Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018)
The Netherlands' GDPR Implementation Act (Uitvoeringswet Algemene Verordening Gegevensbescherming, UAVG) of 2018 supplements the EU GDPR with national provisions. The Autoriteit Persoonsgegevens (AP - Dutch Data Protection Authority) oversees enforcement. The UAVG includes provisions for the age of digital consent (16 years), processing of national identification numbers (BSN), health data in research, journalistic exemptions, and administrative penalties. The Netherlands has a strong data protection tradition dating to the 1988 WBP.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Chapter 1 - General Provisions
| Code | Title |
|---|---|
| 152FZ-1 | Scope of the Federal Law (Article 1) |
| 152FZ-2 | Purpose of the Federal Law (Article 2) |
| 152FZ-3 | Basic Terms (Article 3) |
| 152FZ-4 | Legislation on Personal Data (Article 4) |
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| EPDPA-1 | Scope of Regulation (§1) |
| EPDPA-2 | Specifications for Application (§2) |
| EPDPA-3 | Application of Administrative Procedure Act (§3) |
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
Chapter 2 - Data Protection Authority (Autoriteit Persoonsgegevens)
| Code | Title |
|---|---|
| Art. 12 | Record-Keeping |
| Art. 14 | Human Oversight |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
Chapter 3 - Provisions for Implementation of the GDPR
| Code | Title |
|---|---|
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 26 | Obligations of Deployers of High-Risk AI Systems |
| Art. 29 | Application of a Conformity Assessment Body for Notification |
| Art. 30 | Privacy Policy |
Chapter 4 - Exceptions and Limitations
| Code | Title |
|---|---|
| Art. 41 | Exemptions from Certain GDPR Provisions |
| Art. 44 | Right to Effective Judicial Remedy |
| Art. 46 | Administrative Fines |
| Art. 47 | Existing Legal Procedures |
Chapter 5 - Transitional and Final Provisions
| Code | Title |
|---|---|
| Art. 48 | Criminal Penalties |
| Art. 49 | Collective Dispute Resolution |
| Art. 50 | Transparency Obligations for Providers and Deployers of Certain AI Systems |
| Art. 51 | Classification of General-Purpose AI Models as General-Purpose AI Models with Systemic Risk |
Children
| Code | Title |
|---|---|
| UAVG-6 | Processing of Children's Personal Data |
Civil Remedies
| Code | Title |
|---|---|
| UAVG-20 | Class Actions and Civil Liability |
Data Subject Rights
| Code | Title |
|---|---|
| UAVG-7 | Data Subject Rights under UAVG |
Documentation
| Code | Title |
|---|---|
| UAVG-9 | Records of Processing Activities |
Employment
| Code | Title |
|---|---|
| UAVG-15 | Employee Personal Data Processing |
Enforcement
| Code | Title |
|---|---|
| UAVG-19 | Administrative Fines and Penalties |
Governance
| Code | Title |
|---|---|
| UAVG-8 | Data Protection Officer Appointment |
Incident Response
| Code | Title |
|---|---|
| UAVG-12 | Personal Data Breach Notification |
Lawful Basis
| Code | Title |
|---|---|
| UAVG-2 | Lawful Basis for Processing under National Law |
Marketing
| Code | Title |
|---|---|
| UAVG-16 | Direct Marketing and Cookies |
Research
| Code | Title |
|---|---|
| UAVG-17 | Scientific Research and Statistics Exemption |
Risk Management
| Code | Title |
|---|---|
| UAVG-10 | Data Protection Impact Assessments |
Scope
| Code | Title |
|---|---|
| UAVG-1 | Scope and Relationship to GDPR |
Security
| Code | Title |
|---|---|
| UAVG-11 | Security of Processing |
Special Categories
| Code | Title |
|---|---|
| UAVG-3 | Processing of National Identification Numbers (BSN) |
| UAVG-4 | Special Categories of Personal Data |
| UAVG-5 | Processing of Criminal Conviction Data |
Supervision
| Code | Title |
|---|---|
| UAVG-18 | Autoriteit Persoonsgegevens Supervisory Powers |
Third Party
| Code | Title |
|---|---|
| UAVG-13 | Processor Engagement and Contracts |
Transfers
| Code | Title |
|---|---|
| UAVG-14 | International Data Transfers |
Your Compliance Coverage
If you comply with Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018), you already cover:
EU AI Act
32%
17 controls mapped
Compare →Turkey Personal Data Protection Law (KVKK - Law No. 6698)
32%
17 controls mapped
Compare →ILO Nursing Personnel Convention C149 (1977)
32%
17 controls mapped
Compare →+ 608 more: 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673) - superseded by AMLD7 (32%), ISO 8000 - Data Quality (32%)
See all 611 mapped frameworks ↓Maps to 611 other frameworks
Frequently Asked Questions
What is Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018)?
Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018) is a compliance framework from Netherlands with 23 domains and 53 controls. The Netherlands' GDPR Implementation Act (Uitvoeringswet Algemene Verordening Gegevensbescherming, UAVG) of 2018 supplements the EU GDPR with national provisions. The Autoriteit Persoonsgegevens (AP - Dutch Data Protection Authority) oversees enforcement. The UAVG includes provisions for the age of digital consent (16 years), processing of national identification numbers (BSN), health data in research, journalistic exemptions, and administrative penalties. The Netherlands has a strong data protection tradition dating to the 1988 WBP. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018) have?
Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018) has 53 controls organised across 23 domains. The largest domains are Chapter 1 - General Provisions (15 controls), Chapter 2 - Data Protection Authority (Autoriteit Persoonsgegevens) (5 controls), Chapter 3 - Provisions for Implementation of the GDPR (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018) map to?
Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018) maps to 611 other compliance frameworks. The top mapping partners are EU AI Act (32% coverage), Turkey Personal Data Protection Law (KVKK - Law No. 6698) (32% coverage), ILO Nursing Personnel Convention C149 (1977) (32% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018) compliance?
Start your Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 53 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required