Business.gov.nl uses cookies to improve the website. These functional and analytical cookies do not contain your personal data. Do you want to watch video content? Third parties may place tracking cookies to track your online behaviour. You can refuse these tracking cookies. How cookies are used on Business.gov.nl.

How to comply with GDPR rules

Published by:
Netherlands Chamber of Commerce, KVK
5 min read
Nederlandse versie

The General Data Protection Regulation (GDPR) is the European privacy law for organisations that process personal data. The rules also apply to SME business owners and self-employed professionals. Do you, for example, process personal data for a newsletter, a price quotation, an invoice, or staff records? If so, use this checklist to make sure you are complying with the key GDPR obligations.

  1. You may not invent a reason yourself. The GDPR sets out 6 reasons that are considered valid grounds. These 4 are important for business owners:

    1. It is needed to carry out a contract

    For example, you need to process address details to deliver your product to someone. This reason also applies if no contract has yet been agreed, but you need personal data to enter into a contract. For example, when drawing up a price quotation.

    2. It is needed to comply with the law

    For example, you must report your staff’s salary levels to the Netherlands Tax Administration.

    3. You have consent

    There are several requirements that consent must meet. For instance, people must actively give their consent, based on clear information.

    4. It is needed for a legitimate interest

    This means there is a reason that takes precedence over protecting a person’s privacy. For example, you want to prevent fraud or protect yourself against theft. You must meet several conditions if you want to process personal data due to a legitimate interest.

    > Check if you have a good reason to process personal data (in Dutch)

  2. For example: To send out a newsletter, you do need an email address, but you do not need a date of birth.

    Privacy by default

    Do not process more personal data than needed in the default settings of your products or services. For example:

    • Do not allow an app to track a user’s location without a valid reason.
    • If you have newsletter sign-up options at the checkout of your online shop, do not tick these options by default.

    Are you designing new products or services? Then ensure that personal data is already properly protected from the design phase.

  3. For example: You have asked for an email address to send an invoice. In that case, you must not use that email address to send advertising to a customer.

  4. The GDPR does not set a fixed retention period. However, you must not keep personal data for longer than is necessary. The retention period depends on:

    • how long you need the data for your services
    • whether there are any statutory time limits you must comply with, such as the retention period for business records or the Public Records Act (Archiefwet)

    > Read more about storing personal data

  5. For example:

    • what data you store
    • why
    • for how long

    Write the privacy statement in plain language and make sure it is easy to find.

    > Find out how to draw up a privacy notice

    Also tell your clients what their rights are

    Your customers have many rights when it comes to privacy. You must ensure that they can easily exercise these rights. For example, your customers may:

    • view, modify, and delete their data
    • restrict and withdraw consent they have previously given
    • request their data in some situations so that they can easily switch to another business. This is called the right to data portability (in Dutch).

    Your customers may file a complaint with the Dutch Data Protection Authority (DPA). The DPA must process these complaints.

  6. For example:

    • Secure your website using secure protocols (HTTPS).
    • Install software updates.
    • Only send personal data to customers or other business contacts, for example, via a secure connection.

    > Read more tips on securing personal data (in Dutch)

  7. Examples of data leaks are:

    • You lose a laptop, tablet, USB stick, or document that includes unencrypted personal data.
    • You email personal data to the wrong person.
    • The personal data you are processing is stolen in a cyberattack.

    You must report all serious data breaches to the Dutch Data Protection Authority (DPA) within 72 hours. You must also document all data breaches, including internal leaks that you do not have to report.

    > Read more about preventing and reporting a data breach

  8. For example:

    • which personal data you process and why
    • who you share the data with
    • the date when you must delete the data. This is usually the end of the retention period

    This overview falls under the so-called accountability principle. You must always be able to explain how you handle data.

    > Read more about drawing up a processing register

  9. You may want to share personal data with another business. For example:

    • You work with an external call centre.
    • You use an agency for your business administration.

    You need consent from your customers to share their personal data with another business. Set this out in a customer agreement or contract that says what you will be sharing and why.

  10. Data Protection Impact Assessment

    Do you process data that carries a high privacy risk? If so, you must carry out a Data Protection Impact Assessment (DPIA). This is an extensive investigation to identify the risks of data processing. Based on this DPIA, you can take measures to reduce the privacy risks.

    Carry out a Data Protection Impact Assessment (DPIA)

    Data protection officer

    Does your company process special categories of personal data? Or personal data on a large scale for a longer period? If so, check whether you are required to appoint a data protection officer (DPO). This is someone who monitors whether you are doing everything according to the GDPR within your organisation. Your organisation may also voluntarily appoint a DPO.

    Read when appointing a data protection officer is mandatory

Who must follow the GDPR rules?

The GDPR applies to all businesses and organisations that process personal data, including freelancers and SME entrepreneurs. Personal data is information that allows you to identify a person. For example:

  • name
  • address
  • telephone number

Processing includes everything an organisation can do with data. Think of collecting, storing, and forwarding it.

This means you will often be affected by the GDPR. For example, if you:

  • send a newsletter
  • send a price quotation
  • hire staff
  • send an invoice
  • have a contact form on your website

> Read more about personal data and how you protect it

Personal data and staff

The GDPR also applies when you recruit staff. For example, in the following situations:

  • job applications
  • background checks
  • processing of staff data

Find out what you need to keep in mind when recruiting staff (in Dutch).

What is the significance of the GDPR?

The GDPR is a European law designed to protect people’s privacy. The GDPR sets out what businesses and organisations are and are not permitted to do with the personal data of their customers, staff, and other individuals. In Dutch, the GDPR is known as AVG or Algemene Verordening Gegevensbescherming.

How would you rate this page?(question 1 of max 3)
We are sorry to hear that. How can we improve?(question 2 of 3)

Questions relating to this article?

Please contact the Netherlands Chamber of Commerce, KVK