Netherlands
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in the Netherlands — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
For most businesses, data can leave the Netherlands once you have the right paperwork. The Netherlands follows the ordinary European rules. Two areas are much harder. Online gambling firms must keep their regulator-facing database physically in the Netherlands. Central government must keep all its information inside Europe. The Dutch privacy regulator hands out some of the largest fines in Europe for sending data abroad wrongly.
Data governance in the Netherlands
The eight things that decide how you handle data about people in the Netherlands. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The rules apply even if you have no office in the Netherlands. Europe's privacy law, the General Data Protection Regulation, covers any company anywhere that sells goods or services to people in the Netherlands. It also covers you if you track what they do online. There is no minimum size or revenue. The new Dutch cybersecurity law adds a rule. Are you a cloud provider, data centre, managed service provider, online marketplace, search engine or social network? If you are based outside Europe and sell into the Netherlands, you must appoint a representative inside the European Union.
- What you have to do here:
- Appoint a representative
Who the privacy rules cover comes from Article 3 of the General Data Protection Regulation. The Dutch national top-up law is the Uitvoeringswet Algemene verordening gegevensbescherming, or UAVG. It adds Dutch-specific choices. It does not change who is covered. The duty to appoint a representative comes from Article 42 of the Cyberbeveiligingswet, the Dutch cybersecurity law. That law has applied since 15 August 2026. If a company from outside the European Union has appointed no representative in any member state where it offers services, it must appoint one. The Dutch cybersecurity law also covers public bodies. It covers higher education institutions too, but only after a long lead time.
Sources
- Official sourceStaatsblad van het Koninkrijk der Nederlanden 2026, 187Cyberbeveiligingswet, Act of 8 July 2026, Article 42 (appointment of a representative)
zoek.officielebekendmakingen.nl
“Indien een hierna genoemde essentiële entiteit of belangrijke entiteit ... niet in de Europese Unie is gevestigd, maar wel in Nederland diensten aanbiedt, en deze entiteit geen vertegenwoordiger heeft aangewezen in een lidstaat ... wijst deze entiteit een vertegenwoordiger aan die is gevestigd in een lidstaat van de Europese Unie.”
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankUitvoeringswet Algemene verordening gegevensbescherming (Dutch GDPR Implementation Act), consolidated text consulted 18 August 2026
wetten.overheid.nl
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation), Article 3
eur-lex.europa.eu
Where the data is allowed to live
In general yes, with paperwork. The Netherlands is an EU country, so European rules cover sending data abroad. Three Dutch rules override that. An online gambling licence holder must physically place its regulator-facing control database in the Netherlands. Central government must keep all its information inside the European Economic Area plus Switzerland. A healthcare provider, bank or insurer can put data abroad only if the supervisor can still see and audit it.
- What you have to do here:
- Keep the data in the country
Sector by sector, checked 18 August 2026. ONLINE GAMBLING. Closed. The Remote Gambling Decree says the gaming system may sit in any member state. But the control database must go in the Netherlands. A companion ministerial regulation adds that it may not sit anywhere Dutch inspectors cannot reach immediately in person. CENTRAL GOVERNMENT. Closed outside Europe. The revised government-wide cloud policy of 3 July 2026 says storage and use of data must happen within the European Economic Area and Switzerland. Email and documents may not go into public cloud at all. The only way around that is to meet three conditions and get a minister to sign off. Vital and essential bodies are advised not to use suppliers under non-EU jurisdiction for core work. Existing arrangements have four years to change. HEALTH. Conditional. We found no rule saying data must stay in the Netherlands or Europe, checked 18 August 2026. Dutch law does make the national security standards NEN 7510 and NEN 7512 legally binding on care providers running electronic exchange systems. It does the same for the access-logging standard NEN 7513. Breaking medical secrecy is a crime. BANKING, PAYMENTS, INSURANCE, SECURITIES. Conditional. We found no rule about where data must sit. Dutch banking supervision rules forbid outsourcing that would block proper supervision. The EU digital operational resilience rules cover the rest. TELECOM. Conditional. The duty to keep telecom data cannot be enforced. See the traps answer. It says nothing about where data must sit. EDUCATION, GAMING OTHER THAN GAMBLING, E-COMMERCE, MAPPING AND LOCATION DATA. We found no rule about where data must sit, checked 18 August 2026. Confidence is medium on mapping, because we searched the statute book rather than every licence condition. DEFENCE. The Ministry of Defence is left out of the government cloud policy entirely. It runs stricter rules that we could not open.
