Skip to the content
Global Data RulesData governance rules, country by country

Netherlands

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Aggressive

For most businesses the Netherlands follows the ordinary European rules: data may leave the country once you have the right paperwork in place. Two areas are much harder. Online gambling firms must keep their regulator-facing database physically in the Netherlands, and central government now has to keep all its information inside Europe. The Dutch privacy regulator hands out some of the largest transfer fines in Europe.

Eight questions about the Netherlands

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do the Netherlands' rules apply to my company?

Yes, it reaches you with no Dutch office. Europe's privacy law applies to any organisation anywhere that offers goods or services to people in the Netherlands or watches what they do online, and there is no size or revenue floor. Separately, the new Dutch cybersecurity law says that if you are a cloud provider, data centre, managed service provider, online marketplace, search engine or social network based outside Europe but selling into the Netherlands, you must appoint a representative inside the European Union.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside the Netherlands?

In general yes, with paperwork, because the Netherlands is an EU country and European rules govern transfers. But three Dutch walls override that. An online gambling licence holder must physically place its regulator-facing control database in the Netherlands. Central government must keep all its information inside the European Economic Area plus Switzerland. And a healthcare provider, bank or insurer can put data abroad only if the supervisor can still see and audit it.

High confidenceDepends on your industryBlocklistKeep the data in the country

What do I need in place before data leaves the Netherlands?

The model is an allowlist run at European level, not a Dutch one. You may send personal data outside Europe only if the destination has been officially approved, or you sign the standard European contract, or you use approved group-wide rules. The approved list is full and active. The Netherlands adds no national approval step and keeps no blocklist of its own.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentPut a transfer safeguard in place

Who enforces the rules in the Netherlands, and what can they do?

The Dutch Data Protection Authority, and it is very much operational and very much willing to fine. It has a full three-person board, and a new chair, Geert Potjewijd, took office on 1 August 2026. It has issued two of the largest cross-border transfer fines in Europe: 290 million euros against Uber in 2024 and 100 million euros against a taxi app in May 2026. Cybersecurity is enforced separately, by sector ministries and inspectorates, and that machinery is only now being assembled.

High confidenceAggressive

How long do I have to keep the data?

There is a firm floor and a soft ceiling. You must keep your books and tax records for seven years, and money-laundering records for five years after the relationship or transaction ends. Against that, privacy law says you must delete personal data once you no longer need it, and there is no fixed number. When the two collide, the legal duty to keep wins for as long as it lasts, and deletion follows immediately after.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Count three clocks, not one. For a personal data breach you have 72 hours to tell the Dutch Data Protection Authority. If you are covered by the new cybersecurity law that started on 15 August 2026, you must raise an early warning within 24 hours, file a full report within 72 hours, and deliver a final report within one month. Telecom operators have a fourth clock and must tell the privacy regulator without delay.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in the Netherlands?

Five things that are not in the summary. Your works council can block an HR or monitoring system. Breaking a professional secrecy duty is a crime, not a fine. The telecom retention duty printed in the law cannot be enforced. Children need a parent's permission until they turn sixteen. And the new cybersecurity law started on 15 August 2026 with a phased exception for universities that most checklists miss.

High confidenceCriminal liabilityUnenforceableGet a parent's consent for childrenPartly in force

What is changing soon in the Netherlands?

Three dated changes. On 1 September 2026 an amendment act tidies up the Dutch privacy law and adds new rules for handing over health files, but one part of it has deliberately been left switched off. Registration and incident duties under the cybersecurity law that started on 15 August 2026 are being phased in now. And by 12 January 2027 every cloud provider must drop switching and data export charges to zero across Europe.

High confidencePartly in forceMake switching cloud provider possible

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    5 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules3 rules

Uitvoeringswet Algemene verordening gegevensbescherming (UAVG)

Act of parliament · Act of 16 May 2018; amended by the Verzamelwet gegevensbescherming, Act of 9 June 2026, commencing 1 September 2026 (Stb. 2026, 196)

Partly in forceYes, with paperwork

The Dutch national top-up to Europe's privacy law. It imposes no storage location rule, sets the age of digital consent at sixteen, and leaves transfers to the European allowlist. An amendment act commences on 1 September 2026 with one part deliberately left uncommenced.

In force since 25 May 2018

Enforced by Dutch Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Cyberbeveiligingswet (Cbw)

Act of parliament · Act of 8 July 2026, Stb. 2026, 187; commenced by Article 35 of the Cyberbeveiligingsbesluit, Stb. 2026, 189

Partly in forceYes — store it anywhere

The Dutch implementation of Europe's cybersecurity directive. In force since 15 August 2026, it repeals the older Dutch network security law and adds a 24-hour early warning, a 72-hour report and a one-month final report. It imposes no storage location rule, but it does force non-EU digital infrastructure providers to appoint a European representative.

In force since 15 August 2026

Enforced by National Cyber Security Centre

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Wet op de ondernemingsraden, artikel 27, eerste lid, onder k en l

Act of parliament · Consolidated text in force from 18 February 2023

In forceYes — store it anywhere

A purely Dutch veto that sits outside privacy law. Before you deploy an HR system, access control, cameras, productivity monitoring or an employee-facing artificial intelligence tool, the works council has to agree. A decision taken without that consent can be voided.

In force since 1 April 1971

Enforced by Dutch Data Protection Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules5 rules

Besluit kansspelen op afstand, artikel 4.42, tweede lid

Directly binding regulation · Decree of 26 January 2021; consolidated text in force from 15 July 2022 · Online gaming

In forceNo — it stays put

The hardest data residency rule in Dutch law. An online gambling licensee must physically place its regulator-facing control database in the Netherlands, and may not place it anywhere the regulator's inspectors cannot reach immediately in person. There is no paperwork route around it.

