Data Protection & Privacy
DETAIL

Netherlands Implementation Act GDPR — UAVG (Uitvoeringswet AVG)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

arrow_back
arrow_forward

Overview

The Netherlands Implementation Act GDPR (Uitvoeringswet AVG or UAVG) is a national data protection regulation that helps organizations in the Netherlands comply with the European Union General Data Protection Regulation (GDPR) requirements. The UAVG supplements the GDPR by providing specific rules and clarifications for data processing activities within the Dutch jurisdiction.

Published by the Dutch government, the UAVG applies to all public and private sector organizations processing personal data in the Netherlands. It addresses areas such as data subject rights, special categories of data, employee data processing, and supervision by the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). The UAVG ensures that organizations align local practices with EU-wide data protection and privacy standards.

Organizations typically operationalize the UAVG by updating privacy policies, implementing technical and organizational security controls, conducting data protection impact assessments, and ensuring lawful data processing. Integrating UAVG requirements supports compliance, risk management programs, and ongoing oversight to meet both Dutch and EU data protection obligations.

Why it Matters

The UAVG enables organizations in the Netherlands to meet bothnational and EU data protection obligations and safeguardindividuals’ personal data.

Key benefits include:

  • Enhance regulatory alignment

Aligns local dataprocessing activities with EU GDPR standards to support consistentand lawful privacy practices.

  • Strengthen data protection practices

Requires robustprivacy controls and risk assessments, improving how organizationsmanage and protect sensitive information.

  • Support audit and oversight readiness

Facilitatescontinuous monitoring and documentation to efficiently demonstratecompliance during regulatory inspections and audits.

  • Improve employee data governance

Clarifies rulesfor handling employee data, reducing risks related to workforceprivacy violations and legal disputes.

  • Reduce compliance risks

Minimizesexposure to legal penalties and reputational harm by ensuringpersonal data processing is backed by clear, lawful justifications.

How it Works

The Netherlands Implementation Act GDPR — UAVG (Uitvoeringswet AVG)structures GDPR obligations into national statutory provisions thatsupplement EU rules, organizing requirements around data processinglifecycle, lawful bases, data subject rights, supervisoryenforcement, and specific national derogations. It aligns with GDPRprinciples and prescribes processes such as records of processing(RoPA), DPIAs, and breach notification timelines.

Organizations implement the UAVG by mapping processing activities tolegal obligations, establishing governance for consent, processors,and data transfers, and embedding security controls andprivacy-by-design practices. Typical activities include conductingDPIAs and risk management, maintaining RoPA, appointing a DPO whererequired, operationalizing data subject request workflows, performingcompliance assessments, and monitoring incidents and vendorcompliance.

Within SmartSuite, teams can operationalize the UAVG using controllibraries mapped to articles and national clauses, a risk registerfor DPIAs and mitigation actions, policy governance for RoPA and DPOroles, evidence collection for audits and breach records, compliancetracking, remediation workflows, and dashboards for monitoringregulatory posture and audit readiness.

Key Elements

  • Lawful Data Processing Principles

Specifiesfoundational requirements for the legal collection, use, andretention of personal data within the Netherlands.

  • Special Categories of Data Rules

Outlines distinctconditions and additional safeguards for processing sensitive orspecial categories of personal information.

  • Employee Data Handling Provisions

Describesrequirements for the management and protection of employee personaldata in employment contexts.

  • Data Subject Rights Framework

Defines thestructural organization of mechanisms supporting data access,correction, erasure, and objection for individuals.

  • Supervision and Enforcement Structure

Establishesprocedures for oversight, audit, and enforcement led by the DutchData Protection Authority.

  • National GDPR Supplementary Provisions

Detailsadditional Dutch regulations that extend or clarify the applicationof the EU GDPR at the national level.

Framework Scope

The Netherlands Implementation Act GDPR (UAVG) is implemented byentities processing personal data within the Netherlands, includingpublic institutions and private companies. The UAVG governs personaldata processing activities, employee records, and specialized datacategories, and is commonly adopted to fulfill Dutch and Europeandata protection obligations while improving compliance oversight andprivacy management programs.

Framework Objectives

The Netherlands Implementation Act GDPR (UAVG) clarifies and augmentsdata protection, cybersecurity, and compliance requirements fororganizations operating in the Netherlands.

Strengthen compliance with EU and national data protection andprivacy obligations

Safeguard personal data through comprehensive security controls andrisk management

Enhance governance and oversight of data processing and privacypractices

Promote transparency and accountability in personal data handling andcybersecurity

Support operational resilience and preparedness for data protectionauthority audits

Enable effective management of risks related to special categories ofpersonal data The Netherlands Implementation Act (UAVG)operationalizes EU GDPR requirements nationally and is commonlyaligned with the EU GDPR, the ePrivacy Directive, and ISO/IEC 27701for privacy management. Organizations adopt UAVG compliance measuresfor regulatory compliance, data processing contracts, cross‑bordertransfer safeguards, and to integrate privacy governance or pursueprivacy certifications.

Framework in Context

The NetherlandsImplementation Act (UAVG) operationalizes EU GDPR requirementsnationally and is commonly aligned with the EU GDPR, the ePrivacyDirective, and ISO/IEC 27701 for privacy management. Organizationsadopt UAVG compliance measures for regulatory compliance, dataprocessing contracts, cross‑border transfer safeguards, and tointegrate privacy governance or pursue privacy certifications.

Common Framework Mappings

Organizations map national and international privacy laws andstandards to harmonize obligations, streamline controls, and supportcross-border data transfers and vendor compliance assessments.

