AVG in the Netherlands: the Uitvoeringswet AVG and the Autoriteit Persoonsgegevens

AVG stands for Algemene verordening gegevensbescherming, the Dutch name for the General Data Protection Regulation. It is an EU regulation, so it applies in the Netherlands directly and in the same words as in every other Member State. What differs from one country to the next is the national layer built on top of it.
In the Netherlands that layer has two parts: the Uitvoeringswet AVG (UAVG), the Dutch implementing act, and the supervisory authority it constitutes, the Autoriteit Persoonsgegevens (AP). This page is about that layer. It covers the choices the Netherlands made where the regulation left room, what the AP can and cannot do, and the Dutch procedural routes open to a person here.
For the regulation's own general obligations, see what the GDPR is and data subject rights under the GDPR, and for a shorter country summary written as part of the worldwide privacy survey see the Netherlands data privacy entry. Where this section sits in the wider Dutch legal map is set out on privacy law in the Netherlands.
Four Dutch words carry most of what follows. A verwerkingsverantwoordelijke is the controller, the organisation that decides why and how personal data are processed. A betrokkene is the data subject, the person the data are about. A grondslag is the lawful basis a controller needs before it processes anything, and a datalek is a personal data breach.
Information last verified on 21 July 2026. This page provides general legal information about Netherlands law and does not constitute legal advice in an individual case.
What the Uitvoeringswet AVG does that the AVG does not
The UAVG is short by the standards of Dutch legislation because it deliberately does not repeat the regulation. It does four things: it constitutes the Autoriteit Persoonsgegevens, it exercises the derogations the AVG left open to Member States, it builds the Dutch legal-protection route against a controller, and it carves out journalistic, academic, artistic and literary expression.
The consolidated text has been in force since 1 July 2021. Several of its articles carry a note that amendments have been passed without a commencement date. Those are not yet law and the account below is the law as it currently stands.
Criminal-conviction data is a closed list
This is the largest and most distinctive Dutch derogation, and it runs on artikel 10 AVG. Artikel 31 UAVG provides that gegevens van strafrechtelijke aard, data relating to criminal convictions and offences, may be processed only to the extent artikelen 32 and 33 allow it. The structure is a prohibition with an exhaustive list of exits, not a balancing test.
Artikel 32 permits processing on explicit consent, to protect vital interests, where the betrokkene has manifestly made the data public, for the establishment, exercise or defence of a legal claim or by courts acting judicially, on a substantial public interest ground, and for research or statistics with the safeguards in artikel 24 UAVG.
Artikel 33 adds the exits that matter in practice. Lid 2 onder b lets a controller process criminal data to protect its own interests, so far as the offences were committed, or on the facts are expected to be committed, against it or against people in its service. Lid 3 provides that criminal data about the controller's own personnel may be processed only under rules adopted through the procedure in the Wet op de ondernemingsraden, and lid 4 opens processing for third parties to holders of a licence under the Wet particuliere beveiligingsorganisaties en recherchebureaus, to processing within a group as defined in artikel 2:24b BW, and to a controller holding a vergunning granted by the AP. That last exit is itself conditioned: under lid 5 the AP may grant such a vergunning only where the processing is necessary in view of a substantial interest of third parties (een zwaarwegend belang van derden) and safeguards are in place so that the private life of the betrokkene is not disproportionately harmed.
Artikel 17 UAVG then puts a breach of artikel 10 AVG or artikel 31 UAVG in the top fine tier, at EUR 20,000,000 or 4 percent of total worldwide annual turnover in the preceding financial year, whichever is higher.
The age threshold, and what the Netherlands actually chose
Artikel 8 lid 1 AVG sets the age for a child's own consent to an information society service at 16 and lets a Member State legislate a lower age, but not below 13. The Netherlands took no lower age, so 16 is the figure here. The Dutch addition points in the other direction.
Artikel 5 lid 1 UAVG provides that where artikel 8 AVG does not apply, the consent of the legal representative is required instead of the betrokkene's own consent if the betrokkene has not yet reached 16. That extends the same threshold to consent situations outside the artikel 8 scenario. Artikel 5 lid 4 adds that the hoofdstuk III rights of an under-16, and of a person under curatele, bewind or mentorschap, are exercised by the legal representative.
