Data Protection & Privacy
DETAIL

Netherlands Implementation Act GDPR — UAVG (Uitvoeringswet AVG)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

The NetherlandsImplementation Act GDPR (Uitvoeringswet AVG or UAVG) is a nationaldata protection regulation that helps organizations in theNetherlands comply with the European Union General Data ProtectionRegulation (GDPR) requirements. The UAVG supplements the GDPR byproviding specific rules and clarifications for data processingactivities within the Dutch jurisdiction.

Published by theDutch government, the UAVG applies to all public and private sectororganizations processing personal data in the Netherlands. Itaddresses areas such as data subject rights, special categories ofdata, employee data processing, and supervision by the Dutch DataProtection Authority (Autoriteit Persoonsgegevens). The UAVG ensuresthat organizations align local practices with EU-wide data protectionand privacy standards.

Organizationstypically operationalize the UAVG by updating privacy policies,implementing technical and organizational security controls,conducting data protection impact assessments, and ensuring lawfuldata processing. Integrating UAVG requirements supports compliance,risk management programs, and ongoing oversight to meet both Dutchand EU data protection obligations.

Why it Matters

The UAVG enablesorganizations in the Netherlands to meet both national and EU dataprotection obligations and safeguard individuals’ personal data.

Key benefitsinclude:

•  Enhance regulatory alignment

Aligns localdata processing activities with EU GDPR standards to supportconsistent and lawful privacy practices.

•  Strengthen data protection practices

Requires robustprivacy controls and risk assessments, improving how organizationsmanage and protect sensitive information.

•  Support audit and oversight readiness

Facilitatescontinuous monitoring and documentation to efficiently demonstratecompliance during regulatory inspections and audits.

•  Improve employee data governance

Clarifies rulesfor handling employee data, reducing risks related to workforceprivacy violations and legal disputes.

•  Reduce compliance risks

Minimizesexposure to legal penalties and reputational harm by ensuringpersonal data processing is backed by clear, lawful justifications.

How it Works

The NetherlandsImplementation Act GDPR — UAVG (Uitvoeringswet AVG) structures GDPRobligations into national statutory provisions that supplement EUrules, organizing requirements around data processing lifecycle,lawful bases, data subject rights, supervisory enforcement, andspecific national derogations. It aligns with GDPR principles andprescribes processes such as records of processing (RoPA), DPIAs, andbreach notification timelines.

Organizationsimplement the UAVG by mapping processing activities to legalobligations, establishing governance for consent, processors, anddata transfers, and embedding security controls and privacy-by-designpractices. Typical activities include conducting DPIAs and riskmanagement, maintaining RoPA, appointing a DPO where required,operationalizing data subject request workflows, performingcompliance assessments, and monitoring incidents and vendorcompliance.

WithinSmartSuite, teams can operationalize the UAVG using control librariesmapped to articles and national clauses, a risk register for DPIAsand mitigation actions, policy governance for RoPA and DPO roles,evidence collection for audits and breach records, compliancetracking, remediation workflows, and dashboards for monitoringregulatory posture and audit readiness.

Key Elements

•  Lawful Data Processing Principles

Specifiesfoundational requirements for the legal collection, use, andretention of personal data within the Netherlands.

•  Special Categories of Data Rules

Outlinesdistinct conditions and additional safeguards for processingsensitive or special categories of personal information.

•  Employee Data Handling Provisions

Describesrequirements for the management and protection of employee personaldata in employment contexts.

•  Data Subject Rights Framework

Defines thestructural organization of mechanisms supporting data access,correction, erasure, and objection for individuals.

•  Supervision and Enforcement Structure

Establishesprocedures for oversight, audit, and enforcement led by the DutchData Protection Authority.

•  National GDPR Supplementary Provisions

Detailsadditional Dutch regulations that extend or clarify the applicationof the EU GDPR at the national level.

Framework Scope

The NetherlandsImplementation Act GDPR (UAVG) is implemented by entities processingpersonal data within the Netherlands, including public institutionsand private companies. The UAVG governs personal data processingactivities, employee records, and specialized data categories, and iscommonly adopted to fulfill Dutch and European data protectionobligations while improving compliance oversight and privacymanagement programs.

Framework Objectives

The NetherlandsImplementation Act GDPR (UAVG) clarifies and augments dataprotection, cybersecurity, and compliance requirements fororganizations operating in the Netherlands.

•  Strengthen compliance with EU and national data protection andprivacy obligations

•  Safeguard personal data through comprehensive security controlsand risk management

•  Enhance governance and oversight of data processing and privacypractices

•  Promote transparency and accountability in personal datahandling and cybersecurity

•  Support operational resilience and preparedness for dataprotection authority audits

•  Enable effective management of risks related to specialcategories of personal data The Netherlands Implementation Act (UAVG)operationalizes EU GDPR requirements nationally and is commonlyaligned with the EU GDPR, the ePrivacy Directive, and ISO/IEC 27701for privacy management. Organizations adopt UAVG compliance measuresfor regulatory compliance, data processing contracts, cross bordertransfer safeguards, and to integrate privacy governance or pursueprivacy certifications.

Common Framework Mappings

Organizationsmap national and international privacy laws and standards toharmonize obligations, streamline controls, and support cross-borderdata transfers and vendor compliance assessments.

