Digital Operational Resilience Act (DORA)

🇳🇱Digital Operational Resilience Act in Netherlands

A comprehensive guide to Digital Operational Resilience Act compliance for organisations operating in Netherlands. Understand local enforcement, the national data protection authority, key focus areas, and notable enforcement actions.

About Digital Operational Resilience Act

The EU regulation establishing a comprehensive framework for digital operational resilience in the financial sector, covering ICT risk management, incident reporting, testing, and third-party risk.

Effective: 17 January 2025Max penalty: €5,000,000 for entities; €500,000 for individuals or 2% of total annual worldwide turnover for critical ICT third-party providers
Full Digital Operational Resilience Act overview

Digital Operational Resilience Act Enforcement in Netherlands

The Dutch Autoriteit Persoonsgegevens (AP) has become increasingly active in GDPR enforcement since 2020. The Netherlands implemented the GDPR through the Uitvoeringswet AVG (UAVG), which sets the age of digital consent for children at 16 and includes specific exemptions for journalistic and academic processing. The AP has focused heavily on government and public sector compliance, issuing significant findings against the Tax Authority for discriminatory automated decision-making and against the Ministry of Foreign Affairs. The AP has also investigated major international companies operating from the Netherlands, collaborating frequently with the Irish DPC on cross-border cases. Netherlands hosts many international tech companies due to its business environment, making cross-border enforcement cooperation particularly important.

Data Protection Authority

Key Enforcement Focus Areas in Netherlands

  • Government and public sector data processing
  • Automated decision-making and algorithmic bias
  • Cross-border enforcement cooperation
  • Surveillance and tracking technology
  • Data breach notification compliance

Notable Enforcement Actions in Netherlands

Clearview AI

€30,500,000(2024)

Illegal facial recognition database built by scraping photos from the internet without consent

Uber Technologies

€10,000,000(2024)

Failing to adequately inform EU drivers about data retention and international transfers to the US

Dutch Tax Authority (Belastingdienst)

€3,700,000(2022)

Discriminatory processing of personal data in childcare benefits system based on nationality

TikTok

€750,000(2021)

Privacy information for Dutch children provided only in English, violating transparency requirements

Check Your Compliance Status

Take our free assessment to evaluate your organisation's compliance posture. Get a personalised report with actionable recommendations in minutes — no sign-up required.

Start Free Assessment

Disclaimer: The information on this page is for educational purposes and does not constitute legal advice. For specific compliance guidance, consult a qualified legal professional in your jurisdiction.

Other Regulations Affecting Netherlands