Sources
- Official sourceOverheid.nl WettenbankBesluit kansspelen op afstand (Remote Gambling Decree), Article 4.42
wetten.overheid.nl
“1 De vergunninghouder plaatst de elektronische middelen in een lidstaat of de staat waar hij met ontheffing ... zijn statutaire zetel, zijn hoofdbestuur of zijn hoofdvestiging heeft. 2 In afwijking van het eerste lid, plaatst de vergunninghouder de controledatabank, bedoeld in artikel 5.3, in Nederland.”
Link checked 18 August 2026
- Official sourceMinistry of the Interior and Kingdom Relations, tabled in ParliamentHerziening rijksbreed cloudbeleid 2026 (revised government-wide cloud policy), 3 July 2026, section 4.6
zoek.officielebekendmakingen.nl
“Voor alle informatie geldt dat opslag en verwerking plaatsvindt binnen de EER en Zwitserland.”
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankBesluit prudentiële regels Wft (Prudential Rules Decree), Article 27 — outsourcing must not obstruct supervision
wetten.overheid.nl
“gaat niet over tot het uitbesteden van werkzaamheden indien die uitbesteding een belemmering kan vormen voor een adequaat toezicht”
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankBesluit elektronische gegevensverwerking door zorgaanbieders — makes NEN 7510, 7512 and 7513 binding on care providers
wetten.overheid.nl
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Europe runs this, not the Netherlands. You may send personal data outside Europe in one of three ways. The destination country has an official decision saying it is safe enough. Or you sign Europe's standard contract with whoever receives the data. Or you use approved group-wide rules. The approved country list is full and active. The Netherlands adds no national approval step, and it bans no countries of its own.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent
Approved destinations as at 18 August 2026 are Andorra, Argentina, Brazil, Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay and the European Patent Organisation. The United States counts only for organisations self-certified under the EU-US Data Privacy Framework. The 2021 Standard Contractual Clauses are still the set to use, and they have not been amended. Europe promised extra clauses for receivers already covered directly by European privacy law. Those are still not adopted. You are still expected to write down why the destination country is safe. The Dutch regulator treats missing transfer paperwork as a very serious breach, not a technicality. It fined Uber 290 million euros (about 315 million dollars) in 2024. Uber had sent data to the United States for two years with no paperwork at all. It fined a taxi app 100 million euros (about 109 million dollars) in May 2026 for sending driver and customer data to Russia. Both cases were about sending data abroad, not about security.
Sources
- Official sourceAutoriteit PersoonsgegevensAutoriteit Persoonsgegevens — transferring personal data outside the European Economic Area
autoriteitpersoonsgegevens.nl
- Official sourceAutoriteit PersoonsgegevensDutch DPA fines taxi app Yango 100 million euros for transfers to Russia, 8 May 2026
autoriteitpersoonsgegevens.nl
“De Autoriteit Persoonsgegevens (AP) legt MLU B.V. een boete op van 100 miljoen euro, voor het doorgeven van persoonsgegevens naar Rusland.”
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Dutch Data Protection Authority enforces the rules, and it is willing to fine. It has a full three-person board. A new chair, Geert Potjewijd, took office on 1 August 2026. It has issued two of the largest fines in Europe for sending data abroad. They are 290 million euros against Uber in 2024, and 100 million euros against a taxi app in May 2026. Cybersecurity is enforced separately, by sector ministries and inspectorates. That machinery is only now being assembled.
The privacy regulator is the Autoriteit Persoonsgegevens. Its board as at 18 August 2026: Geert Potjewijd, chair since 1 August 2026, appointed for five years; Monique Verdier, deputy chair; Katja Mur, member. Its 2025 annual report was published on 2 April 2026. It describes a deliberate shift toward faster settlements and interventions alongside formal sanctions. The focus is algorithms and artificial intelligence, big tech, data trading and digital government. Its published toolkit starts with warnings and reprimands. Next come orders backed by a penalty payment, then bans on using data. At the top are fines up to 20 million euros, or four percent of worldwide turnover. Rate: aggressive. Under the new Cyberbeveiligingswet the supervisors are the responsible sector ministries. The national cyber security centre acts as the computer security incident response team. The Ministry of the Interior published a designation of supervisors and delegation of powers on 14 August 2026. That was one day before the law took effect, so this enforcement track is only starting up. Other live regulators. The Netherlands Authority for Consumers and Markets handles telecom and cookie rules. The Dutch Central Bank and the Authority for the Financial Markets handle finance. The Netherlands Gambling Authority handles online gambling. The Health and Youth Care Inspectorate handles care providers.