There is one carve-out. Artikel 5 lid 5 excludes help and advice services offered directly and free of charge to a minor or to a person placed under curatele, so a young person can use a confidential helpline without a parent consenting first.
A restriction of a different kind sits a few articles further on. Artikel 46 lid 1 UAVG provides that a number prescribed by law for the identification of a person may be used in processing only to give effect to that law, or for purposes laid down by law, with further cases open to designation by algemene maatregel van bestuur. It is written in general terms and names no particular number, so it covers whatever identifier a statute prescribes.
Journalism, academic, artistic and literary expression
Artikel 43 UAVG is unusually wide and it is the provision most often missed. Lid 1 disapplies the whole UAVG, apart from artikelen 1 tot en met 4 and artikel 5 leden 1 en 2, to processing for exclusively journalistic purposes and for exclusively academic, artistic or literary expression. Lid 2 then disapplies, for those same purposes, artikel 7 lid 3 and artikel 11 lid 2 AVG, the whole of hoofdstuk III, hoofdstuk IV apart from artikelen 24, 25, 28, 29 en 32, and hoofdstukken V, VI en VII, and lid 3 disapplies artikelen 9 en 10 AVG so far as necessary for the purpose.
The consequence is concrete. Hoofdstuk III is the chapter containing the data-subject rights, so there is no artikel 17 erasure right against processing that is exclusively journalistic, and hoofdstuk VI is the chapter on independent supervisory authorities. The route against a publication is therefore the civil court, under artikel 6:162 BW and, where a portrait is involved, portretrecht in artikel 21 Auteurswet. Whether a given publication is exclusively journalistic is a question for the court, not a label the publisher applies to itself.
Research, archives and one financial-sector carve-out
Artikel 24 UAVG lifts the artikel 9 lid 1 prohibition on special-category data for scientific or historical research and statistics, but only where the research serves a general interest, asking for explicit consent proves impossible or would take a disproportionate effort, and safeguards ensure the betrokkene's private life is not disproportionately harmed. Those conditions apply together, not in the alternative. Artikel 44 lets a research or statistics institution that has secured the data against any other use set aside artikelen 15, 16 en 18 AVG, and artikel 45 replaces the ordinary access and correction rights for archives held under the Archiefwet 1995 with a targeted access right and a right to add the betrokkene's own version to the record.
Artikel 42 is short and easy to miss: artikel 34 AVG does not apply to financiële ondernemingen as defined in the Wet op het financieel toezicht. That switches off the duty to communicate a breach to the people affected for that sector. It leaves the artikel 33 duty to notify the AP within 72 hours completely untouched.
The Autoriteit Persoonsgegevens: how it is built and what it can do
Artikel 6 lid 1 UAVG states that there is an Autoriteit Persoonsgegevens and that it has legal personality. Lid 2 designates it as the supervisory authority referred to in artikel 51 lid 1 AVG. That provision does the designating and nothing more; the powers sit further on.
Artikel 7 sets the composition: a chair and two other members, appointed by royal decree (koninklijk besluit) for five years and eligible for reappointment once. Under artikel 7 lid 4 the chair must meet the requirements for appointment as a judge in a district court (rechtbank), which is a deliberate marker of independence.