Mapped frameworks include:

California Consumer Privacy Act (CCPA) / California Privacy RightsAct (CPRA)

ePrivacy Directive (2002/58/EC)

EU General Data Protection Regulation (GDPR)

ISO/IEC 27701

NIST Privacy Framework

Swiss Federal Act on Data Protection (FADP)

UK Data Protection Act 2018

At a Glance
Uitvoeringswet AVG (UAVG) — GDPR (EU) 2016/679
  • checklist
    Classification
    Category
    info
    Data Protection & Privacy
    Domain
    info
    Privacy
    Framework Family
    info
    Global Privacy Regulations
  • info
    Regulatory Context
    Type
    info
    Regulation
    Legal Instrument
    info
    Act
    Sector
    info
    Cross-Sector
    Industry
    info
    Cross-Industry
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Europe
    Region Detail
    info
    Netherlands
    Publisher
    info
    Autoriteit Persoonsgegevens
  • published_with_changes
    Versioning
    Version
    info
    UAVG — Implementation Act GDPR
    Effective Date
    info
    May 25, 2018
    Issue Date
    info
    May 25, 2018
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

The Netherlands Implementation Act GDPR is publicly available through official Dutch government legal resources.

Official Resources
Netherlands Implementation Act GDPR (UAVG) Text
Provides the full legislative text of the Netherlands Implementation Act GDPR (UAVG).
chevron_forward
Autoriteit Persoonsgegevens - GDPR/UAVG Guidance
Outlines guidance for organizations to align with GDPR and UAVG requirements in the Netherlands.
chevron_forward
Dutch Government GDPR Information
Describes the implementation and impact of GDPR and UAVG within the Netherlands.
chevron_forward
Dutch Data Protection Authority Regulatory Overview
Defines the role and oversight capabilities of the Dutch Data Protection Authority under UAVG.
chevron_forward
SMARTSUITE

How SmartSuite Supports Netherlands UAVG

Manage privacy governance, personal data protection controls, and regulatory compliance through connected workflows aligned with GDPR and the Netherlands’ national data protection requirements.

Personal Data Inventory and Mapping

Track personal data assets, systems, and data flows across the organization.

Records of Processing and Legal Basis Tracking

Maintain documentation of processing activities and legal bases for processing personal data.

Data Subject Rights Workflows

Automate access, correction, and deletion requests with deadlines and audit trails.

Privacy Risk and Impact Assessments

Track privacy impact assessments, approvals, mitigation tasks, and compliance evidence.

Vendor and Processor Oversight

Monitor vendors and processors that handle personal data on behalf of the organization.

Privacy Compliance Reporting and Audit Readiness

Provide dashboards and reports showing privacy program coverage and regulatory readiness.

Related frameworks

CCPA/CPRA

CCPA/CPRA is California privacy law giving residents control over personal data and requiring businesses to protect and disclose data practices.

Learn More
arrow_forward
GDPR

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

Learn More
arrow_forward
ISO 27701

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

Learn More
arrow_forward
NIST Privacy Framework v1.0

NIST Privacy Framework provides voluntary guidance to help organizations identify, assess, and manage privacy risks to individuals' data.

Learn More
arrow_forward
UK DPA 2018

The UK Data Protection Act 2018 sets UK legal requirements for protecting personal data and enforcing individuals' privacy rights.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For Netherlands Implementation Act GDPR — UAVG (Uitvoeringswet AVG)

What is the Netherlands Implementation Act GDPR (UAVG) used for?

The UAVG is used to supplement the European Union GDPR with national rules and clarifications specific to the Netherlands. It ensures that organizations processing personal data in the Netherlands comply with both EU-level and Dutch-specific data protection requirements.

Is compliance with the UAVG mandatory for organizations?

Yes, compliance with the UAVG is mandatory for all public and private sector organizations that process personal data within the Netherlands. Failure to comply can result in enforcement actions from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Who does the UAVG apply to?

The UAVG applies to any entity—public or private—processing personal data in the Netherlands, regardless of where the organization is headquartered. This includes multinational organizations, small businesses, and government agencies handling data concerning Dutch residents.

What key concepts and documentation does the UAVG require?

Key concepts and required artifacts include Data Protection Impact Assessments (DPIAs), Records of Processing Activities (RoPA), lawful bases for processing, breach notification procedures, and documentation of data subject requests. Organizations must also appoint a Data Protection Officer (DPO) in certain cases and maintain technical and organizational security measures.

How should organizations implement the UAVG?

Organizations should map data processing activities to UAVG and GDPR requirements, update privacy policies, conduct DPIAs, and ensure secure data handling procedures. Establishing robust governance processes for consent management, documentation, and responding to data subject requests is essential for compliance.

How does the UAVG relate to the EU GDPR and other frameworks?

The UAVG builds on the EU GDPR by providing additional, Netherlands-specific requirements and clarifications but does not replace or override GDPR obligations. Organizations must comply with both the GDPR and UAVG where applicable, aligning Dutch practices with EU-wide standards and integrating with other privacy frameworks as needed.

What are the ongoing compliance requirements under the UAVG?

Ongoing requirements include regularly reviewing and updating processing records, risk assessments, security controls, and privacy notices. Organizations must also monitor data processing activities, manage data breaches according to prescribed timelines, and respond promptly to data subject requests.

How would SmartSuite support Netherlands Implementation Act GDPR — UAVG compliance?

SmartSuite supports UAVG compliance by providing pre-mapped control libraries, facilitating risk tracking through integrated registers for DPIAs and mitigation actions, and managing policy and RoPA documentation. The platform enables evidence collection for audits, breach response tracking, compliance management, and real-time dashboards for monitoring regulatory posture and audit readiness.

Operationalize UAVG with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

Schedule a Demo
chevron_forward
Demo Library
chevron_forward