Sources
- Official sourceAutoriteit PersoonsgegevensGeert Potjewijd, chair of the Autoriteit Persoonsgegevens since 1 August 2026
autoriteitpersoonsgegevens.nl
“Geert Potjewijd is sinds 1 augustus 2026 voorzitter van de Autoriteit Persoonsgegevens (AP), voor een periode van 5 jaar.”
Link checked 18 August 2026
- Official sourceAutoriteit PersoonsgegevensDutch DPA imposes a fine of 290 million euros on Uber over transfers of drivers' data to the US, 26 August 2024
autoriteitpersoonsgegevens.nl
Link checked 18 August 2026
- Official sourceAutoriteit PersoonsgegevensDutch DPA annual report 2025, published 2 April 2026
autoriteitpersoonsgegevens.nl
Link checked 18 August 2026
- Official sourceStaatscourant 2026, 27674Decision of the State Secretary for the Interior of 14 August 2026 designating supervisors and delegating powers under the Cyberbeveiligingswet
zoek.officielebekendmakingen.nl
How long you must keep it — and when to delete it
There is a firm floor and a soft ceiling. You must keep your books and tax records for seven years. You must keep money-laundering records for five years after the relationship or transaction ends. Privacy law says you must delete personal data once you no longer need it. It gives no fixed number. When the two clash, the duty to keep wins for as long as it lasts. Delete straight after that.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
Here are the minimum keeping periods we verified in the statutes on 18 August 2026. Company books and records: seven years, plus seven years after a company is dissolved. Tax records: seven years. Anti-money-laundering customer and transaction records: five years from the end of the business relationship or from the transaction. Online gambling system change records: at least five years. Cybersecurity incident data held by the national response team works the other way round. It has a maximum, not a minimum. Some categories must be deleted within twelve months and others within sixty months. Care providers must log every access to an electronic patient record to a national standard. Sector bodies set how long those logs are kept, not the decree itself. This is a common source of confusion. There is no general Dutch deadline to delete. The ceiling is the European rule that you keep data no longer than you need it, plus the right to erasure. So a specific legal duty to keep a record lets you keep it for exactly that period and no longer.
Sources
- Official sourceOverheid.nl WettenbankBurgerlijk Wetboek Boek 2, Article 10 (company records, seven years) and Article 24 (seven years after dissolution)
wetten.overheid.nl
“Het bestuur is verplicht de in de leden 1 en 2 bedoelde boeken, bescheiden en andere gegevensdragers gedurende zeven jaren te bewaren.”
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankAlgemene wet inzake rijksbelastingen, Article 52 (tax records, seven years)
wetten.overheid.nl
“zijn administratieplichtigen verplicht de in de voorgaande leden bedoelde gegevensdragers gedurende zeven jaar te bewaren”
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankWet ter voorkoming van witwassen en financieren van terrorisme, Articles 33 and 34 (five years)
wetten.overheid.nl
“Een instelling bewaart de in het eerste en tweede lid bedoelde gegevens op toegankelijke wijze gedurende vijf jaar na het tijdstip van het beëindigen van de zakelijke relatie”
Link checked 18 August 2026
- Official sourceStaatsblad 2026, 187Cyberbeveiligingswet, Article 65 (deletion of incident personal data within 12 and 60 months)
zoek.officielebekendmakingen.nl
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count three clocks, not one. For a personal data breach you have 72 hours to tell the Dutch Data Protection Authority. The new cybersecurity law started on 15 August 2026. If it covers you, you must raise an early warning within 24 hours. You then file a full report within 72 hours and a final report within one month. Telecom operators have a fourth clock and must tell the privacy regulator without delay.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The 72-hour privacy clock starts the moment you become aware of the breach. It comes from European law. The cybersecurity clocks come from the Cyberbeveiligingswet. They apply to essential and important bodies across energy, transport, banking, health, water, digital infrastructure, public administration, post, waste, chemicals, food, manufacturing, digital providers and research. The early warning must say whether the incident looks malicious. It must say whether it may have effects in other countries. It must name the responsible contact. If the incident is still running when the final report is due, you file a progress report instead. The final report then follows within one month of the incident being resolved. You must also warn the users of your service where the incident may affect them. The fourth clock is Article 11.3a of the Telecommunications Act. A provider of a public electronic communications service must tell the privacy regulator without delay about a security breach affecting personal data. It must also tell affected people where the breach is likely to harm their privacy. Financial firms have a fifth set of deadlines under the European digital operational resilience rules. The overlap is where things go wrong. A ransomware attack on a hospital or a cloud provider starts the 24-hour cyber clock and the 72-hour privacy clock at the same time. They go to different authorities.