| Power | Where it sits | What it means |
|---|---|---|
| All supervisory tasks and powers under the AVG | artikel 14 lid 1 UAVG | the AP may carry out every task and exercise every power the regulation gives a supervisory authority |
| Administrative fine | artikel 14 lid 3 UAVG | up to the amounts in artikel 83 leden 4, 5 en 6 AVG |
| Fine for criminal-data breaches | artikel 17 UAVG | EUR 20,000,000 or 4 percent of worldwide annual turnover, whichever is higher |
| Fine against a public body | artikel 18 UAVG | the same ceilings applied to an overheidsinstantie or overheidsorgaan |
| Last onder bestuursdwang and dwangsom | artikel 16 UAVG | an enforcement order, backed by a penalty payment that accrues to the State |
| Inspection, including entering a home | artikel 15 leden 2 en 3 UAVG | designated persons may enter a home without the occupant's consent, but only on an express and special authorisation from the AP and subject to the Algemene wet op het binnentreden |
| No professional-secrecy shield | artikel 15 lid 4 UAVG | secrecy cannot be invoked as to a person's own involvement in the processing |
| Fine suspended while challenged | artikel 38 UAVG | the fine decision does not take effect until the period for an administrative objection (bezwaar) or an appeal to the administrative court (beroep) lapses, or until the challenge is decided |
Two smaller points round the picture out. Artikel 14 lid 4 applies the punitive-sanction safeguards in artikelen 5:4 tot en met 5:10a van de Algemene wet bestuursrecht to the corrective measures in artikel 58 lid 2 onderdelen b tot en met j AVG. Artikel 14 lid 6, artikel 17 lid 3 and artikel 18 lid 3 all provide that the fine accrues to the State.
The enforcement ladder in practice
A fine is the last rung, not the first. On its own account of how it handles complaints, updated 18 April 2025, the AP works through an invitation to a conversation, a berisping (a formal reprimand), verscherpt toezicht (intensified supervision), a last onder dwangsom or a last without one, a verwerkingsverbod (an order banning the processing), and only then a boete.
Behind that ladder is the closed list of corrective powers in artikel 58 lid 2 AVG, running from a warning and a reprimand through orders to comply with a betrokkene's request, to bring processing into line, to communicate a breach or to rectify, erase or restrict, to a temporary or definitive limitation including a ban, an administrative fine, and suspension of data flows to a third country.
Reading the fine ceilings
Artikel 83 lid 4 AVG sets the lower tier at EUR 10,000,000 or 2 percent of total worldwide annual turnover in the preceding financial year. Artikel 83 lid 5 sets the higher tier at EUR 20,000,000 or 4 percent, and artikel 83 lid 6 puts non-compliance with an order under artikel 58 lid 2 at that same higher level. Artikel 83 lid 3 caps the total where several provisions are breached in one or linked processing operations at the amount for the gravest breach.
Two points decide how those figures work out. For an undertaking the applicable ceiling is whichever of the fixed amount and the percentage is higher, so the percentage matters only once turnover is large enough to beat the fixed figure. Take an undertaking with EUR 400,000,000 of worldwide turnover in the preceding year: 4 percent is EUR 16,000,000, which is below EUR 20,000,000, so the higher-tier ceiling stays at EUR 20,000,000. At EUR 900,000,000 of turnover the lower tier flips the other way: 2 percent is EUR 18,000,000, well above EUR 10,000,000, so that is the ceiling.
These are ceilings on the maximum, not the fine itself. They are fixed by the regulation and have not moved since it came into application, so any figure presented as this year's indexed AVG maximum is wrong on its face. Where an undertaking is fined, the AP calculates using the EDPB fining guidelines; for government bodies and for natural persons not acting as an undertaking it applies its own Boetebeleidsregels Autoriteit Persoonsgegevens 2023. The CJIB collects, and the money goes to the treasury.
The Autoriteit Persoonsgegevens supervises and enforces, but it does not award damages to an individual. Compensation for a privacy breach is a civil claim under artikel 6:162 BW, brought before the civil court and decided on its own evidence.
Filing with the AP is free, but it expects a person to have contacted the organisation first and will not handle a complaint where that has not happened, and a complaint discloses the complainant's identity to the organisation it concerns. The choice between an anonymous tip, a named klacht and a datalektip, together with the AP's own timelines, is set out on making a complaint to the Autoriteit Persoonsgegevens.
