Netherlands Implementation Act GDPR — UAVG (Uitvoeringswet AVG)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The Netherlands Implementation Act GDPR (Uitvoeringswet AVG or UAVG) is a national data protection regulation that helps organizations in the Netherlands comply with the European Union General Data Protection Regulation (GDPR) requirements. The UAVG supplements the GDPR by providing specific rules and clarifications for data processing activities within the Dutch jurisdiction.
Published by the Dutch government, the UAVG applies to all public and private sector organizations processing personal data in the Netherlands. It addresses areas such as data subject rights, special categories of data, employee data processing, and supervision by the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). The UAVG ensures that organizations align local practices with EU-wide data protection and privacy standards.
Organizations typically operationalize the UAVG by updating privacy policies, implementing technical and organizational security controls, conducting data protection impact assessments, and ensuring lawful data processing. Integrating UAVG requirements supports compliance, risk management programs, and ongoing oversight to meet both Dutch and EU data protection obligations.
Why it Matters
The UAVG enables organizations in the Netherlands to meet bothnational and EU data protection obligations and safeguardindividuals’ personal data.
Key benefits include:
- Enhance regulatory alignment
Aligns local dataprocessing activities with EU GDPR standards to support consistentand lawful privacy practices.
- Strengthen data protection practices
Requires robustprivacy controls and risk assessments, improving how organizationsmanage and protect sensitive information.
- Support audit and oversight readiness
Facilitatescontinuous monitoring and documentation to efficiently demonstratecompliance during regulatory inspections and audits.
- Improve employee data governance
Clarifies rulesfor handling employee data, reducing risks related to workforceprivacy violations and legal disputes.
- Reduce compliance risks
Minimizesexposure to legal penalties and reputational harm by ensuringpersonal data processing is backed by clear, lawful justifications.
How it Works
The Netherlands Implementation Act GDPR — UAVG (Uitvoeringswet AVG)structures GDPR obligations into national statutory provisions thatsupplement EU rules, organizing requirements around data processinglifecycle, lawful bases, data subject rights, supervisoryenforcement, and specific national derogations. It aligns with GDPRprinciples and prescribes processes such as records of processing(RoPA), DPIAs, and breach notification timelines.
Organizations implement the UAVG by mapping processing activities tolegal obligations, establishing governance for consent, processors,and data transfers, and embedding security controls andprivacy-by-design practices. Typical activities include conductingDPIAs and risk management, maintaining RoPA, appointing a DPO whererequired, operationalizing data subject request workflows, performingcompliance assessments, and monitoring incidents and vendorcompliance.
Within SmartSuite, teams can operationalize the UAVG using controllibraries mapped to articles and national clauses, a risk registerfor DPIAs and mitigation actions, policy governance for RoPA and DPOroles, evidence collection for audits and breach records, compliancetracking, remediation workflows, and dashboards for monitoringregulatory posture and audit readiness.
Key Elements
- Lawful Data Processing Principles
Specifiesfoundational requirements for the legal collection, use, andretention of personal data within the Netherlands.
- Special Categories of Data Rules
Outlines distinctconditions and additional safeguards for processing sensitive orspecial categories of personal information.
- Employee Data Handling Provisions
Describesrequirements for the management and protection of employee personaldata in employment contexts.
- Data Subject Rights Framework
Defines thestructural organization of mechanisms supporting data access,correction, erasure, and objection for individuals.
- Supervision and Enforcement Structure
Establishesprocedures for oversight, audit, and enforcement led by the DutchData Protection Authority.
- National GDPR Supplementary Provisions
Detailsadditional Dutch regulations that extend or clarify the applicationof the EU GDPR at the national level.
Framework Scope
The Netherlands Implementation Act GDPR (UAVG) is implemented byentities processing personal data within the Netherlands, includingpublic institutions and private companies. The UAVG governs personaldata processing activities, employee records, and specialized datacategories, and is commonly adopted to fulfill Dutch and Europeandata protection obligations while improving compliance oversight andprivacy management programs.
Framework Objectives
The Netherlands Implementation Act GDPR (UAVG) clarifies and augmentsdata protection, cybersecurity, and compliance requirements fororganizations operating in the Netherlands.
Strengthen compliance with EU and national data protection andprivacy obligations
Safeguard personal data through comprehensive security controls andrisk management
Enhance governance and oversight of data processing and privacypractices
Promote transparency and accountability in personal data handling andcybersecurity
Support operational resilience and preparedness for data protectionauthority audits
Enable effective management of risks related to special categories ofpersonal data The Netherlands Implementation Act (UAVG)operationalizes EU GDPR requirements nationally and is commonlyaligned with the EU GDPR, the ePrivacy Directive, and ISO/IEC 27701for privacy management. Organizations adopt UAVG compliance measuresfor regulatory compliance, data processing contracts, cross‑bordertransfer safeguards, and to integrate privacy governance or pursueprivacy certifications.
