country: Netherlands framework: GDPR region: EU language: nl version: 2024-06 status: published last_updated: 2025-06-30 source_verified: true authority: Autoriteit Persoonsgegevens (Dutch DPA) notes: - The Netherlands enforces GDPR directly and supplements it with the Uitvoeringswet Algemene verordening gegevensbescherming (UAVG). - The Dutch DPA provides extensive sectoral guidance, particularly in healthcare, education, and employee data use. categories: - name: Full Name type: direct_identifier subtype: personal_name required_masking: true tags: - pii citations: - regulation: GDPR article: 4(1) category_tags: - core - identity - name: Email Address type: direct_identifier subtype: digital_contact required_masking: true tags: - pii citations: - regulation: GDPR article: 4(1) category_tags: - core - contact - name: Phone Number type: direct_identifier subtype: telecom_contact required_masking: true tags: - pii citations: - regulation: GDPR article: 4(1) category_tags: - core - contact - name: IP Address type: indirect_identifier subtype: network_identifier required_masking: true tags: - tracking citations: - regulation: GDPR recital: '30' - authority: Autoriteit Persoonsgegevens guideline: Cookies en andere trackingtechnologieën url: https://autoriteitpersoonsgegevens.nl/nl/onderwerpen/internet-telefoon-tv-en-post/cookies category_tags: - digital - behavioral - name: BSN (Burgerservicenummer / Dutch Citizen Service Number) type: national_identifier subtype: government_id required_masking: true tags: - pii - national_id - government_id citations: - regulation: GDPR article: '87' - national_law: UAVG article: '46' description: Restricts processing of the BSN to lawful contexts such as government and healthcare category_tags: - identity - sensitive - name: Health Data (diagnoses, lab results, medical history) type: special_category subtype: health required_masking: true tags: - phi - sensitive citations: - regulation: GDPR article: 9(1) - authority: Autoriteit Persoonsgegevens guideline: Gezondheidsgegevens url: https://autoriteitpersoonsgegevens.nl/nl/onderwerpen/gezondheid/gezondheidsgegevens category_tags: - health - sensitive - name: Biometric Data (e.g., facial scans, fingerprints) type: special_category subtype: biometric required_masking: true tags: - biometric - sensitive citations: - regulation: GDPR article: 9(1) category_tags: - biometric - sensitive - name: Location Data (real-time GPS, travel history) type: behavioral subtype: geolocation required_masking: true tags: - tracking citations: - regulation: GDPR article: 4(1) description: Location data can contribute to identification of individuals category_tags: - tracking - digital - name: Cookie Identifiers / Device IDs type: indirect_identifier subtype: device_id required_masking: true tags: - tracking - online_identifier - pii citations: - regulation: GDPR recital: '30' - authority: Autoriteit Persoonsgegevens guideline: Cookies & tracking url: https://autoriteitpersoonsgegevens.nl/nl/onderwerpen/internet-telefoon-tv-en-post/cookies category_tags: - tracking - digital - name: Employment History and Records type: contextual_identifier subtype: hr_data required_masking: true tags: - pii - hr_data - employment_records citations: - regulation: GDPR article: '88' - national_law: UAVG article: '32' description: Regulates processing of personal data in the employment context category_tags: - employment - sensitive