Mappedframeworks include:

CaliforniaConsumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)

ePrivacyDirective (2002/58/EC)

EU General DataProtection Regulation (GDPR)

ISO/IEC 27701

NIST PrivacyFramework

Swiss FederalAct on Data Protection (FADP)

UK DataProtection Act 2018

At a Glance
Uitvoeringswet AVG (UAVG) — GDPR (EU) 2016/679
  • checklist
    Classicifation
    Category
    info
    Data Protection & Privacy
    Domain
    info
    Privacy
    Framework Family
    info
    Global Privacy Regulations
  • info
    Regulatory Context
    Type
    info
    Regulation
    Legal Instrument
    info
    Act
    Sector
    info
    Cross-Sector
    Industry
    info
    Cross-Industry
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Europe
    Region Detail
    info
    Netherlands
    Publisher
    info
    Autoriteit Persoonsgegevens
  • published_with_changes
    Versioning
    Version
    info
    UAVG — Implementation Act GDPR
    Effective Date
    info
    May 25, 2018
    Issue Date
    info
    May 25, 2018
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

The Netherlands Implementation Act GDPR is publicly available through official Dutch government legal resources.

Official Resources
Netherlands Implementation Act GDPR (UAVG) Text
Provides the full legislative text of the Netherlands Implementation Act GDPR (UAVG).
chevron_forward
Autoriteit Persoonsgegevens - GDPR/UAVG Guidance
Outlines guidance for organizations to align with GDPR and UAVG requirements in the Netherlands.
chevron_forward
Dutch Government GDPR Information
Describes the implementation and impact of GDPR and UAVG within the Netherlands.
chevron_forward
Dutch Data Protection Authority Regulatory Overview
Defines the role and oversight capabilities of the Dutch Data Protection Authority under UAVG.
chevron_forward
SMARTSUITE

How SmartSuite Supports Netherlands UAVG

Manage privacy governance, personal data protection controls, and regulatory compliance through connected workflows aligned with GDPR and the Netherlands’ national data protection requirements.

Personal Data Inventory and Mapping

Track personal data assets, systems, and data flows across the organization.

Records of Processing and Legal Basis Tracking

Maintain documentation of processing activities and legal bases for processing personal data.

Data Subject Rights Workflows

Automate access, correction, and deletion requests with deadlines and audit trails.

Privacy Risk and Impact Assessments

Track privacy impact assessments, approvals, mitigation tasks, and compliance evidence.

Vendor and Processor Oversight

Monitor vendors and processors that handle personal data on behalf of the organization.

Privacy Compliance Reporting and Audit Readiness

Provide dashboards and reports showing privacy program coverage and regulatory readiness.

Related frameworks

CCPA/CPRA

CCPA/CPRA is California privacy law giving residents control over personal data and requiring businesses to protect and disclose data practices.

Learn More
arrow_forward
GDPR

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

Learn More
arrow_forward
ISO 27701

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

Learn More
arrow_forward
NIST Privacy Framework v1.0

NIST Privacy Framework provides voluntary guidance to help organizations identify, assess, and manage privacy risks to individuals' data.

Learn More
arrow_forward
UK DPA 2018

The UK Data Protection Act 2018 sets UK legal requirements for protecting personal data and enforcing individuals' privacy rights.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For Netherlands Implementation Act GDPR — UAVG (Uitvoeringswet AVG)

What is the Netherlands Implementation Act GDPR (UAVG) used for?

The UAVG is used to supplement the European Union GDPR with national rules and clarifications specific to the Netherlands. It ensures that organizations processing personal data in the Netherlands comply with both EU-level and Dutch-specific data protection requirements.

Is compliance with the UAVG mandatory for organizations?

Yes, compliance with the UAVG is mandatory for all public and private sector organizations that process personal data within the Netherlands. Failure to comply can result in enforcement actions from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Who does the UAVG apply to?

The UAVG applies to any entity—public or private—processing personal data in the Netherlands, regardless of where the organization is headquartered. This includes multinational organizations, small businesses, and government agencies handling data concerning Dutch residents.

What key concepts and documentation does the UAVG require?

Key concepts and required artifacts include Data Protection Impact Assessments (DPIAs), Records of Processing Activities (RoPA), lawful bases for processing, breach notification procedures, and documentation of data subject requests. Organizations must also appoint a Data Protection Officer (DPO) in certain cases and maintain technical and organizational security measures.

How should organizations implement the UAVG?

Organizations should map data processing activities to UAVG and GDPR requirements, update privacy policies, conduct DPIAs, and ensure secure data handling procedures. Establishing robust governance processes for consent management, documentation, and responding to data subject requests is essential for compliance.

How does the UAVG relate to the EU GDPR and other frameworks?

The UAVG builds on the EU GDPR by providing additional, Netherlands-specific requirements and clarifications but does not replace or override GDPR obligations. Organizations must comply with both the GDPR and UAVG where applicable, aligning Dutch practices with EU-wide standards and integrating with other privacy frameworks as needed.

What are the ongoing compliance requirements under the UAVG?

Ongoing requirements include regularly reviewing and updating processing records, risk assessments, security controls, and privacy notices. Organizations must also monitor data processing activities, manage data breaches according to prescribed timelines, and respond promptly to data subject requests.

How would SmartSuite support Netherlands Implementation Act GDPR — UAVG compliance?

SmartSuite supports UAVG compliance by providing pre-mapped control libraries, facilitating risk tracking through integrated registers for DPIAs and mitigation actions, and managing policy and RoPA documentation. The platform enables evidence collection for audits, breach response tracking, compliance management, and real-time dashboards for monitoring regulatory posture and audit readiness.

NEXT STEP

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

Explore in SmartSuite
chevron_forward
View all Frameworks
chevron_forward