 and 5 · Directly binding regulation

In forceYes, with paperwork

Dutch healthcare has no rule about where data must be stored. It does have strict security law. National standards for information security, and for logging every access to a patient record, are legally binding. Breaking medical secrecy is a crime rather than an administrative fine.

In force since 1 January 2018Enforced from 1 October 2020

Enforced by Health and Youth Care Inspectorate

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Uitvoeringswet Algemene verordening gegevensbescherming (UAVG) · Act of 16 May 2018; amended by the Verzamelwet gegevensbescherming, Act of 9 June 2026, commencing 1 September 2026 (Stb. 2026, 196) · Act of parliament

Partly in forceYes, with paperwork

The Dutch national top-up to Europe's privacy law. It says nothing about where data must be stored. It sets the age of digital consent at sixteen. It leaves sending data abroad to Europe's approved country list. An amendment act starts on 1 September 2026, with one part deliberately left switched off.

In force since 25 May 2018

Enforced by Dutch Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

Cyber security rules

Official name: Cyberbeveiligingswet (Cbw) · Act of 8 July 2026, Stb. 2026, 187; commenced by Article 35 of the Cyberbeveiligingsbesluit, Stb. 2026, 189 · Act of parliament

Partly in forceYes — store it anywhere

The Dutch version of Europe's cybersecurity directive. It has applied since 15 August 2026 and repeals the older Dutch network security law. It adds a 24-hour early warning, a 72-hour report and a one-month final report. It says nothing about where data must be stored. It does force digital infrastructure providers from outside the European Union to appoint a European representative.

In force since 15 August 2026

Enforced by National Cyber Security Centre

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Works council sign-off for staff data systems

Official name: Wet op de ondernemingsraden, artikel 27, eerste lid, onder k en l · Consolidated text in force from 18 February 2023 · Act of parliament

In forceYes — store it anywhere

A purely Dutch veto that sits outside privacy law. Before you deploy an HR system, access control, cameras, productivity monitoring or an employee-facing artificial intelligence tool, the works council has to agree. A decision taken without that consent can be voided.

In force since 1 April 1971

How this country controls where data goes: No restriction · Accepted routes: Nothing required

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

Telecoms

Telecoms rules

Official name: Telecommunicatiewet, artikel 13.2a (Wet bewaarplicht telecommunicatiegegevens) · Still printed in the consolidated Telecommunicatiewet as at 15 August 2026; suspended by Rechtbank Den Haag, 11 March 2015, ECLI:NL:RBDHA:2015:2498 · Act of parliament

UnenforceableYes — store it anywhere

A retention duty that a text search of Dutch law would wrongly report as binding. The Telecommunications Act still prints articles requiring twelve months of telephone data and six months of internet data. The Hague District Court suspended the underlying act on 11 March 2015. It has never been repealed or replaced.

In force since 1 September 2009

Enforced by Netherlands Authority for Digital Infrastructure

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Autoriteit Persoonsgegevens

    General privacy law, cookies alongside the consumer and markets authority, coordination of algorithm and artificial intelligence supervision

    Fully staffed and highly active. The board has three members. Geert Potjewijd took office as chair on 1 August 2026 for a five-year term, succeeding Aleid Wolfsen. Monique Verdier is deputy chair and Katja Mur is a member. It fined Uber 290 million euros in August 2024. It fined MLU B.V., the operator of the Yango taxi app, 100 million euros in May 2026. Both fines were for sending data out of Europe unlawfully. Its 2025 annual report was published on 2 April 2026. It sets out five focus areas: algorithms and artificial intelligence, freedom and security, big tech, data trading and digital government.

  • Nationaal Cyber Security Centrum

    Computer security incident response team under the Cyberbeveiligingswet; receives 24-hour early warnings and 72-hour incident reports

    Long-established. But its legal role under the new cybersecurity law only started on 15 August 2026. A designation of supervisors and delegation of powers was published on 14 August 2026. This enforcement track is still being assembled.

  • Rijksinspectie Digitale Infrastructuur

    Telecom networks, spectrum, digital infrastructure security and integrity

  • Autoriteit Consument & Markt

    Telecommunications Act enforcement including cookie and unsolicited communication rules

  • De Nederlandsche Bank

    Prudential supervision of banks, insurers, payment institutions and pension funds, including outsourcing and operational resilience

  • Autoriteit Financiële Markten

    Conduct supervision of securities markets and financial services

  • Kansspelautoriteit

    Online gambling licensing, including the control database that must sit in the Netherlands

  • Inspectie Gezondheidszorg en Jeugd

    Care providers, including the binding national information security and access-logging standards

  • CIO Rijk, Ministerie van Binnenlandse Zaken en Koninkrijksrelaties

    Government-wide cloud policy, including the requirement to keep all central government information inside the European Economic Area and Switzerland

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact original commencement dates of the Besluit kansspelen op afstand (recorded here as 1 April 2021, biting from 1 October 2021)

    We could not confirm the exact start dates. We did check the current consolidated text, which says it has been in force since 15 July 2022. We also checked the underlying decree date of 26 January 2021. We did not open the commencement decree. The storage rule itself is confirmed from the statute text and is not in doubt.

  • Whether any licence conditions, ministerial regulations or supervisory instructions impose keeping data in the country in mapping and geospatial, education, or defence

    We searched the consolidated statute book and found no such rule as at 18 August 2026. We did not review individual licences. We also did not review the Ministry of Defence rules, which sit outside the government cloud policy and which we could not open. Check before you rely on this.

  • Whether the Dutch Central Bank or the Authority for the Financial Markets has published guidance that goes beyond the statutory outsourcing rules on where financial data may be stored

    Both regulator websites refused our requests on 18 August 2026. So the finance rule rests only on the statute text, and we rate it medium confidence. Check with the regulator before you rely on it.

  • Whether any supervisor has been formally designated and is operational for every sector under the Cyberbeveiligingswet

    We could not confirm which sectors the new supervisors cover. A designation of supervisors and delegation of powers dated 14 August 2026 was published in the official gazette. We did not read the full text. The law itself started on 15 August 2026.

  • The precise retention periods for access logs to electronic patient records

    We could not confirm how long access logs must be kept. The decree makes the national logging standard binding and leaves the keeping period to sector bodies. Those bodies publish it separately in the official gazette. If you run care systems, check for your sector's notice.

  • Whether a bill to replace the suspended telecom data retention regime is currently before Parliament

    We confirmed that the articles are still printed in the Telecommunications Act, and that the court suspension of 11 March 2015 stands. We did not check the whole legislative pipeline for a replacement. Check before you assume the duty stays unenforceable.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.