Sources
- Official sourceStaatsblad 2026, 187Cyberbeveiligingswet, Articles 26, 27 and 29 (24-hour early warning, 72-hour notification, one-month final report)
zoek.officielebekendmakingen.nl
“Dit doet zij onverwijld of, indien dat niet mogelijk is, binnen 24 uur nadat zij kennis heeft gekregen van het significante incident.”
Link checked 18 August 2026
- Official sourceAutoriteit PersoonsgegevensAutoriteit Persoonsgegevens — reporting a data breach
autoriteitpersoonsgegevens.nl
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankTelecommunicatiewet, Article 11.3a (telecom breach notification to the privacy regulator)
wetten.overheid.nl
“De aanbieder van een openbare elektronische communicatiedienst stelt de Autoriteit persoonsgegevens onverwijld in kennis van een inbreuk op de beveiliging”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things. Your works council can block an HR or monitoring system. Breaking a professional secrecy duty is a crime, not a fine. The telecom data retention duty printed in the law cannot be enforced. Children need a parent's permission until they turn sixteen. And the new cybersecurity law started on 15 August 2026, with a phased exception for universities that most checklists miss.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
1. WORKS COUNCIL VETO. Under the Works Councils Act you need the works council's consent for rules about staff personal data. That covers adopting, changing or withdrawing any rule on how staff data is used and protected. You also need consent for any system built to watch or check the presence, conduct or performance of staff. That covers HR systems, access control, camera schemes, keystroke or productivity monitoring, and most artificial intelligence tools aimed at employees. Without consent the decision can be voided. This is a Dutch trap because it is employment law, not privacy law, so privacy lawyers routinely miss it. 2. CRIMINAL LIABILITY. Deliberately breaking a duty of secrecy that comes from an office, profession or statute is a crime under the Dutch Criminal Code. The penalty is up to one year in prison, or a fifth-category fine. Since 1 January 2026 that fine is 110,000 euros (about 120,000 dollars). The sentence goes up by one third if the act was done for a foreign power. This applies to doctors, lawyers, notaries and tax advisers. It attaches to people, not to companies. 3. A LAW THAT LOOKS BINDING AND IS NOT. Article 13.2a of the Telecommunications Act still says operators must keep telephone traffic data for twelve months and internet data for six months. The Hague District Court suspended the underlying Data Retention Act on 11 March 2015. It has never been repealed or replaced. Reading the statute book alone gets this wrong. 4. AGE SIXTEEN. The Dutch implementation act sets the age of digital consent at sixteen, the top of the European range. Below that age a legal representative must consent. That consent can be withdrawn at any time. 5. PHASED CYBERSECURITY DUTIES. The Cyberbeveiligingswet took effect on 15 August 2026. But the duty of care and the governance duty only apply to designated higher education institutions 36 months after they are designated. Separately, one part of the September 2026 privacy amendment act has deliberately been left switched off.
Sources
- Official sourceOverheid.nl WettenbankWet op de ondernemingsraden (Works Councils Act), Article 27(1)(k) and (l)
wetten.overheid.nl
“k. een regeling omtrent het verwerken van alsmede de bescherming van de persoonsgegevens van de in de onderneming werkzame personen; l. een regeling inzake voorzieningen die gericht zijn op of geschikt zijn voor waarneming van of controle op aanwezigheid, gedrag of prestaties van de in de onderneming werkzame personen”
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankWetboek van Strafrecht, Article 272 (breach of secrecy) and Article 23 (fine categories, fifth category 110,000 euros from 1 January 2026)
wetten.overheid.nl
“Hij die enig geheim ... opzettelijk schendt, wordt gestraft met gevangenisstraf van ten hoogste een jaar of geldboete van de vijfde categorie.”
Link checked 18 August 2026
- Official sourceRaad voor de RechtspraakRechtbank Den Haag, 11 March 2015, ECLI:NL:RBDHA:2015:2498 — data retention law suspended
data.rechtspraak.nl
“De voorzieningenrechter: - stelt de Wet bewaarplicht telecommunicatiegegevens buiten werking”
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankUitvoeringswet Algemene verordening gegevensbescherming, Article 5 (consent below sixteen)
wetten.overheid.nl
“is in de plaats van de toestemming van de betrokkene die van zijn wettelijk vertegenwoordiger vereist indien de betrokkene de leeftijd van zestien jaren nog niet heeft bereikt”
Link checked 18 August 2026
What's changing next
Three dated changes. On 1 September 2026 an amendment act tidies up the Dutch privacy law. It also adds new rules for handing over health files. One part of it has deliberately been left switched off. Registration and incident duties under the cybersecurity law that started on 15 August 2026 are being phased in now. By 12 January 2027 every cloud provider must drop switching and data export charges to zero across Europe.
