Law / Netherlands

Netherlands

European Union law applies in the Netherlands The Netherlands is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of the Netherlands, described on this page below, applies here too.

16 of 17 named instruments researched to a stage, across all six areas of law we track: 15 in force and 1 proposed. As of 12 September 2026.

When they take effect15 of 16 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 7 instruments (7 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 2 instruments (2 in force) 2022: 0 instruments 2023: 0 instruments 2024: 1 instrument (1 in force) 2025: 1 instrument (1 in force) 2026: 2 instruments (2 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 7
  3. Scraping law 3
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 1 in force, 1 proposed

Research summary (166 words)

The EU AI Act (Regulation (EU) 2024/1689) is directly applicable in the Netherlands and is not restated here; its Article 50 transparency and output-labeling duties, and the Digital Omnibus on AI's rescheduling of the Chapter III high-risk regime, are covered by the eu-level document.

The Netherlands has a criminal-law addition that predates and sits alongside the AI Act: Wetboek van Strafrecht art. 252 (renumbered from art. 240b by the Wet seksuele misdrijven, in force 1 July 2024, with the penalty raised to six years) bans producing, distributing, or possessing an image of a sexual act involving a person who is apparently, not only actually, under eighteen, which reaches a computer-generated or virtual depiction on its own terms.

As of September 2026 the Uitvoeringswet AI-verordening, the bill that would designate the ten national market-surveillance authorities responsible for enforcing the AI Act (led by the Autoriteit Persoonsgegevens and the Rijksinspectie Digitale Infrastructuur), remains a concept bill whose public consultation closed 1 June 2026; it has not been enacted.

AI governance

Uitvoeringswet AI-verordening (concept), National Enforcement of the EU AI Act

Uitvoeringswet verordening artificiele intelligentie (Uitvoeringswet AI-verordening, UAIV) conceptwetsvoorstel, internetconsultatie 20 april 2026 tot 1 juni 2026internetconsultatie.nl, Ministerie van Economische Zaken en Klimaat consultation page for the Uitvoeringswet AI-verordening

Proposed: draft date not recorded. A published draft that has not reached a legislature, dated 20 April 2026, as of 12 September 2026. Binds public and private bodies.

What this law does

Not yet in force. As published for consultation, the bill designates ten existing Dutch market-surveillance authorities as the competent authorities responsible for market surveillance and enforcement of the EU AI Act, gives them the accompanying powers and a duty to cooperate, and provides for the operators of AI systems in the Netherlands to fall under that supervision.

The public consultation ran from 20 April 2026 and closed 1 June 2026; as of the date below the bill has not been submitted to the Tweede Kamer.

What it requires

AI prohibited practices

Wetboek van Strafrecht, art. 252, Sexual Imagery of an Apparent Minor (Virtual Child Sexual Abuse Material)

Wetboek van Strafrecht, art. 252 (until 1 July 2024: art. 240b) (BWBR0001854)wetten.overheid.nl, consolidated text of the Wetboek van Strafrecht

In force since 1 July 2024. Binds public and private bodies.

What this law does

Whoever distributes, offers, publicly displays, produces, imports, transships, exports, acquires, possesses, or accesses a visual representation of a sexual act involving a person who apparently has not yet reached the age of eighteen, whether or not that person is actually involved, is punished with imprisonment of up to six years or a fine of the fifth category.

The provision does not require the depicted minor to be real, so it reaches a computer-generated or otherwise synthetic depiction on its own terms. Its predecessor, art. 240b, carried the same apparent-involvement wording with a four-year maximum before the Wet seksuele misdrijven renumbered and raised the penalty for the current text, effective 1 July 2024.

What it requires

Privacy law7 instruments, 7 in force

Research summary (94 words)

The Netherlands' private-sector personal-data regime is the General Data Protection Regulation (GDPR) as given domestic effect by the Uitvoeringswet Algemene verordening gegevensbescherming (UAVG, GDPR Implementation Act). Beyond restating the GDPR, UAVG adds a genuine national addition on biometric data (Article 29, an authentication-or-security exception to the Article 9 prohibition), plus derogations on health data, criminal-conviction data, the citizen service number, and journalistic or academic processing.

The Autoriteit Persoonsgegevens has taken a strict public position that scraping personal data is almost always unlawful, and the WAMCA collective-action regime is a live vehicle for a pending mass claim against TikTok.

Biometric privacy

UAVG Article 29, Biometric-Data Exception for Authentication or Security

UAVG, Art. 29wetten.overheid.nl, UAVG Art. 29 (verbatim, confirmed twice)

In force since 25 May 2018. Binds public and private bodies.

