25-09-2026 - The Dutch Data Protection Collection Act is now in force: what changes?
Since 1 September 2026, most of the Dutch Data Protection Collection Act (Verzamelwet gegevensbescherming) has been in force. The Act does not amend the GDPR itself but introduces several changes to the Dutch GDPR Implementation Act (UAVG). Some changes are mainly technical, while others may require organisations to adjust their existing processes and procedures.
In this blog, we discuss the key changes and what they mean for organisations in practice.
Fewer types of data fall under the rules for criminal personal data
Stricter rules apply to criminal personal data than to ordinary personal data. The Act changes which data the UAVG automatically classifies as criminal personal data.
Previously, information concerning a court-imposed ban resulting from unlawful or disruptive behavior was automatically classified as criminal personal data. This specific Dutch addition has now been removed. The mere fact that such a prohibition has been imposed no longer automatically makes the related personal data criminal personal data.
This does not mean that data concerning such a prohibition can never be criminal personal data. This may still be the case, for example, if the prohibition forms part of a criminal conviction or if breaching the prohibition itself constitutes a criminal offence.
Organisations processing such data may therefore wish to reassess whether these data are still correctly classified as criminal personal data. Even if the data no longer fall within this category, the general rules of the GDPR continue to apply.
New uses of the BSN require a specific legal basis
The rules on the use of the Dutch citizen service number (burgerservicenummer or BSN) have also changed. Organisations may only use a BSN if there is a legal basis for doing so.
Previously, the UAVG provided a general mechanism for designating additional situations in which a statutory identification number, such as the BSN, could be used. This general mechanism has now been removed. New uses must therefore have a specific legal basis, which may be further elaborated.
Existing regulations remain in force. This means that the changes do not automatically affect existing lawful use of the BSN. However, when introducing new processing activities or changing existing processes, organisations should verify that there is a legal basis for using the BSN.
The substantial public interest requirement for biometric data must be explicitly assessed
The UAVG already contained an exception allowing biometric data, such as fingerprints or facial features, to be used under certain circumstances for authentication or security purposes.
The Act adds further requirements to this exception. Organisations must now assess in each specific case whether the use of biometric data is necessary for reasons of substantial public interest. The purpose is also defined more clearly: it must concern securing lawful access to, for example, buildings, services, products or information systems.
A regular business interest, such as convenience or cost savings, is not sufficient. Organisations using biometric access controls must therefore be able to explain why biometrics are necessary and why a less intrusive alternative would not be sufficient.
Minors gain more opportunities to exercise their privacy rights independently
The Act gives children aged twelve and older more opportunities to exercise their privacy rights independently. For children under twelve, these rights are generally exercised by their legal representative on their behalf. Between the ages of twelve and sixteen, both the child and their legal representative can, for example, request access to, correction of or deletion of personal data.
For children under the age of sixteen, consent must generally be given by their legal representative. However, from the age of twelve, children can independently withdraw consent previously given on their behalf. From the age of sixteen, children can also take legal action independently in disputes concerning their GDPR rights.
For organisations processing children's personal data, these new age thresholds may affect how privacy requests and withdrawals of consent are handled. It is therefore advisable to review existing procedures.
The Dutch DPA must publish sanction decisions
The Act requires the Dutch Data Protection Authority (Autoriteit Persoonsgegevens or AP) to, in principle, publish decisions imposing administrative sanctions. Publication will normally take place no earlier than ten working days after the decision has been communicated. If an application for interim relief is made within that period, publication is postponed.
For organisations, this means that a sanction may not only have legal and financial consequences but may also become publicly known.
Other changes
In addition to these changes, the Act introduces several amendments that are mainly relevant to specific organisations and sectors. These include clarifications regarding the transfer of medical records when a healthcare provider ceases operations, the processing of personal data by trustees and administrators in insolvency proceedings, and the rules for banks and payment service providers that automatically block or temporarily suspend unusual payment transactions.
The Act also contains a new provision on the processing of special categories of personal data in the context of statutory audit engagements. This is the only provision that has not yet entered into force and will take effect at a later date.
What should organisations do now?
Not every change affects every organisation. It is therefore important to identify which changes are relevant to the personal data and processes within your organisation.
Organisations can, for example, assess whether certain data are still correctly classified as criminal personal data, verify the legal basis for their use of BSNs, review the justification for biometric applications and check whether procedures relating to children's personal data reflect the new rules.
Where a change is relevant, it may be necessary to update existing policies, procedures or other privacy documentation.
At Considerati, we are following these developments closely and will continue to share updates on their implications for organisations. If you would like to discuss what the introduced changes mean for your organisation, we are happy to get in contact.
Do you have any questions about the above or are you looking for strategic Legal advice? Contact Considerati, we offer specialised advice and tailored support.
Our services Contact