Skip to main content
๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands ยท GDPR + UAVG

Netherlands Data Removal Guide (2026)

Dutch residents have GDPR rights under the UAVG, supervised by the Autoriteit Persoonsgegevens. A practical issue is the KvK trade register publishing business information, including some sole proprietors' visiting addresses; current shielding eligibility and procedure depend on the register rules.

Research status: sources last checked 2026-09-07.

This page is educational orientation, not legal advice. The legal fields below are a research snapshot; eligibility, exemptions, deadlines, penalty rules and broker routes can change. Verify the current statute and regulator guidance before relying on a right or filing a complaint.

At a glance

Governing law
GDPR + UAVG
Response deadline
1 month (extendable by 2 months for complex requests)
Regulator
Autoriteit Persoonsgegevens (AP)
Private right of action
Yes: compensation under Article 82; collective actions under WAMCA

GDPR + Uitvoeringswet AVG (UAVG)

The Netherlands applies the GDPR plus the UAVG implementation act, which includes national rules such as digital-consent and BSN provisions. You have GDPR rights, including an absolute right to object to direct marketing, with the Article 12 response framework. The AP supervises compliance, while the applicable route and any collective-redress option depend on the facts and current Dutch procedure.

Read the full GDPR + UAVGexplainer โ†’Scope, penalties, private right of action, enforcement history.

What rights do Netherlands residents have?

  • โ†’Right of access (Article 15)
  • โ†’Right to erasure / right to be forgotten (Article 17)
  • โ†’Right to object: absolute for direct marketing (Article 21)
  • โ†’Right to rectification and restriction (Articles 16, 18)
  • โ†’Right to shield a KvK visiting address and request BRP confidentiality (geheimhouding)
  • โ†’Right to lodge a complaint with the Autoriteit Persoonsgegevens (Article 77)

Who holds your data in Netherlands?

One notable Dutch exposure is the KvK (Chamber of Commerce) trade register, which publishes business information and may include a sole proprietor's visiting address. Phone/address directories and marketing brokers also operate; current disclosure, objection, and telemarketing rules depend on the provider and activity. US/global people-search sites may surface some Dutch data.

Public-record sources brokers scrape

  • KvK Handelsregister: company + sole-trader data and addresses (shieldable; see steps)
  • BRP (Basisregistratie Personen): municipal residents' database (cannot opt out, but can request confidentiality)
  • Kadaster: land registry, property ownership (paid lookup)
  • Court records

Related guide: How to Shield Your Home Address on the KvK

How to remove your data in Netherlands

  1. 1Ask the KvK about shielding your visiting address ("afschermen"): eligibility and evidence requirements depend on the registrant, address, and current Business Register rules, and a separate public postal address may be required.
  2. 2Request BRP "geheimhouding" (confidentiality) at your municipality (gemeente) to block sharing with non-obligated third parties.
  3. 3Send GDPR objection (Art. 21) + erasure (Art. 17) requests to brokers and directories.
  4. 4Since 1 July 2026, telemarketing to consumers and small businesses generally requires explicit prior consent, subject to limited exceptions; use the current ACM rules and report calls that do not qualify.
  5. 5File a complaint with the Autoriteit Persoonsgegevens if requests are ignored.

Generate requests in under 60 seconds

Generate requests for 1,034 US/global broker workflows for $9

Some Netherlands residents may encounter US-based people-search providers. OfflistMe can prepare source-aware deletion-request drafts for selected recorded workflows; you review the route and applicable law, then send from your own inbox. No account or ID upload to OfflistMe is required for drafting. Pair it with the Netherlands-specific steps above.

What if a company ignores your request?

Consider the Autoriteit Persoonsgegevens (AP) information or complaint route above if the controller does not respond or the response is unsatisfactory. This guide records the following penalty orientation: โ‚ฌ20M or 4% of global annual turnover. The private-action note is: Yes: compensation under Article 82; collective actions under WAMCA. Neither field is an individual award or a promise of enforcement.

Open the Autoriteit Persoonsgegevens (AP) information or complaint route โ†—

FAQ: Netherlands data removal

Who enforces privacy in the Netherlands?+

The Autoriteit Persoonsgegevens (AP), the Dutch Data Protection Authority, which enforces both the GDPR and the national UAVG implementation act.

My home address is public on the KvK: can I hide it?+

Possibly. KvK shielding eligibility and evidence requirements depend on the registrant, address, and current Business Register rules; a separate public postal address may be required. Shielding at the KvK does not remove data already copied by online brokers, so review those providers separately.

Can I opt out of the BRP residents' database?+

No: your municipality is legally required to register you. But you can request "geheimhouding" (confidentiality) so your data is not shared with certain third parties such as churches and non-government organisations.

Is telemarketing allowed in the Netherlands?+

Since 1 July 2026, businesses generally need explicit prior consent to call consumers and small businesses. ACM lists limited exceptions for specified charities, lotteries that donate to charities, and publishers; those exceptions can include calls to their current or former customers. Use the current ACM guidance and right-of-objection route.

Related resources

Other country guides