Knowledge
GDPR (AVG) for your Dutch website.
In the Netherlands the GDPR travels under a local name: the AVG. The rules are European, the regulator is Dutch, and for your website the essentials fit on one page.
Updated 12 August 2026
The short answer
The AVG (Algemene verordening gegevensbescherming) is simply the Dutch name for the GDPR, enforced here by the Autoriteit Persoonsgegevens (AP). For a business website the practical duties are: a clear privacy statement describing what data you process and why, a lawful basis per purpose (consent, contract or legitimate interest), processor agreements with tools that handle data for you (hosting, analytics, email), consent before tracking cookies, and secure handling throughout — HTTPS included. Compact compliance is very achievable; ignoring it is the only expensive option.
What your website actually processes
More than founders expect: a contact form (names, emails), analytics (behaviour, identifiers), a newsletter signup, a booking tool, even server logs. Map these flows once and the privacy statement writes itself — per purpose: what you collect, why, how long you keep it, who processes it for you, and the rights visitors can exercise. Plain language beats legal fog; the AP itself says so, and so do your visitors.
The Dutch flavour of enforcement
The AP is an active regulator with real fining power, and Dutch consumers are privacy-aware: complaints are normal and cookie walls draw attention. The practical posture for a small business: keep the data you collect minimal, keep the statement honest and current, sign processor agreements with your main tools (most provide them as standard), and configure analytics privacy-friendly. That posture satisfies the regulator — and reads as respect to your customers.
Frequently asked questions
Do I need a privacy statement for a one-page site?
As soon as any personal data flows — a form, analytics, embedded video — yes. For a truly static page with zero data processing the duty stays dormant, but in practice almost every business site processes something.
I already have a GDPR statement from my home country — does it carry over?
The regulation is the same across the EU, so the substance largely travels. Localise the practicalities: your Dutch entity details, the AP as supervisory authority, and the actual tools and flows of this website. A carbon copy that misdescribes your processing is itself a compliance gap.
What is a processor agreement (verwerkersovereenkomst)?
The contract between you and any party processing personal data on your behalf — your host, email provider, analytics platform. Major tools offer standard agreements you accept in their dashboard; the work is mostly ticking them off knowingly and keeping the list current.
Further reading
Free advice
Shall Ovolum take a look at your website?
Ask your question — you will receive a personal, written answer within one working day. Free of charge, with full attention.