Subject Access Request Template for the Netherlands

Generate a bespoke document

What is a Subject Access Request?

A Subject Access Request is your legal right to ask any organization to share all the personal information they have about you. Under Dutch privacy law and the GDPR, you can request details about what data is being stored, how it's being used, and who it's being shared with.

Companies in the Netherlands must respond within one month of receiving your request and provide the information free of charge. You can make these requests verbally or in writing, and organizations must verify your identity before sharing the data. This right helps you understand and control how businesses and government agencies handle your personal information.

Frequently Asked Questions

When should you use a Subject Access Request?

File a Subject Access Request when you need to understand exactly what personal information an organization holds about you in the Netherlands. This is particularly useful if you're applying for jobs and want to see your employment records, dealing with credit issues and need to check financial data, or investigating how your data is being used for marketing.

It's also valuable when preparing legal cases, addressing privacy concerns, or correcting outdated information. For example, if you notice inconsistencies in your medical records or suspect a company is mishandling your data, a Subject Access Request helps you gather evidence and take control of your personal information.

What are the different types of Subject Access Request?

Who should typically use a Subject Access Request?

  • Data Subjects: Any individual in the Netherlands who wants to know what personal information organizations hold about them
  • Data Protection Officers: Professionals responsible for handling and responding to Subject Access Requests within organizations
  • Organizations and Businesses: Any entity that processes personal data must respond to these requests within legal timeframes
  • Legal Representatives: Lawyers and advisors who help individuals file requests or assist organizations in responding properly
  • Dutch Data Protection Authority: Oversees compliance and handles complaints when organizations fail to properly respond to requests

How do you write a Subject Access Request?

  • Personal Details: Gather your full name, contact information, and any reference numbers related to your relationship with the organization
  • Identity Verification: Prepare a copy of your passport, ID card, or driver's license to prove your identity
  • Data Scope: Specify exactly what information you're seeking and the time period it covers
  • Organization Details: Note the correct legal name and contact information of the organization holding your data
  • Format Preference: Indicate how you'd like to receive the information (digital or paper copy)
  • Documentation: Keep copies of all correspondence and note the date you submit your request

What should be included in a Subject Access Request?

  • Personal Identification: Clear statement of your full name, address, and any relevant account numbers
  • Request Scope: Specific description of the personal data you're requesting access to
  • Time Period: Clear indication of the date range for which you're requesting information
  • Response Format: Statement of how you want to receive the information (electronic or physical copy)
  • Identity Verification: Reference to enclosed proof of identity documents
  • Legal Rights Reference: Citation of GDPR Article 15 and Dutch AVG implementation
  • Response Timeline: Mention of the one-month statutory response period

What's the difference between a Subject Access Request and an Access Agreement?

A Subject Access Request differs significantly from an Access Agreement in both purpose and legal framework. While both deal with access rights, they serve distinct functions under Dutch law.

  • Legal Basis: Subject Access Requests are a fundamental right under GDPR and Dutch privacy law, while Access Agreements are contractual arrangements between parties
  • Purpose: Subject Access Requests focus on obtaining personal data an organization holds about you, whereas Access Agreements establish terms for accessing facilities, systems, or resources
  • Duration: Subject Access Requests are one-time inquiries with a mandatory 30-day response period, while Access Agreements typically establish ongoing permissions
  • Enforceability: Subject Access Requests are backed by data protection authorities and can't be denied without legal justification, but Access Agreements depend on mutual contract terms
  • Cost Structure: Subject Access Requests must be fulfilled free of charge (with few exceptions), while Access Agreements often involve fees or considerations

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Netherlands

Publisher

GenieAI

Category

other

Cost

Free to use

Last updated

About the Subject Access Request

  • Personal Details: Gather your full name, contact information, and any reference numbers related to your relationship with the organization
  • Identity Verification: Prepare a copy of your passport, ID card, or driver's license to prove your identity
  • Data Scope: Specify exactly what information you're seeking and the time period it covers
  • Organization Details: Note the correct legal name and contact information of the organization holding your data
  • Format Preference: Indicate how you'd like to receive the information (digital or paper copy)
  • Documentation: Keep copies of all correspondence and note the date you submit your request

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it