- What you have to do here:
- Make switching cloud provider possible
DATED ITEMS. 1 September 2026. The Verzamelwet gegevensbescherming comes into force. This is the Act of 9 June 2026 that amends the Dutch privacy implementation act. One part is held back by the commencement decree of 9 July 2026. The act adds exemptions for statutory audit work. It adds two new rules on handing over health files, one for care providers and one for others. It adds a rule for temporary commissions and advisory boards, plus transitional rules. 15 August 2026. The Cyberbeveiligingswet and its implementing decree took effect. They repealed the older network and information systems security law. The national register of bodies must be up within one month of the register rule starting. The Critical Entities Resilience Act was enacted the same day. 12 January 2027. Under the European Data Act all cloud switching charges and data export fees must be zero. POWERS THAT CAN BE USED WITHOUT WARNING. These matter more than pending bills. The government cloud policy is ministerial policy, not law. Its scope, its four-year transition and its exceptions can be tightened at any moment without consultation. Parliament has already asked for at least 30 percent of central government cloud storage and applications to come from Dutch or European soil by 2029. The policy says it will be rewritten once a sovereign government cloud exists. The telecom retention articles are still printed in the Telecommunications Act. A new act or a successful appeal could make them live again, with no new parliamentary vote on the text itself. The cybersecurity law lets ministers name extra essential and important bodies by decision. That can pull a company into 24-hour incident reporting overnight. At European level, the European Data Protection Board wrote to the Commission on 31 July 2026. It asked the Commission to re-examine the EU-US Data Privacy Framework. That is the single biggest outside risk to any Dutch business relying on that route alone.
Sources
- Official sourceStaatsblad 2026, 196Royal Decree of 9 July 2026 setting 1 September 2026 as the commencement date of the Verzamelwet gegevensbescherming
zoek.officielebekendmakingen.nl
“(Verzamelwet gegevensbescherming), met uitzondering van artikel I, onderdeel I, treedt in werking met ingang van 1 september 2026.”
Link checked 18 August 2026
- Official sourceStaatsblad 2026, 189Cyberbeveiligingsbesluit, Article 35 — the Cyberbeveiligingswet and this decree enter into force on 15 August 2026
zoek.officielebekendmakingen.nl
“De Cyberbeveiligingswet en dit besluit treden in werking met ingang van 15 augustus 2026.”
Link checked 18 August 2026
- Official sourceMinistry of the Interior and Kingdom RelationsHerziening rijksbreed cloudbeleid 2026 — 30 percent Dutch-European target by 2029 and four-year transition
zoek.officielebekendmakingen.nl
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2023/2854 (Data Act) — zero switching charges from 12 January 2027
eur-lex.europa.eu
What to do: Diarise 12 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Online gaming data must stay in the country
Official name: Besluit kansspelen op afstand, artikel 4.42, tweede lid · Decree of 26 January 2021; consolidated text in force from 15 July 2022 · Directly binding regulation
This is the strictest storage rule in Dutch law. An online gambling licence holder must physically place its regulator-facing control database in the Netherlands. It may not place it anywhere the regulator's inspectors cannot reach immediately in person. There is no paperwork route around it.
Enforced by Netherlands Gambling Authority
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryThe control database itself must be placed in the Netherlands. The rest of the gaming system may sit in any member state. It may also sit in the state of the licensee's registered office, where an exemption has been granted.
- Keep logs — 5 yearsEvery change to the gaming system must be recorded and kept for at least five years.
- Register or notifyRemote gambling licences run for at most five years. The control database must meet technical specifications set by the regulator, agreed with the tax administration.
What it costs if you get it wrong
- Loss of your licenceBreach of licence conditions, including the placement of the control database
Sources
- Official sourceOverheid.nl WettenbankBesluit kansspelen op afstand, Article 4.42
wetten.overheid.nl
“In afwijking van het eerste lid, plaatst de vergunninghouder de controledatabank, bedoeld in artikel 5.3, in Nederland.”
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankRegeling kansspelen op afstand, Articles 4.19 to 4.21 (integrity, separation and physical placement of the control database), text in force from 1 April 2026
wetten.overheid.nl
“De vergunninghouder plaatst de controledatabank niet in een woning of een andere ruimte waartoe de ambtenaren en personen, bedoeld in artikel 34 van de wet, geen onverwijlde, fysieke toegang tot kunnen verkrijgen.”