The six grondslagen in artikel 6 lid 1 AVG
Processing is lawful only so far as at least one of six bases applies. There is no hierarchy between them, but there is no seventh option either, and a controller cannot fall back on the idea that it means no harm.
| Basis | What it covers | |
|---|---|---|
| a | toestemming | consent given by the betrokkene for one or more specific purposes |
| b | uitvoering van een overeenkomst | necessary to perform a contract the betrokkene is party to, or to take steps at their request before entering one |
| c | wettelijke verplichting | necessary to comply with a legal obligation on the controller |
| d | vitale belangen | necessary to protect the vital interests of the betrokkene or another natural person |
| e | taak van algemeen belang | necessary for a task in the public interest or in the exercise of official authority |
| f | gerechtvaardigd belang | necessary for the legitimate interests of the controller or a third party, unless the betrokkene's interests or fundamental rights override them, particularly where the betrokkene is a child |
The closing sentence of artikel 6 lid 1 matters as much as the list: onderdeel f does not apply to processing carried out by public authorities in the performance of their tasks. A gemeente cannot reach for gerechtvaardigd belang to justify its own official activity, and has to rely on the public-task basis in onderdeel e together with the statutory task that confers it.
Artikel 4 lid 2 AVG counts collection and recording as processing, so the AVG engages when the recording is made rather than when it is shared. What removes most private recordings is not the absence of publication but the exemption in artikel 2 lid 2 onder c AVG for a purely personal or household activity. Where and how a home camera loses that exemption, and the gerechtvaardigd belang test it then has to satisfy, is covered on cameras at a neighbour's house; a drone with a camera raises the same data protection question alongside the separate aviation rules, and is covered on drone rules in the Netherlands.
Data protection is not the only regime in play when someone records. The criminal provisions on covert recording and covert images sit in the Wetboek van Strafrecht and run on their own tests, which are set out on recording conversations in the Netherlands.
What a betrokkene can ask for, and how long an organisation has
Artikelen 15 tot en met 22 AVG give the betrokkene the recht van inzage (access, artikel 15), rectificatie (artikel 16), gegevenswissing (erasure, artikel 17), beperking van de verwerking (restriction, artikel 18), dataportabiliteit (artikel 20), the recht van bezwaar (objection, artikel 21) and the right not to be subject to a decision based solely on automated processing including profiling (artikel 22). Artikel 19 obliges the controller to pass a rectification, erasure or restriction on to the recipients it disclosed the data to.
Dataportabiliteit is narrower than the others. It applies only where the processing rests on consent or on a contract and is carried out by automated means, so it does not reach a paper file or processing based on a legal obligation. Artikel 22 also has a Dutch overlay: artikel 40 UAVG disapplies the prohibition on solely automated decisions where the decision, other than one based on profiling, is necessary to comply with a legal obligation or to perform a public-interest task, and where the controller is not a bestuursorgaan the safeguards must include human intervention and the rights to state a position and to contest the decision.
Artikel 12 lid 3 AVG sets the timetable. The controller informs the betrokkene without delay and in any event within one month of receiving a request under artikelen 15 tot en met 22, and that period may where necessary be extended by two further months depending on the complexity and the number of requests, with the extension notified within the first month.
Take an access request (inzageverzoek) received on 3 March. The answer is due by 3 April, and if the controller wants the extension it has to say so by 3 April as well, which moves the outside date to 3 June. An extension announced in May is not an extension.
Responding is free under artikel 12 lid 5, and a controller may charge a reasonable fee or refuse only where the request is manifestly unfounded or excessive, in particular because it is repetitive, which it has to demonstrate itself. Under artikel 12 lid 4, a controller that does not act must say why within one month and point the person to the supervisory authority and to a judicial remedy.
The Dutch procedural layer on top
Artikel 34 UAVG provides that a written decision on a request under artikelen 15 tot en met 22 is taken within the artikel 12 lid 3 periods, and that where it is taken by a government body (bestuursorgaan) it counts as a formal decision (besluit) under the Algemene wet bestuursrecht. Against a government body, then, the route is an internal objection (bezwaar) and after that an appeal to the administrative court (beroep bij de bestuursrechter).
Against anything that is not a bestuursorgaan, the Netherlands provides a distinct and quicker route, by application to a court (verzoekschrift). Where a company refuses an access request, artikel 35 van de Uitvoeringswet AVG allows a verzoekschrift to the rechtbank within six weeks, without an advocaat. Artikel 35 lid 2 adds a detail that works in the requester's favour: where the controller did not answer within the artikel 12 lid 3 periods at all, the verzoekschrift is subject to no time limit.
