Privacy Notice Statement Template for the Netherlands
Generate a bespoke document
What is a Privacy Notice Statement?
The Privacy Notice Statement is a mandatory document under both the EU General Data Protection Regulation (GDPR) and Dutch privacy law. It must be provided wherever personal data is collected from data subjects in the Netherlands, whether directly or indirectly. This document fulfills the transparency requirements of GDPR Articles 13 and 14, providing clear information about data processing activities, data subject rights, and organizational practices. The Privacy Notice Statement should be written in clear, plain language and must be easily accessible to Dutch residents and other data subjects. It serves as both a legal compliance document and a trust-building tool, demonstrating the organization's commitment to data protection and privacy rights. Regular updates are required when processing activities change or at least annually to ensure continued accuracy and compliance.
About the Privacy Notice Statement
A Privacy Notice Statement is your organization's formal disclosure to individuals about how you collect, use, and protect their personal data. Under Dutch and EU law, this document is not optional—it's a legal requirement that must be provided whenever you process personal information from data subjects in the Netherlands.
When do you need this document?
You need a Privacy Notice Statement whenever your organization collects personal data from individuals, whether through websites, mobile apps, customer registration, employee onboarding, or marketing campaigns. This includes both direct collection (when individuals provide data to you) and indirect collection (when you obtain data from third parties). E-commerce businesses, healthcare providers, financial institutions, employers, and marketing agencies all require comprehensive privacy notices to operate legally in the Netherlands. Even small businesses collecting customer email addresses or processing employee data must provide proper privacy notifications.
Key legal considerations
Your Privacy Notice Statement must include specific mandatory information under GDPR Articles 13 and 14. This includes your identity as data controller, contact details including your Data Protection Officer if applicable, the categories of personal data collected, and the legal basis for processing each type of data. You must clearly explain the purposes of processing, retention periods, and any automated decision-making or profiling activities. The notice must detail data subject rights including access, rectification, erasure, and portability, plus information about third-party recipients and international transfers. Failure to provide adequate privacy notices can result in significant GDPR fines up to €20 million or 4% of global turnover.
Legal requirements in the Netherlands
Under Dutch law, your Privacy Notice Statement must comply with both the GDPR and the Dutch GDPR Implementation Act (UAVG). The notice must be available in Dutch when targeting Dutch residents, though English versions are acceptable for international organizations with clear multilingual policies. For websites and online services, you must also address cookie usage under the Dutch Telecommunications Act and EU ePrivacy Directive, explaining tracking technologies and obtaining proper consent. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) requires that privacy notices be easily accessible, typically through website footers or prominent links during data collection. Special attention must be paid to children's data protection rights, with enhanced transparency requirements for processing data of individuals under 16 years old.
GOVERNING LAW
Applicable law
This Privacy Notice Statement is drafted to comply with Netherlands law. Key legislation includes:
Dutch GDPR Implementation Act (UAVG): The Dutch law implementing the GDPR, containing national specifications and derogations (Uitvoeringswet Algemene verordening gegevensbescherming)
Dutch Telecommunications Act: Contains specific provisions about cookies and electronic communications privacy (Telecommunicatiewet), implementing the EU ePrivacy Directive
EU Cookie Law (ePrivacy Directive): European directive governing the use of cookies and similar technologies (Directive 2002/58/EC, amended by Directive 2009/136/EC)
Dutch Civil Code: Contains general provisions about legal notices and information requirements (Burgerlijk Wetboek)
Dutch Data Protection Authority Guidelines: Guidelines and interpretations issued by the Autoriteit Persoonsgegevens for privacy notices and data protection compliance
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it