Link checked 18 August 2026
- Official sourceKansspelautoriteitKansspelautoriteit (Netherlands Gambling Authority)
kansspelautoriteit.nl
Government data must stay in the country
Official name: Herziening rijksbreed cloudbeleid 2026 · Policy of 3 July 2026, issued under the Coördinatiebesluit organisatie, bedrijfsvoering en informatiesystemen rijksdienst and the Besluit CIO-stelsel Rijksdienst 2026; tabled in Parliament as blg-1264434 · Government policy document
Central government's own cloud rule, tightened on 3 July 2026. All central government information must be stored and used inside the European Economic Area and Switzerland. Email and documents are pushed out of public cloud unless a minister signs off. Suppliers from countries running an active cyber programme against Dutch interests are excluded outright.
That is a long gap: the duty is real law today, but no penalty can follow until 3 July 2030. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Chief Information Officer of Central Government
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the country — from 3 July 2026Storage and use of data must take place within the European Economic Area and Switzerland. Existing arrangements have four years to change. Longer is allowed where a contract runs longer, or where migration costs or risks are excessive.
- Prove the data stays under local controlVital providers are advised not to use suppliers that fall wholly or partly under jurisdiction outside the European Union for their main work. The same advice covers bodies under the Critical Entities Resilience Act and essential bodies under the cybersecurity law.
- Keep records of how you use dataEvery department must keep a register of which public cloud is used for what, and of the risks.
- Assess high-risk projectsSpecial categories of personal data should preferably stay out of public cloud. Where they must go in, you need a data protection impact assessment and privacy-enhancing technology.
- Secure the dataData must be encrypted when stored and when sent. Key management should preferably not sit with the cloud provider.
Sources
- Official sourceMinistry of the Interior and Kingdom Relations, tabled in the House of RepresentativesHerziening rijksbreed cloudbeleid 2026, 3 July 2026, sections 4.3, 4.5, 4.6 and 5
zoek.officielebekendmakingen.nl
“Voor alle informatie geldt dat opslag en verwerking plaatsvindt binnen de EER en Zwitserland. Voor informatie en processen die nationale veiligheid of digitale autonomie raken, zullen aanvullende eisen worden gesteld.”
Link checked 18 August 2026
Health data rules
Official name: Besluit elektronische gegevensverwerking door zorgaanbieders · Consolidated text in force from 1 October 2020; Articles 3 and 5 · Directly binding regulation
Dutch healthcare has no rule about where data must be stored. It does have strict security law. National standards for information security, and for logging every access to a patient record, are legally binding. Breaking medical secrecy is a crime rather than an administrative fine.
Enforced by Health and Youth Care Inspectorate
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Hold a security certificateThe Dutch health information security standards NEN 7510 and NEN 7512 are made legally binding on anyone responsible for an electronic exchange system in care.
- Keep logsSystem logging must meet the Dutch access-logging standard NEN 7513. Sector bodies set how long those logs are kept and publish it in the official gazette. The decree itself does not set it.
- Extra vendor secrecy termsBreaking medical secrecy is a crime under the Dutch Criminal Code. So a standard supplier data contract is not enough for a cloud arrangement in care.
What it costs if you get it wrong
- Criminal liability: Up to one year in prison or a fifth-category fine of €110,000 — about $120 thousandDeliberate breach of a professional or statutory duty of secrecy
Sources
- Official sourceOverheid.nl WettenbankBesluit elektronische gegevensverwerking door zorgaanbieders, Articles 3 and 5
wetten.overheid.nl
“De verantwoordelijke voor een elektronisch uitwisselingssysteem draagt overeenkomstig het bepaalde in NEN 7510 en NEN 7512, zorg voor een veilig en zorgvuldig gebruik”
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankWet elektronische gegevensuitwisseling in de zorg, text in force from 5 July 2025 — checked for a storage location rule, none found
wetten.overheid.nl
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankWetboek van Strafrecht, Articles 23 and 272
wetten.overheid.nl
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Besluit prudentiële regels Wft, hoofdstuk 5 (uitbesteden van werkzaamheden) · Decree of 12 October 2006; consolidated text in force from 29 May 2026, Articles 27 to 32a · Directly binding regulation
Dutch banking, payments, insurance and securities rules say nothing about where data must be stored, checked 18 August 2026. They do ban any outsourcing that would block proper supervision. So an offshore cloud arrangement fails if the supervisor cannot inspect it. Europe's digital operational resilience rules sit on top of this.
Enforced by Dutch Central Bank
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Written vendor contractStructural outsourcing must be in a written contract, and the firm must retain the procedures, expertise and information needed to assess the outsourced work.
