What Is UAVG? GDPR + Uitvoeringswet Algemene verordening gegevensbescherming (GDPR Implementation Act)
The Netherlands applies the EU GDPR together with the Uitvoeringswet AVG (UAVG), the national implementation act that clarifies how GDPR applies locally and uses opening clauses for Dutch-specific rules, including the age of digital consent and rules on the BSN national-ID number. The supervisory authority is the Autoriteit Persoonsgegevens (AP). The KvK (Kamer van Koophandel / Chamber of Commerce) trade register is a practical exposure layer. Businesses register in the Handelsregister, and for sole proprietorships (eenmanszaken) the visiting address may be a home address. The KVK publishes current conditions for shielding a visiting address and for providing a separate postal address; officials' home addresses have additional protections. Separately, the residents' database (BRP, Basisregistratie Personen) cannot be opted out of because municipalities are legally required to maintain it, but residents can request 'geheimhouding' (confidentiality) so their data is not shared with certain third parties under the applicable rules.
At a glance
- Full name
- GDPR + Uitvoeringswet Algemene verordening gegevensbescherming (GDPR Implementation Act)
- Short code
- UAVG
- Jurisdiction
- Netherlands
- Enacted
- 2018
- Last major update
- UAVG in force 25 May 2018 alongside the EU GDPR
- Regulator
- Autoriteit Persoonsgegevens (AP)
- Private right of action
- Yes
- Statutory citation
- UAVG + Regulation (EU) 2016/679
Scope, who UAVG covers
Protected data
Data subject rights
Right of access (Article 15)
Right to rectification (Article 16)
Right to erasure / right to be forgotten (Article 17)
Right to restriction of processing (Article 18)
Right to data portability (Article 20)
Right to object, incl. absolute right for direct marketing (Article 21)
Right to request BRP confidentiality (geheimhouding) and to shield a KvK visiting address
Right to lodge a complaint with the Autoriteit Persoonsgegevens (Article 77)
Notable features
The Netherlands combines GDPR with Dutch implementation rules and a collective-action procedure under the WAMCA. A practical exposure issue is the KvK trade register: shielding a visiting address does not automatically remove copies already made by other services. Since 1 July 2026, current government guidance generally requires prior consent for sales calls to consumers and certain non-legal-entity businesses; separate exceptions apply to specified charities, charity lotteries, and publishers, and legal-person companies may be called for sales.
Enforcement & penalties
Regulator: Autoriteit Persoonsgegevens (AP)
Penalties: GDPR two-tier fines: up to €10M or 2% of global turnover (lower tier) and up to €20M or 4% of global turnover (higher tier), whichever is greater. The AP publishes current enforcement decisions and guidance; historical cases should not be treated as a forecast of a future penalty.
Private right of action: GDPR Article 82 grants a right to compensation for material or non-material damage before the Dutch civil courts. Collective-action procedures are also available under Dutch law, including the WAMCA regime, subject to its standing, admissibility, and procedural requirements.
Relevance to data brokers
Data brokers, directories, and parties using KvK information may be controllers or processors under GDPR + UAVG depending on their role. Dutch residents can use the current KVK shielding route, request BRP geheimhouding, and exercise GDPR access, objection, or erasure rights when the statutory conditions apply. The AP handles complaints, while collective proceedings remain subject to Dutch procedural requirements.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Who enforces data privacy in the Netherlands?+
The Autoriteit Persoonsgegevens (AP), the Dutch Data Protection Authority, which enforces both the EU GDPR and the national UAVG implementation act.
My home address is public on the KvK: can I hide it?+
Sole proprietors can apply to shield a visiting address under the KVK's current conditions and must provide a separate postal address where required. Other organisations may need to show a qualifying threat, and officials' home addresses have additional protections. Shielding at the KVK does not remove data already copied by online brokers.
Can I opt out of the BRP residents' database?+
No: your municipality is legally required to register you, so the GDPR right to object does not apply to the BRP itself. But you can request "geheimhouding" (confidentiality) so your data is not shared with certain third parties such as churches and non-government organisations.
Is telemarketing allowed in the Netherlands?+
Since 1 July 2026, sales calls to consumers generally require prior consent even when the person is an existing or former customer. Current government guidance separately describes exceptions for specified charities, charity lotteries, and publishers, while companies with legal personality may be called for sales; sole proprietors and other legal structures without legal personality generally require prior consent. Check the current government and ACM guidance for the recipient and call type.
Official sources & citations
Other international privacy regimes
UAVG sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