In force since 1 April 2021But only enforceable from 1 October 2021

Enforced by Netherlands Gambling Authority

Transfer model: Not allowed

High confidence

Herziening rijksbreed cloudbeleid 2026

Government policy document · Policy of 3 July 2026, issued under the Coördinatiebesluit organisatie, bedrijfsvoering en informatiesystemen rijksdienst and the Besluit CIO-stelsel Rijksdienst 2026; tabled in Parliament as blg-1264434 · Government

In forceNo — it stays put

Central government's own cloud rule, tightened on 3 July 2026. All central government information must be stored and processed inside the European Economic Area and Switzerland, email and documents are pushed out of public cloud unless a minister signs off, and suppliers from countries with an active cyber programme against Dutch interests are excluded outright.

In force since 3 July 2026But only enforceable from 3 July 2030

Enforced by Chief Information Officer of Central Government

Transfer model: Not allowed

High confidence

Telecommunicatiewet, artikel 13.2a (Wet bewaarplicht telecommunicatiegegevens)

Act of parliament · Still printed in the consolidated Telecommunicatiewet as at 15 August 2026; suspended by Rechtbank Den Haag, 11 March 2015, ECLI:NL:RBDHA:2015:2498 · Telecoms

UnenforceableYes — store it anywhere

A retention duty that a text search of Dutch law would wrongly report as binding. The articles requiring twelve months of telephony data and six months of internet data are still printed in the Telecommunications Act, but the Hague District Court suspended the underlying act on 11 March 2015 and it has never been repealed or replaced.

In force since 1 September 2009

Enforced by Netherlands Authority for Digital Infrastructure

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • Autoriteit Persoonsgegevens

    General privacy law, cookies alongside the consumer and markets authority, coordination of algorithm and artificial intelligence supervision

    Fully staffed and highly active. Three-member board: Geert Potjewijd took office as chair on 1 August 2026 for a five-year term, succeeding Aleid Wolfsen; Monique Verdier is deputy chair and Katja Mur is a member. It issued a 290 million euro fine against Uber in August 2024 and a 100 million euro fine against MLU B.V., the operator of the Yango taxi app, in May 2026, both for unlawful transfers out of Europe. Its 2025 annual report, published 2 April 2026, sets out five focus areas: algorithms and artificial intelligence, freedom and security, big tech, data trading and digital government.

  • Nationaal Cyber Security Centrum

    Computer security incident response team under the Cyberbeveiligingswet; receives 24-hour early warnings and 72-hour incident reports

    Long-established, but its statutory role under the new cybersecurity law only started on 15 August 2026. A designation of supervisors and delegation of powers was published on 14 August 2026, so this enforcement track is still being assembled.

  • Rijksinspectie Digitale Infrastructuur

    Telecom networks, spectrum, digital infrastructure security and integrity

  • Autoriteit Consument & Markt

    Telecommunications Act enforcement including cookie and unsolicited communication rules

  • De Nederlandsche Bank

    Prudential supervision of banks, insurers, payment institutions and pension funds, including outsourcing and operational resilience

  • Autoriteit Financiële Markten

    Conduct supervision of securities markets and financial services

  • Kansspelautoriteit

    Online gambling licensing, including the control database that must sit in the Netherlands

  • Inspectie Gezondheidszorg en Jeugd

    Care providers, including the binding national information security and access-logging standards

  • CIO Rijk, Ministerie van Binnenlandse Zaken en Koninkrijksrelaties

    Government-wide cloud policy, including the requirement to keep all central government information inside the European Economic Area and Switzerland

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact original commencement dates of the Besluit kansspelen op afstand (recorded here as 1 April 2021, biting from 1 October 2021)

    We verified the current consolidated text, which is stated to be in force from 15 July 2022, and the underlying decree date of 26 January 2021, but we did not open the commencement decree. The substance of the localisation rule is verified from the statute text and is not in doubt; only the exact start dates are.

  • Whether any licence conditions, ministerial regulations or supervisory instructions impose data localisation in mapping and geospatial, education, or defence

    We searched the consolidated statute book and found no such rule as at 18 August 2026, but we did not review individual licences or the Ministry of Defence regime, which is expressly carved out of the government cloud policy and which we could not open.

  • Whether the Dutch Central Bank or the Authority for the Financial Markets has published guidance that goes beyond the statutory outsourcing rules on where financial data may be stored

    Both regulator websites returned an access-denied response to our fetches on 18 August 2026, so the finance rule is backed only by the statute text and is marked medium confidence.

  • Whether any supervisor has been formally designated and is operational for every sector under the Cyberbeveiligingswet

    A designation of supervisors and delegation of powers dated 14 August 2026 was published in the official gazette, but we did not open the full text to confirm which sectors it covers. The law itself started on 15 August 2026.

  • The precise retention periods for access logs to electronic patient records

    The decree makes the national logging standard binding and hands the retention period to representative sector bodies, which publish it separately in the official gazette. We did not locate those publications.

  • Whether a bill to replace the suspended telecom data retention regime is currently before Parliament

    We verified that the articles are still printed in the Telecommunications Act and that the court suspension of 11 March 2015 stands, but we did not exhaustively check the current legislative pipeline for a replacement.

30-day cadence. Three things are moving at once: the cybersecurity law commenced on 15 August 2026 and its registration, designation and supervision machinery is being built week by week; an amendment to the privacy implementation act commences on 1 September 2026 with one part held back; and the government cloud policy is ministerial policy that can be tightened without consultation. Anything slower than 30 days risks publishing a picture that is already out of date.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.