What this law does

UAVG Article 29 is a genuine Dutch national addition beyond the General Data Protection Regulation (GDPR) Article 9 baseline, confirmed verbatim: it exercises the GDPR Article 9(2)(g) substantial public-interest derogation to permit processing biometric data for unique identification specifically where necessary for authentication or security purposes.

The provision does not itself enumerate safeguards, a retention limit, or qualifying use cases beyond authentication or security, and no further AP guidance elaborating its boundaries was found. The exception applies equally to a voiceprint and a faceprint; UAVG Article 29's own text does not distinguish by modality, and no AP guidance specifically addressing voiceprint biometrics as distinct from facial biometrics was found.

What it requires

Breach notification

GDPR Articles 33-34 and UAVG Article 42, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34; UAVG, Art. 42GDPR Arts. 33-34

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the AP within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. UAVG Article 42 adds one national exception to the Article 34 individual-notification duty: it disapplies Article 34 for financial undertakings within the meaning of the Wet op het financieel toezicht (Financial Supervision Act).

Corrected during the #8352 wave 4 review: the article's full text is a single sentence stating exactly this exception, not merely confirmed by a table-of-contents heading.

What it requires

Comprehensive regime

Uitvoeringswet Algemene verordening gegevensbescherming (UAVG), GDPR Implementation Act

Wet van 16 mei 2018, houdende regels ter uitvoering van de Algemene verordening gegevensbescherming (BWBR0040940)wetten.overheid.nl, consolidated text (full table of contents and Art. 1)

In force since 25 May 2018. Binds public and private bodies.

What this law does

The Netherlands gives the General Data Protection Regulation (GDPR) domestic effect through the UAVG (GDPR Implementation Act, Wet van 16 mei 2018), in force since 25 May 2018 alongside the GDPR itself. UAVG Chapter 2 (Arts. 6-21a) establishes the Autoriteit Persoonsgegevens (AP) as supervisory authority, and Chapters 3-4 supply national derogations under GDPR Articles 6, 9, 10, and 23.

UAVG Article 1's definitions add only four defined terms and do not redefine any GDPR term including biometric data, so nothing in UAVG narrows a GDPR definition.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-49, 83(5)GDPR Arts. 44-49, 83(5)

In force since 25 May 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Netherlands-specific derogation from this framework was identified in the UAVG.

What it requires

Data subject rights

GDPR and UAVG Articles 40-43, Data-Subject Rights and Journalistic Exception

Regulation (EU) 2016/679, Arts. 12-23; UAVG, Arts. 40, 41, 43wetten.overheid.nl, UAVG Art. 43 (verbatim)

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12-23 apply directly: access, rectification, erasure, restriction, portability, objection, and Article 22 automated-decision rights. UAVG Article 40 gives GDPR Article 22 its own domestic exceptions (not to be confused with UAVG's own Article 22, the special-categories prohibition, a distinct provision under the same number).

UAVG Article 43, confirmed verbatim, is the significant national narrowing: for processing carried out exclusively for journalistic purposes or academic, artistic, or literary expression, most of GDPR Chapter III's data-subject rights and Chapters IV-VII do not apply, and Articles 9 and 10 are disapplied to the extent the processing serves those purposes.

What it requires

Enforcement supervision

AP Enforcement, GDPR Article 82 and the WAMCA Collective-Action Regime

Regulation (EU) 2016/679, Arts. 82-83; UAVG, Arts. 16-18; Wet Afwikkeling Massaschade in Collectieve Actie (WAMCA)GDPR Arts. 82-83

In force since 25 May 2018. Binds public and private bodies.

What this law does

The Autoriteit Persoonsgegevens (AP) is the Dutch supervisory authority, with General Data Protection Regulation (GDPR) Article 83 fines plus UAVG's own administrative powers including a fine specific to unlawful processing of criminal-conviction data (Art. 17) and administrative fines against government bodies (Art. 18).

GDPR Article 82 arms an individual with a direct private right of action, and the Netherlands' WAMCA collective-action regime is a live vehicle for privacy mass claims: a Consumentenbond and Stichting Take Back Your Privacy claim against TikTok, over unauthorized collection of children's personal data, is currently paused pending a Hoge Raad ruling in a related Oracle/Salesforce case expected 4 September 2026.

What it requires

Sensitive categories

UAVG Articles 30-33 and 46, Health, Criminal-Conviction, and National-ID-Number Data

UAVG, Arts. 30-33, 46wetten.overheid.nl, UAVG Arts. 1, 22, 24-31

In force since 25 May 2018. Binds public and private bodies.

