GDPR for Netherlands
GDPR compliance for companies in the Netherlands — AP enforcement trends, cookie consent, and Dutch-specific data protection guidance.
Data Protection Authority
Autoriteit Persoonsgegevens (AP)
Key Requirements
- →AP is the lead supervisory authority for many major US tech companies' EU operations
- →Netherlands is a common EU establishment for international companies (Amsterdam)
- →AP has investigated Meta, TikTok, and Netflix under one-stop-shop mechanism
- →Strong enforcement on children's data and dark patterns
The Dutch Autoriteit Persoonsgegevens (AP) holds significant authority in the EU data protection landscape because many US technology companies chose the Netherlands as their EU establishment — making the AP the lead supervisory authority under GDPR's one-stop-shop mechanism.
If your company has its main EU establishment in the Netherlands (common due to the Dutch holding company structure and Amsterdam's hub status), the AP is your primary point of contact for cross-border GDPR matters. This means AP approval is needed before the EDPB can investigate you under the consistency mechanism.
The AP has been particularly active on children's data protection. Dutch enforcement actions against gaming platforms and social media have resulted in orders to change age verification practices and delete illegally collected children's data. If your product has any teen or young adult user base, document your age verification methodology carefully.
Cookie consent in the Netherlands follows the AP's guidance that analytics cookies are not strictly necessary and require prior consent. The AP specifically prohibits cookie walls — conditioning service access on tracking consent. This is enforced actively.
The Netherlands also has specific rules under the Telecommunications Act (Telecommunicatiewet) for cookies that go beyond GDPR. Any cookie that processes personal data requires either consent or a strict necessity basis under Dutch telecom law, which predates GDPR and remains in force alongside it.
Check your GDPR compliance now
Free 5-minute self-assessment — score your GDPR controls across lawful basis, data subject rights, security, and breach notification.
Run free GDPR compliance check →