- Independent auditOutsourcing must not block proper supervision. That means the supervisor and the firm's auditors must keep real access wherever the data sits.
What it costs if you get it wrong
- Order to stopSupervisory instruction to unwind or amend an outsourcing arrangement
- Loss of your licencePersistent breach of prudential requirements
Sources
- Official sourceOverheid.nl WettenbankBesluit prudentiële regels Wft, Articles 27 to 32a, text in force from 29 May 2026
wetten.overheid.nl
“gaat niet over tot het uitbesteden van werkzaamheden indien die uitbesteding een belemmering kan vormen voor een adequaat toezicht op de naleving van het bij of krachtens het Deel Prudentieel toezicht financiële ondernemingen van de wet bepaalde”
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2022/2554 (Digital Operational Resilience Act), applicable since 17 January 2025
eur-lex.europa.eu
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Uitvoeringswet Algemene verordening gegevensbescherming (UAVG) · Act of 16 May 2018; amended by the Verzamelwet gegevensbescherming, Act of 9 June 2026, commencing 1 September 2026 (Stb. 2026, 196) · Act of parliament
The Dutch national top-up to Europe's privacy law. It says nothing about where data must be stored. It sets the age of digital consent at sixteen. It leaves sending data abroad to Europe's approved country list. An amendment act starts on 1 September 2026, with one part deliberately left switched off.
Enforced by Dutch Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Keep records of how you use data
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Get a parent's consent for children — applies at: under 16The Netherlands chose the top of the European range. Consent by a legal representative can be withdrawn at any time.
- Appoint a data protection officerRequired for public bodies. Also required if you monitor people on a large scale, or handle special categories of data. Under the Dutch implementing act the officer must keep information confidential.
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: €10 million or 2% of worldwide group turnover — about $11 millionSecurity, records, breach notification and processor duties
- Order to stopProcessing ban, including a ban on further transfers abroad
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceOverheid.nl WettenbankUitvoeringswet Algemene verordening gegevensbescherming, consolidated text
wetten.overheid.nl
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankUitvoeringswet AVG — future text applicable from 1 September 2026 (adds Articles 21b, 23a, 30a, 30b, 47a and 48b)
wetten.overheid.nl
Link checked 18 August 2026
- Official sourceStaatsblad 2026, 196Royal Decree of 9 July 2026 on commencement of the Verzamelwet gegevensbescherming
zoek.officielebekendmakingen.nl
Link checked 18 August 2026
Cyber security rules
Official name: Cyberbeveiligingswet (Cbw) · Act of 8 July 2026, Stb. 2026, 187; commenced by Article 35 of the Cyberbeveiligingsbesluit, Stb. 2026, 189 · Act of parliament
The Dutch version of Europe's cybersecurity directive. It has applied since 15 August 2026 and repeals the older Dutch network security law. It adds a 24-hour early warning, a 72-hour report and a one-month final report. It says nothing about where data must be stored. It does force digital infrastructure providers from outside the European Union to appoint a European representative.
Enforced by National Cyber Security Centre
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 24 hours, from 15 August 2026Early warning to the response team and the competent authority.
- Report cyber incidents — within 72 hours, from 15 August 2026Full notification with initial assessment. Final report due within one month.
- Secure the data — from 15 August 2026Duty of care. For designated higher education institutions, this duty and the governance duty only start 36 months after designation.
- Register or notify — from 15 August 2026You must supply information for the national register. Digital service providers must also supply the European agency's register. Report changes within three months.
- Appoint a representative — from 15 August 2026Cloud, data centre, content delivery, managed service, marketplace, search and social network providers based outside the European Union must appoint a representative in the European Union. This applies if you offer services in the Netherlands.
- Delete data after a period — 5 yearsApplies to incident personal data held by the competent authority. For data held by the response team the period is 12 months.
What it costs if you get it wrong
- Percentage of global turnover: €10 million or 2% of worldwide annual turnover, whichever is higher — about $11 millionEssential entity breaching the duty of care or reporting duties
- Percentage of global turnover: €7 million or 1.4% of worldwide annual turnover, whichever is higher — about $8 millionImportant entity breaching the duty of care or reporting duties
- Fixed maximum fine: €1 million — about $1 millionAny other breach
Sources
- Official sourceStaatsblad van het Koninkrijk der Nederlanden 2026, 187Cyberbeveiligingswet, Act of 8 July 2026
zoek.officielebekendmakingen.nl
Link checked 18 August 2026
- Official sourceStaatsblad 2026, 189Cyberbeveiligingsbesluit, Decree of 8 July 2026, Article 35 (commencement 15 August 2026)
zoek.officielebekendmakingen.nl
“De Cyberbeveiligingswet en dit besluit treden in werking met ingang van 15 augustus 2026.”