What this law does

UAVG Chapter 3 Section 3.1 (Arts. 22-30) implements General Data Protection Regulation (GDPR) Article 9's special-category regime with article-by-article national exceptions: research and statistics, racial or ethnic origin, political opinions, religious or philosophical beliefs, and genetic data (Arts. 24-28), a health-data exception for administrative bodies, pension funds, and employers (Art. 30), and rules on criminal-conviction data (Art. 33, corrected during the #8352 wave 4 review from a mistyped Art. 31, which is a distinct provision on processing under governmental oversight).

Article 46 restricts processing of the citizen service number (BSN) to statutory or law-designated purposes; corrected during this review, its full text is in fact present and readable on the stored page, not truncated as previously stated. The AP's own scraping guidance (published 1 May 2024, as described in secondary commentary) states that publicly available information does not become lawfully processable merely because the source was public.

What it requires

Scraping law3 instruments, 3 in force

Research summary (274 words)

The Netherlands has no scraping-specific statute, so each dimension is governed by general law.

Computervredebreuk (Wetboek van Strafrecht art. 138ab) criminalizes intentionally and unlawfully breaking into an automated work, but breaking in requires defeating a security measure, a technical intervention, false signals or a false key, or assuming a false identity, so reading a public, unauthenticated page without any of those does not fit the provision on its plain text, and no case addressing that boundary has been located.

No reported Dutch decision on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper was located. The Auteurswet gives a text-and-data-miner a copyright exception at arts. 15n (research organizations and cultural heritage institutions, unconditional) and 15o (any miner with lawful access, subject to a rightsholder's machine-readable opt-out).

The Databankenwet gives a database producer a sui generis right against extraction or re-utilization of a substantial part of a database for fifteen years from completion, running from the year the database was first made available if that is earlier, and since 21 November 2025 that right does not reach data obtained from or generated by a connected product or related service within the meaning of Article 43 of the EU Data Act.

Scraping personal data of a person in the Netherlands is a privacy-topic finding, already researched (the Autoriteit Persoonsgegevens has taken the public position that scraping personal data is almost always unlawful under the General Data Protection Regulation (GDPR) and the Uitvoeringswet AVG) and is not restated here.

No Dutch-specific unfair-competition, misappropriation, or trespass doctrine, and no Dutch-specific rule assigning legal weight to robots.txt or governing AI training specifically, beyond the Auteurswet's own text-and-data-mining opt-out mechanism, was located.

Computer misuse

Wetboek van Strafrecht, art. 138ab, Computervredebreuk (Computer Trespass)

Wetboek van Strafrecht, art. 138ab (BWBR0001854)wetten.overheid.nl, consolidated text of the Wetboek van Strafrecht

In force since 15 May 2025. Binds public and private bodies.

What this law does

Whoever intentionally and unlawfully breaks into an automated work, or part of one, is punished with imprisonment of up to two years or a fine of the fourth category. Breaking in requires the access to have been obtained by breaching a security measure, a technical intervention, false signals or a false key, or assuming a false identity.

Copying, tapping, or recording data after that unauthorized access raises the maximum to four years, and doing so through a public telecommunications network for unlawful gain or to pivot to a third party's system also carries a four-year maximum. Because the offense turns on defeating one of the listed access methods, a scraper reading a public, unauthenticated page without doing so falls outside the provision's plain text.

What it requires

Copyright and text and data mining (TDM)

Auteurswet, artt. 15n and 15o, Text and Data Mining Exceptions

Auteurswet, artt. 15n, 15o (BWBR0001886)wetten.overheid.nl, consolidated text of the Auteurswet

In force since 7 June 2021. Binds public and private bodies.

What this law does

Article 15n exempts a reproduction that a research organization or cultural heritage institution makes for text-and-data-mining scientific research on a work to which it has lawful access, provided the reproduction is stored with an appropriate level of protection; a rightsholder may take proportionate security measures, and the exception cannot be contracted around.

Article 15o extends the exception to any miner with lawful access, but only where the rightsholder has not expressly reserved the right in an appropriate way, such as machine-readable means on a work made available online; a reproduction made under either article may be kept only as long as needed for the mining.

What it requires

Database right

Databankenwet, Sui Generis Database Right

Databankenwet (BWBR0010591)wetten.overheid.nl, consolidated text of the Databankenwet

In force since 21 July 1999. Binds public and private bodies.

What this law does

A database producer, defined as the person who bears the investment risk for the database, has the exclusive right to authorize extracting or re-utilizing the whole or a qualitatively or quantitatively substantial part of a database's contents, and to prevent the repeated and systematic extraction or re-utilization of insubstantial parts where that conflicts with the database's normal exploitation or unreasonably prejudices the producer's legitimate interests.