Artikel 36 UAVG offers a middle step. Within the same period the person may instead ask the AP to mediate or advise, or use a dispute-resolution mechanism under an approved gedragscode, and the clock for beroep or for the artikel 35 verzoekschrift then runs again for six weeks from the notice that the matter has been closed.
Reporting a datalek: the 72-hour rule
Artikel 33 lid 1 AVG requires the verwerkingsverantwoordelijke to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Three things in that sentence are routinely misread.
The clock runs from awareness, not from the incident, which can be weeks earlier. There is a risk threshold, so not every breach is notifiable. And a notification after 72 hours is not barred; it must be accompanied by reasons for the delay.
The rest of artikel 33 fills in the mechanics. A processor must inform the controller without undue delay, lid 3 sets the minimum content of a notification, and lid 4 allows the information to be supplied in phases where it is not all available at once. Lid 5 requires the controller to document every breach, including those it decides not to report, so the AP can verify that the assessment was actually made.
Telling the people affected is a separate duty with a higher threshold. Artikel 34 lid 1 applies where the breach is likely to result in a high risk to the rights and freedoms of natural persons, as against the plain risk that triggers notification to the AP. Artikel 34 lid 3 gives three exceptions: appropriate protection was in place and applied to the affected data, in particular measures such as encryption rendering them unintelligible; the controller has since taken measures making the high risk unlikely to materialise; or communication would involve disproportionate effort, in which case there must be a public communication that informs the people affected equally effectively.
Those exceptions are not self-certifying: under artikel 34 lid 4 the AP may require the communication to be made anyway, or decide that an exception does apply. The Dutch overlay is artikel 42 UAVG, which disapplies artikel 34 to financiële ondernemingen within the meaning of the Wet op het financieel toezicht, while the 72-hour notification to the AP under artikel 33 remains in place for them in full. The general shape of the EU rule is set out on the GDPR 72-hour breach notification rule.
Frequently Asked Questions
What does AVG stand for, and is it the same as the GDPR?
AVG stands for Algemene verordening gegevensbescherming. It is the Dutch name for the same instrument that is called the General Data Protection Regulation in English, Regulation (EU) 2016/679. There is no separate Dutch data protection code with different rules in it. The Dutch additions sit in the Uitvoeringswet AVG (UAVG), which fills in the points the regulation deliberately left to each Member State and sets up the Autoriteit Persoonsgegevens as the supervisory authority.
How long does an organisation have to answer an inzageverzoek?
Artikel 12 lid 3 AVG gives the controller one month from receipt of the request to say what it has done with it, and artikel 34 UAVG applies the same period to a written decision on a request under artikelen 15 tot en met 22. The month can be extended by two further months where the request is complex or where a large number of requests has come in, but the controller has to notify that extension inside the first month. Answering is free. Only where a request is manifestly unfounded or excessive, in particular because it is repetitive, may a controller charge a reasonable fee or refuse, and artikel 12 lid 5 puts the burden of showing that on the controller.
How high can an AVG fine be in the Netherlands?
Artikel 83 AVG sets two tiers and artikel 14 lid 3 UAVG lets the AP impose fines up to those amounts. The lower tier is EUR 10,000,000 or 2 percent of total worldwide annual turnover in the preceding financial year, and the higher tier is EUR 20,000,000 or 4 percent. Where an undertaking is involved the ceiling is whichever of the two amounts is higher, never the lower one and never a choice. These are ceilings on the maximum, not the fine, and the figures are fixed by the regulation rather than indexed each year.
Can the Autoriteit Persoonsgegevens make an organisation pay me compensation?
No. The Autoriteit Persoonsgegevens supervises and enforces, but it does not award damages to an individual. Compensation for a privacy breach is a civil claim under artikel 6:162 BW, brought before the civil court and decided on its own evidence. The corrective powers listed in artikel 58 lid 2 AVG run from a warning to a processing ban and a fine, and none of them is compensation. A fine the AP imposes accrues to the State under artikel 14 lid 6, artikel 17 lid 3 and artikel 18 lid 3 UAVG.
What can I do if a company ignores my access request?