Framework in Context
The NetherlandsImplementation Act (UAVG) operationalizes EU GDPR requirementsnationally and is commonly aligned with the EU GDPR, the ePrivacyDirective, and ISO/IEC 27701 for privacy management. Organizationsadopt UAVG compliance measures for regulatory compliance, dataprocessing contracts, cross‑border transfer safeguards, and tointegrate privacy governance or pursue privacy certifications.
Common Framework Mappings
Organizations map national and international privacy laws andstandards to harmonize obligations, streamline controls, and supportcross-border data transfers and vendor compliance assessments.
Mapped frameworks include:
California Consumer Privacy Act (CCPA) / California Privacy RightsAct (CPRA)
ePrivacy Directive (2002/58/EC)
EU General Data Protection Regulation (GDPR)
ISO/IEC 27701
NIST Privacy Framework
Swiss Federal Act on Data Protection (FADP)
UK Data Protection Act 2018
- ClassificationCategoryData Protection & PrivacyDomainPrivacyFramework FamilyGlobal Privacy Regulations
- Regulatory ContextTypeRegulationLegal InstrumentActSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionEuropeRegion DetailNetherlandsPublisherAutoriteit Persoonsgegevens
- VersioningVersionUAVG — Implementation Act GDPREffective DateMay 25, 2018Issue DateMay 25, 2018
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The Netherlands Implementation Act GDPR is publicly available through official Dutch government legal resources.
How SmartSuite Supports Netherlands UAVG
Manage privacy governance, personal data protection controls, and regulatory compliance through connected workflows aligned with GDPR and the Netherlands’ national data protection requirements.
Personal Data Inventory and Mapping
Track personal data assets, systems, and data flows across the organization.
Records of Processing and Legal Basis Tracking
Maintain documentation of processing activities and legal bases for processing personal data.
Data Subject Rights Workflows
Automate access, correction, and deletion requests with deadlines and audit trails.
Privacy Risk and Impact Assessments
Track privacy impact assessments, approvals, mitigation tasks, and compliance evidence.
Vendor and Processor Oversight
Monitor vendors and processors that handle personal data on behalf of the organization.
Privacy Compliance Reporting and Audit Readiness
Provide dashboards and reports showing privacy program coverage and regulatory readiness.
Related frameworks

CCPA/CPRA is California privacy law giving residents control over personal data and requiring businesses to protect and disclose data practices.

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.
Frequently Asked Questions For Netherlands Implementation Act GDPR — UAVG (Uitvoeringswet AVG)
The UAVG is used to supplement the European Union GDPR with national rules and clarifications specific to the Netherlands. It ensures that organizations processing personal data in the Netherlands comply with both EU-level and Dutch-specific data protection requirements.
Yes, compliance with the UAVG is mandatory for all public and private sector organizations that process personal data within the Netherlands. Failure to comply can result in enforcement actions from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
The UAVG applies to any entity—public or private—processing personal data in the Netherlands, regardless of where the organization is headquartered. This includes multinational organizations, small businesses, and government agencies handling data concerning Dutch residents.
Key concepts and required artifacts include Data Protection Impact Assessments (DPIAs), Records of Processing Activities (RoPA), lawful bases for processing, breach notification procedures, and documentation of data subject requests. Organizations must also appoint a Data Protection Officer (DPO) in certain cases and maintain technical and organizational security measures.
Organizations should map data processing activities to UAVG and GDPR requirements, update privacy policies, conduct DPIAs, and ensure secure data handling procedures. Establishing robust governance processes for consent management, documentation, and responding to data subject requests is essential for compliance.
The UAVG builds on the EU GDPR by providing additional, Netherlands-specific requirements and clarifications but does not replace or override GDPR obligations. Organizations must comply with both the GDPR and UAVG where applicable, aligning Dutch practices with EU-wide standards and integrating with other privacy frameworks as needed.
Ongoing requirements include regularly reviewing and updating processing records, risk assessments, security controls, and privacy notices. Organizations must also monitor data processing activities, manage data breaches according to prescribed timelines, and respond promptly to data subject requests.
SmartSuite supports UAVG compliance by providing pre-mapped control libraries, facilitating risk tracking through integrated registers for DPIAs and mitigation actions, and managing policy and RoPA documentation. The platform enables evidence collection for audits, breach response tracking, compliance management, and real-time dashboards for monitoring regulatory posture and audit readiness.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