The right arises when the database's production is completed and lapses fifteen years after 1 January of the following year, or fifteen years from first being made available to the public if that happened earlier; a substantial new investment restarts the term. Circumventing an effective technical protection measure knowing or reasonably suspecting that is unlawful.

Since 21 November 2025, the right does not apply to data obtained from or generated by a connected product or related service within the meaning of Article 43 of Regulation (EU) 2023/2854 (the EU Data Act).

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (416 words)

The Netherlands completed its NIS2 transposition on time to take effect. The Cyberbeveiligingswet (Cbw), Wet van 8 juli 2026 houdende regels ter implementatie van Richtlijn (EU) 2022/2555 (Kamerstukken 36764, Staatsblad 2026, 189), passed the Tweede Kamer on 15 April 2026 and the Eerste Kamer on 7 July 2026, and entered into force on 15 August 2026 by royal decree (Staatsblad 2026, 187).

Its own Article 106 repeals the predecessor Wet beveiliging netwerk- en informatiesystemen (Wbni), which transposed the original NIS Directive (Directive (EU) 2016/1148); the consolidated register confirms the Wbni lapsed on 15 August 2026, so it is not still in force, unlike Ireland's and Spain's predecessor NIS1 regimes.

The Cbw binds an essential entity (Article 8, by operation of law, or Article 9, by criteria-based designation) and an important entity (Article 12 or Article 13) drawn from its Annexes 1 and 2, which restate the NIS2 Annex I and Annex II sector lists, to appropriate and proportionate risk-management measures over its network and information systems (Article 21, with the management board's approval and competency duty under Article 24) and to a graduated significant-incident notification clock to its CSIRT and competent authority: a 24-hour early warning (Article 26), a 72-hour notification (Article 27), an interim report on request (Article 28), and a final report within one month (Article 29).

Annex 2's own digital-provider entry names an online marketplace, an online search engine and a social-networking-services platform, supervised by the Minister of Economic Affairs; Annex 1's digital-infrastructure and ICT-service-management entries separately name a cloud-computing-service provider, a data-centre-service provider and a content-delivery-network provider, also supervised by that Minister.

The wider essential and important entity classes the Cbw designates by sector (energy, transport, banking, health, drinking water, public administration and the rest of the NIS2 Annexes) are a designation and sector class no activity in this vocabulary expresses, so only the digital-provider slice is flagged here.

No Dutch instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here; the Netherlands implements only the Cyber Resilience Act (CRA)'s own supervisory arrangements, assigning market surveillance to the Rijksinspectie Digitale Infrastructuur, rather than creating a further substantive duty.

The Netherlands has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and UAVG Article 42's breach-notification duties to the Autoriteit Persoonsgegevens, both of which sit in the privacy topic rather than here.

Sector security regimes

Cyberbeveiligingswet, Cybersecurity Risk-Management Measures and Governance

Cyberbeveiligingswet, Artt. 21 en 24Consolidated text, wetten.overheid.nl, Cyberbeveiligingswet, BWBR0052872, version in force from 15 August 2026

In force 39 days, effective 15 August 2026. Binds public and private bodies.

What this law does

Article 21 requires an essential entity or an important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems it uses for its work or to provide its services, and to prevent an incident or limit its effect on the recipients of its services and on other services, at a security level matched to the risk and covering, at minimum, risk analysis and information-system security policy, incident handling, business continuity and crisis management, supply-chain security, secure acquisition and development, effectiveness-assessment policy, cyber hygiene and training, cryptography policy, personnel and access-management security, and, where appropriate, multi-factor authentication (Article 21, paragraphs 1 to 3).

Article 24 requires the entity's management board to approve these measures and requires every board member to hold the knowledge and skills to identify network-and-information-system risks, assess cybersecurity risk-management measures, and assess their consequences for the entity's services, with a two-year transition period for a sitting member.

This Act, Wet van 8 juli 2026 (Cyberbeveiligingswet), transposes NIS2 Directive Articles 20 and 21 and, by its own Article 106, repeals the Wet beveiliging netwerk- en informatiesystemen (Wbni), the predecessor NIS1 transposition, which the consolidated register confirms lapsed on 15 August 2026, the date this Act took effect.

What it requires

Vulnerability and incident reporting

Cyberbeveiligingswet, Significant-Incident Reporting Obligations

Cyberbeveiligingswet, Artt. 25-29Consolidated text, wetten.overheid.nl, Cyberbeveiligingswet, BWBR0052872, version in force from 15 August 2026

In force 39 days, effective 15 August 2026. Binds public and private bodies.

