Netherlands Implementation Act GDPR — UAVG (Uitvoeringswet AVG)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The NetherlandsImplementation Act GDPR (Uitvoeringswet AVG or UAVG) is a nationaldata protection regulation that helps organizations in theNetherlands comply with the European Union General Data ProtectionRegulation (GDPR) requirements. The UAVG supplements the GDPR byproviding specific rules and clarifications for data processingactivities within the Dutch jurisdiction.
Published by theDutch government, the UAVG applies to all public and private sectororganizations processing personal data in the Netherlands. Itaddresses areas such as data subject rights, special categories ofdata, employee data processing, and supervision by the Dutch DataProtection Authority (Autoriteit Persoonsgegevens). The UAVG ensuresthat organizations align local practices with EU-wide data protectionand privacy standards.
Organizationstypically operationalize the UAVG by updating privacy policies,implementing technical and organizational security controls,conducting data protection impact assessments, and ensuring lawfuldata processing. Integrating UAVG requirements supports compliance,risk management programs, and ongoing oversight to meet both Dutchand EU data protection obligations.
Why it Matters
The UAVG enablesorganizations in the Netherlands to meet both national and EU dataprotection obligations and safeguard individuals’ personal data.
Key benefitsinclude:
• Enhance regulatory alignment
Aligns localdata processing activities with EU GDPR standards to supportconsistent and lawful privacy practices.
• Strengthen data protection practices
Requires robustprivacy controls and risk assessments, improving how organizationsmanage and protect sensitive information.
• Support audit and oversight readiness
Facilitatescontinuous monitoring and documentation to efficiently demonstratecompliance during regulatory inspections and audits.
• Improve employee data governance
Clarifies rulesfor handling employee data, reducing risks related to workforceprivacy violations and legal disputes.
• Reduce compliance risks
Minimizesexposure to legal penalties and reputational harm by ensuringpersonal data processing is backed by clear, lawful justifications.
How it Works
The NetherlandsImplementation Act GDPR — UAVG (Uitvoeringswet AVG) structures GDPRobligations into national statutory provisions that supplement EUrules, organizing requirements around data processing lifecycle,lawful bases, data subject rights, supervisory enforcement, andspecific national derogations. It aligns with GDPR principles andprescribes processes such as records of processing (RoPA), DPIAs, andbreach notification timelines.
Organizationsimplement the UAVG by mapping processing activities to legalobligations, establishing governance for consent, processors, anddata transfers, and embedding security controls and privacy-by-designpractices. Typical activities include conducting DPIAs and riskmanagement, maintaining RoPA, appointing a DPO where required,operationalizing data subject request workflows, performingcompliance assessments, and monitoring incidents and vendorcompliance.
WithinSmartSuite, teams can operationalize the UAVG using control librariesmapped to articles and national clauses, a risk register for DPIAsand mitigation actions, policy governance for RoPA and DPO roles,evidence collection for audits and breach records, compliancetracking, remediation workflows, and dashboards for monitoringregulatory posture and audit readiness.
Key Elements
• Lawful Data Processing Principles
Specifiesfoundational requirements for the legal collection, use, andretention of personal data within the Netherlands.
• Special Categories of Data Rules
Outlinesdistinct conditions and additional safeguards for processingsensitive or special categories of personal information.
• Employee Data Handling Provisions
Describesrequirements for the management and protection of employee personaldata in employment contexts.
• Data Subject Rights Framework
Defines thestructural organization of mechanisms supporting data access,correction, erasure, and objection for individuals.
• Supervision and Enforcement Structure
Establishesprocedures for oversight, audit, and enforcement led by the DutchData Protection Authority.
• National GDPR Supplementary Provisions
Detailsadditional Dutch regulations that extend or clarify the applicationof the EU GDPR at the national level.
Framework Scope
The NetherlandsImplementation Act GDPR (UAVG) is implemented by entities processingpersonal data within the Netherlands, including public institutionsand private companies. The UAVG governs personal data processingactivities, employee records, and specialized data categories, and iscommonly adopted to fulfill Dutch and European data protectionobligations while improving compliance oversight and privacymanagement programs.
Framework Objectives
The NetherlandsImplementation Act GDPR (UAVG) clarifies and augments dataprotection, cybersecurity, and compliance requirements fororganizations operating in the Netherlands.