Where a company refuses an access request, artikel 35 van de Uitvoeringswet AVG allows a verzoekschrift to the rechtbank within six weeks, without an advocaat. If the company never answered within the artikel 12 lid 3 periods, artikel 35 lid 2 attaches no time limit at all. Where the organisation is a government body the route is different: artikel 34 UAVG makes its decision a besluit under the Algemene wet bestuursrecht, so the route is bezwaar and then beroep to the bestuursrechter.
When does a data breach have to be reported to the Autoriteit Persoonsgegevens?
Artikel 33 lid 1 AVG requires the controller to notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The clock runs from awareness, not from the incident itself. A notification made after 72 hours has to be accompanied by reasons for the delay. Artikel 33 lid 5 also requires the controller to document every breach, including the ones it decides not to notify.
Do the people affected by a datalek have to be told as well?
Only where the threshold is higher. Artikel 34 lid 1 AVG requires communication to the betrokkene where the breach is likely to result in a high risk to the rights and freedoms of natural persons, which is a higher bar than the risk that triggers notification to the AP. Artikel 34 lid 3 sets out three exceptions, including where the affected data were protected by measures such as encryption that render them unintelligible to unauthorised persons. Artikel 42 UAVG switches the artikel 34 duty off altogether for financiële ondernemingen under the Wet op het financieel toezicht, while leaving the 72-hour duty to notify the AP fully in place.
Does the AVG apply to a private person filming at home?
Artikel 4 lid 2 AVG counts collection and recording as processing, so the AVG engages when the recording is made rather than when it is shared. What removes most private recordings is not the absence of publication but the exemption in artikel 2 lid 2 onder c AVG for a purely personal or household activity. Where a camera reaches past the owner's own property the exemption stops applying and the AVG governs the camera, which is a different thing from the camera being unlawful.
Sources and References
- Artikel 6 Uitvoeringswet AVG, instelling en aanwijzing van de Autoriteit persoonsgegevens(wetten.overheid.nl).gov
- Artikel 7 Uitvoeringswet AVG, samenstelling en benoeming van de Autoriteit persoonsgegevens(wetten.overheid.nl).gov
- Artikel 14 Uitvoeringswet AVG, taken en bevoegdheden, met de boetebevoegdheid in het derde lid(wetten.overheid.nl).gov
- Artikelen 15 tot en met 18 Uitvoeringswet AVG, toezicht op de naleving, last onder bestuursdwang en bestuurlijke boetes(wetten.overheid.nl).gov
- Artikelen 31 tot en met 33 Uitvoeringswet AVG, verwerking van persoonsgegevens van strafrechtelijke aard(wetten.overheid.nl).gov
- Artikelen 34 tot en met 36 Uitvoeringswet AVG, rechtsbescherming bij een verzoek van de betrokkene(wetten.overheid.nl).gov
- Artikel 5 Uitvoeringswet AVG, toestemming van de wettelijk vertegenwoordiger beneden zestien jaar(wetten.overheid.nl).gov
- Artikelen 40 tot en met 43 Uitvoeringswet AVG, uitzonderingen en beperkingen, waaronder journalistieke doeleinden en financiële ondernemingen(wetten.overheid.nl).gov
- Artikel 46 Uitvoeringswet AVG, gebruik van een bij wet voorgeschreven identificatienummer(wetten.overheid.nl).gov
- Verordening (EU) 2016/679 (AVG), artikelen 2, 4, 6 en 12 (toepassingsgebied, verwerking, grondslagen en termijnen), artikelen 15 tot en met 22 (rechten van de betrokkene), artikelen 33 en 34 (melding van een inbreuk in verband met persoonsgegevens) en artikelen 58 en 83 (corrigerende bevoegdheden en de voorwaarden voor bestuurlijke boetes)(eur-lex.europa.eu).gov
- Artikel 24 Uitvoeringswet AVG, uitzondering voor wetenschappelijk of historisch onderzoek en statistiek, met de cumulatieve waarborgen(wetten.overheid.nl).gov
- Artikel 21 Auteurswet, portretrecht(wetten.overheid.nl).gov
- Artikel 6:162 BW, onrechtmatige daad(wetten.overheid.nl).gov
- Autoriteit Persoonsgegevens, Boetes en andere sancties van de AP(autoriteitpersoonsgegevens.nl).gov