What this law does

Article 25 requires an essential entity or an important entity to report every significant incident to its CSIRT and competent authority in accordance with Articles 26 to 29. Article 26 requires an early warning without delay, or within 24 hours of becoming aware of the incident if immediate reporting is not possible, stating whether the incident is suspected to result from unlawful or malicious action and whether it may have cross-border effects.

Article 27 requires a notification, without delay or within 72 hours, updating the early warning with an initial assessment of the incident's severity and effect. Article 28 requires an interim report on request.

Article 29 requires a final report no later than one month after the Article 27 notification, describing the incident, its severity and effects, the likely threat or root cause, mitigating measures taken, and, where relevant, cross-border effects; an incident still ongoing at that point is instead covered by a progress report, with the final report due within one month of the incident's resolution.

This Act transposes NIS2 Directive Article 23 and, by its own Article 106, repeals the Wet beveiliging netwerk- en informatiesystemen (Wbni), the predecessor NIS1 transposition, which lapsed on 15 August 2026, the date this Act took effect.

What it requires

Age gating law1 instrument, 1 in force

Research summary (156 words)

The Netherlands has no dedicated adult-content age-verification statute, no social-media minimum-age statute, and no app-store age-verification statute beyond the EU baseline (Digital Services Act Article 28 and the Audiovisual Media Services Directive, both already covered at the EU level).

The national addition is the Mediawet 2008's content-classification and access-restriction scheme: an audiovisual media provider may only offer content capable of harming the development of a person under sixteen if it is affiliated with a Minister-recognized classification organization, and the most harmful content, expressly including pornography, must be made technically inaccessible to persons under sixteen, under the oversight of the Commissariaat voor de Media.

Chapter 3a of the same Act separately requires a video-sharing platform provider established in the Netherlands to maintain a code of conduct implementing the measures referred to in the EU directive it transposes. A minor's digital-consent age under the General Data Protection Regulation (GDPR) and the Uitvoeringswet AVG is a privacy-topic finding and is not restated here.

Adult content age verification (AV)

Mediawet 2008, Chapter 4, Protection of Minors (Content Classification and Access Restriction)

Mediawet 2008, arts. 4.1, 4.1a (BWBR0025028)wetten.overheid.nl, consolidated text of the Mediawet 2008

In force since 1 January 2009.

What this law does

An audiovisual media provider may only offer content capable of harming the physical, mental, or moral development of a person under sixteen if the institution responsible for the content is affiliated with the organization the Minister has recognized under Article 4.2, and is bound by that organization's rules and supervision, per Article 4.1. Article 4.1a requires the most harmful content, expressly including pornography, to be made technically inaccessible to persons under sixteen.

It separately forbids the commercial processing of any personal data of minors collected under this scheme. The Commissariaat voor de Media supervises compliance with the classification scheme. A video-sharing platform provider established in the Netherlands carries a parallel code-of-conduct duty under Mediawet 2008 Chapter 3a.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (166 words)

The Netherlands transposed the EU Digital Single Market Copyright Directive's press-publisher neighbouring right into national law at Article 7b of the Wet op de naburige rechten (WNR), a separate act from the Auteurswet.

A Dutch press publisher holds the exclusive right to authorize the online reproduction and making-available of its press publications by an information-society-service provider, subject to exemptions for private or non-commercial use, hyperlinking, single words or very short fragments, and material whose own protection term has expired; a journalist whose work is carried in the publication is entitled to an appropriate share of the revenue the publisher earns from the right.

The Netherlands has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act. No hot-news or misappropriation doctrine specific to press content, distinct from general Dutch tort law, has been located. The general text-and-data-mining exception that also governs an aggregator's automated indexing (Auteurswet arts. 15n-15o) is researched under the scraping topic and is not restated here.

Press publishers' right

Wet op de naburige rechten, Article 7b, Press Publisher Online Right

Wet op de naburige rechten (WNR), art. 7b (BWBR0005921)wetten.overheid.nl, consolidated text of the Wet op de naburige rechten

In force since 7 June 2021. Binds private bodies.

What this law does

The publisher of a press publication has the exclusive right to authorize the online reproduction and the making available to the public of its press publication by an information-society-service provider, per Article 7b(1). The right does not reach private or non-commercial use by individual users, hyperlinking to a press publication, the use of single words or very short fragments, or the use of a work whose own protection term has expired, per Article 7b(2).

The right cannot be invoked against the author, performer, or producer whose own protected material is embedded in the press publication, per Article 7b(3). The author of a literary, scientific, or artistic work carried in a press publication is entitled to an appropriate share of the revenue the publisher receives for the work's use by an information-society-service provider, per Article 7b(5).

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.