• Strengthen compliance with EU and national data protection andprivacy obligations
• Safeguard personal data through comprehensive security controlsand risk management
• Enhance governance and oversight of data processing and privacypractices
• Promote transparency and accountability in personal datahandling and cybersecurity
• Support operational resilience and preparedness for dataprotection authority audits
• Enable effective management of risks related to specialcategories of personal data The Netherlands Implementation Act (UAVG)operationalizes EU GDPR requirements nationally and is commonlyaligned with the EU GDPR, the ePrivacy Directive, and ISO/IEC 27701for privacy management. Organizations adopt UAVG compliance measuresfor regulatory compliance, data processing contracts, cross bordertransfer safeguards, and to integrate privacy governance or pursueprivacy certifications.
Common Framework Mappings
Organizationsmap national and international privacy laws and standards toharmonize obligations, streamline controls, and support cross-borderdata transfers and vendor compliance assessments.
Mappedframeworks include:
CaliforniaConsumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
ePrivacyDirective (2002/58/EC)
EU General DataProtection Regulation (GDPR)
ISO/IEC 27701
NIST PrivacyFramework
Swiss FederalAct on Data Protection (FADP)
UK DataProtection Act 2018
- ClassicifationCategoryData Protection & PrivacyDomainPrivacyFramework FamilyGlobal Privacy Regulations
- Regulatory ContextTypeRegulationLegal InstrumentActSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionEuropeRegion DetailNetherlandsPublisherAutoriteit Persoonsgegevens
- VersioningVersionUAVG — Implementation Act GDPREffective DateMay 25, 2018Issue DateMay 25, 2018
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The Netherlands Implementation Act GDPR is publicly available through official Dutch government legal resources.
How SmartSuite Supports Netherlands UAVG
Manage privacy governance, personal data protection controls, and regulatory compliance through connected workflows aligned with GDPR and the Netherlands’ national data protection requirements.
Personal Data Inventory and Mapping
Track personal data assets, systems, and data flows across the organization.
Records of Processing and Legal Basis Tracking
Maintain documentation of processing activities and legal bases for processing personal data.
Data Subject Rights Workflows
Automate access, correction, and deletion requests with deadlines and audit trails.
Privacy Risk and Impact Assessments
Track privacy impact assessments, approvals, mitigation tasks, and compliance evidence.
Vendor and Processor Oversight
Monitor vendors and processors that handle personal data on behalf of the organization.
Privacy Compliance Reporting and Audit Readiness
Provide dashboards and reports showing privacy program coverage and regulatory readiness.
Related frameworks

CCPA/CPRA is California privacy law giving residents control over personal data and requiring businesses to protect and disclose data practices.

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.
Frequently Asked Questions For Netherlands Implementation Act GDPR — UAVG (Uitvoeringswet AVG)
The UAVG is used to supplement the European Union GDPR with national rules and clarifications specific to the Netherlands. It ensures that organizations processing personal data in the Netherlands comply with both EU-level and Dutch-specific data protection requirements.
Yes, compliance with the UAVG is mandatory for all public and private sector organizations that process personal data within the Netherlands. Failure to comply can result in enforcement actions from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
The UAVG applies to any entity—public or private—processing personal data in the Netherlands, regardless of where the organization is headquartered. This includes multinational organizations, small businesses, and government agencies handling data concerning Dutch residents.
Key concepts and required artifacts include Data Protection Impact Assessments (DPIAs), Records of Processing Activities (RoPA), lawful bases for processing, breach notification procedures, and documentation of data subject requests. Organizations must also appoint a Data Protection Officer (DPO) in certain cases and maintain technical and organizational security measures.
Organizations should map data processing activities to UAVG and GDPR requirements, update privacy policies, conduct DPIAs, and ensure secure data handling procedures. Establishing robust governance processes for consent management, documentation, and responding to data subject requests is essential for compliance.
The UAVG builds on the EU GDPR by providing additional, Netherlands-specific requirements and clarifications but does not replace or override GDPR obligations. Organizations must comply with both the GDPR and UAVG where applicable, aligning Dutch practices with EU-wide standards and integrating with other privacy frameworks as needed.
Ongoing requirements include regularly reviewing and updating processing records, risk assessments, security controls, and privacy notices. Organizations must also monitor data processing activities, manage data breaches according to prescribed timelines, and respond promptly to data subject requests.
SmartSuite supports UAVG compliance by providing pre-mapped control libraries, facilitating risk tracking through integrated registers for DPIAs and mitigation actions, and managing policy and RoPA documentation. The platform enables evidence collection for audits, breach response tracking, compliance management, and real-time dashboards for monitoring regulatory posture and audit readiness.
Put CRI Profile into action with SmartSuite
Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

