Netherlands
Tier 2 Comprehensive law EuropePrincipal framework: GDPR + Implementation Act (UAVG) (2018). Regulator: AP. Strict medical-data rules; the BSN citizen number is restricted.
At a glance
- Public-sector fines
- Yes
- Principal law
- GDPR + Implementation Act (UAVG)
- Regulator
- Autoriteit Persoonsgegevens
- Breach notification
- 72 hours to the supervisory authority (Art 33); undue-delay notice to individuals at high risk
- Maximum penalty
- Up to €20m or 4% of global annual turnover
- DPO required
- Public authorities; large-scale regular monitoring or special-category processing (Art 37)
- Digital consent age
- 16
- Extraterritorial reach
- Yes — targeting or monitoring people in the EU (Art 3(2))
- National implementing act
- GDPR Implementation Act (UAVG)
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- NL
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- Yes
- EEA member
- Yes
- Holds EU adequacy
- Yes
EU/EEA member — intra-EEA transfers need no adequacy decision.
Instruments
Also applies here
Directly applicable as EU law, without national transposition. The national act supplements it rather than replacing it.
Sources
- Regulator Autoriteit Persoonsgegevens
- Primary Regulation (EU) 2016/679 (GDPR) EUR-Lex
Never independently verified — seeded from the prototype.