Link checked 18 August 2026
Works council sign-off for staff data systems
Official name: Wet op de ondernemingsraden, artikel 27, eerste lid, onder k en l · Consolidated text in force from 18 February 2023 · Act of parliament
A purely Dutch veto that sits outside privacy law. Before you deploy an HR system, access control, cameras, productivity monitoring or an employee-facing artificial intelligence tool, the works council has to agree. A decision taken without that consent can be voided.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What it costs if you get it wrong
- Claims by individualsA decision taken without the works council's consent can be declared void, and the works council can seek an injunction
Sources
- Official sourceOverheid.nl WettenbankWet op de ondernemingsraden, Article 27
wetten.overheid.nl
“De ondernemer behoeft de instemming van de ondernemingsraad voor elk door hem voorgenomen besluit tot vaststelling, wijziging of intrekking van: ... k. een regeling omtrent het verwerken van alsmede de bescherming van de persoonsgegevens van de in de onderneming werkzame personen”
Link checked 18 August 2026
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
Telecoms rules
Official name: Telecommunicatiewet, artikel 13.2a (Wet bewaarplicht telecommunicatiegegevens) · Still printed in the consolidated Telecommunicatiewet as at 15 August 2026; suspended by Rechtbank Den Haag, 11 March 2015, ECLI:NL:RBDHA:2015:2498 · Act of parliament
A retention duty that a text search of Dutch law would wrongly report as binding. The Telecommunications Act still prints articles requiring twelve months of telephone data and six months of internet data. The Hague District Court suspended the underlying act on 11 March 2015. It has never been repealed or replaced.
Enforced by Netherlands Authority for Digital Infrastructure
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 1 yearFixed and mobile telephone data. This cannot be enforced. A court order suspended it on 11 March 2015 and it was never repealed.
- Keep data for a minimum period — 6 monthsInternet access, internet email and internet telephony data. Same suspension applies.
Sources
- Official sourceRaad voor de RechtspraakRechtbank Den Haag, 11 March 2015, C/09/480009 KG ZA 14/1575 — Data Retention Act suspended
data.rechtspraak.nl
“De kortgedingrechter in Den Haag heeft de Wet bewaarplicht telecommunicatiegegevens buiten werking gesteld.”
Link checked 18 August 2026
- Official sourceOverheid.nl WettenbankTelecommunicatiewet, Article 13.2a, consolidated text in force from 15 August 2026 — still printed
wetten.overheid.nl
“De gegevens, bedoeld in het tweede lid, worden door de aanbieders bewaard gedurende een periode van: a. twaalf maanden voor gegevens in verband met telefonie ... b. zes maanden voor gegevens in verband met internettoegang”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact original commencement dates of the Besluit kansspelen op afstand (recorded here as 1 April 2021, biting from 1 October 2021)
We could not confirm the exact start dates. We did check the current consolidated text, which says it has been in force since 15 July 2022. We also checked the underlying decree date of 26 January 2021. We did not open the commencement decree. The storage rule itself is confirmed from the statute text and is not in doubt.
Whether any licence conditions, ministerial regulations or supervisory instructions impose keeping data in the country in mapping and geospatial, education, or defence
We searched the consolidated statute book and found no such rule as at 18 August 2026. We did not review individual licences. We also did not review the Ministry of Defence rules, which sit outside the government cloud policy and which we could not open. Check before you rely on this.
Whether the Dutch Central Bank or the Authority for the Financial Markets has published guidance that goes beyond the statutory outsourcing rules on where financial data may be stored
Both regulator websites refused our requests on 18 August 2026. So the finance rule rests only on the statute text, and we rate it medium confidence. Check with the regulator before you rely on it.
Whether any supervisor has been formally designated and is operational for every sector under the Cyberbeveiligingswet
We could not confirm which sectors the new supervisors cover. A designation of supervisors and delegation of powers dated 14 August 2026 was published in the official gazette. We did not read the full text. The law itself started on 15 August 2026.
The precise retention periods for access logs to electronic patient records
We could not confirm how long access logs must be kept. The decree makes the national logging standard binding and leaves the keeping period to sector bodies. Those bodies publish it separately in the official gazette. If you run care systems, check for your sector's notice.
Whether a bill to replace the suspended telecom data retention regime is currently before Parliament
We confirmed that the articles are still printed in the Telecommunications Act, and that the court suspension of 11 March 2015 stands. We did not check the whole legislative pipeline for a replacement. Check before you assume the duty stays unenforceable.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.