The GDPR has been in force since 2018, but enforcement has changed considerably. The Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, has moved from guidance to fines, and the cases now reaching businesses are not exotic. They are cookie banners, unclear privacy statements, and data kept far longer than necessary.
This article covers what actually applies to a normal Dutch business website in 2026, what the regulator is looking at, and how to bring a site into line without hiring a legal department.
The Dutch layer on top of the GDPR
Two things frequently surprise business owners.
First, the GDPR is implemented in the Netherlands through the AVG, the Algemene Verordening Gegevensbescherming. In practice the requirements are the GDPR’s, but Dutch guidance and enforcement come from the Autoriteit Persoonsgegevens, and their published positions matter.
Second, cookies are governed not only by the GDPR but by article 11.7a of the Telecommunicatiewet. That article is why you need consent before placing non-essential cookies, and it applies regardless of whether the cookie processes personal data.
Cookie banners: where most sites fail
Cookie consent is the most common compliance failure precisely because so many businesses installed a banner years ago and assumed the matter was settled. The regulator’s expectations have tightened since.
A compliant banner in 2026 needs to meet several conditions at once:
- Refusing must be as easy as accepting. A prominent “Accept all” button next to a faint “Manage preferences” link is the single most cited problem. Refusal should be one click, at the same level of prominence.
- Nothing non-essential fires before consent. Many banners are decorative: the analytics script has already loaded by the time the visitor sees the question. This is the failure that is easiest to detect and hardest to defend.
- Consent is specific. Visitors should be able to accept analytics while refusing marketing, rather than facing a single all-or-nothing switch.
- Consent can be withdrawn. There must be a way to change your mind later that is as accessible as the original banner.
- No pre-ticked boxes and no implied consent. “By continuing to browse you agree” has not been valid for years.
How to check your own site: open it in a private browser window, refuse all cookies, then look at the cookies your browser has stored. If anything beyond strictly necessary cookies is present, your banner is decorative.
Website forms and lawful basis
Every form that collects a name, email address, or phone number is processing personal data, and you need a lawful basis for it.
For a contact or quote form, that basis is usually legitimate interest or steps taken prior to entering a contract. You do not need a consent checkbox to reply to someone who asked you a question. Adding one is a common and harmless mistake, but it is not the requirement people assume.
What you do need is separate consent for anything beyond answering the enquiry. Adding someone to your newsletter because they requested a quote is not permitted. That requires its own unticked checkbox with its own clear wording.
You also need to tell people, at the point of collection, what happens to their data. A short line next to the form linking to your privacy statement is sufficient.
What your privacy statement must actually say
A privacy statement is not a formality, and copying a competitor’s is a poor idea because it will describe their processing rather than yours. At minimum it should cover:
- Who you are, with real contact details and your KVK number
- What personal data you collect, in concrete terms
- Why you collect it and the lawful basis for each purpose
- Who else receives it: hosting, email, analytics, payment providers
- Whether data leaves the EU, and what safeguards apply
- How long you keep it, with actual periods rather than “as long as necessary”
- The visitor’s rights, and how to exercise them
- The right to complain to the Autoriteit Persoonsgegevens
Write it in plain language. A statement that is technically complete but incomprehensible does not meet the transparency requirement, and the regulator has said so repeatedly.
Processors, and the agreements you probably lack
Anyone who handles personal data on your behalf is a processor, and you need a processing agreement with each of them. In a typical small business website that list includes your hosting provider, your email service, your analytics tool, your newsletter platform, your payment provider, and your web agency.
Most reputable suppliers publish a standard agreement you can accept in their dashboard. The work is not negotiating them, it is knowing which ones you have. Make a list of every service that touches customer data and check each one. Businesses are routinely surprised by what is on that list.
Data transfers outside the EU
This is where a lot of otherwise careful websites quietly fail, usually through embedded content.
Loading fonts from an external service transmits your visitor’s IP address to that provider. Embedding a video player, a map, or a social feed does the same, and typically sets cookies as well. A German court decision on externally loaded fonts made this concrete, and the reasoning applies across the EU.
The fix is straightforward: host fonts on your own server, and load embedded third-party content only after the visitor has consented to the relevant category. Our own site uses self-hosted fonts for exactly this reason.
Retention: the requirement nobody enjoys
You may not keep personal data indefinitely because it might be useful one day. Every category needs a defined period and a way of actually deleting it.
Reasonable starting points for a service business: quote requests that did not convert, two years; customer records, seven years where Dutch tax law requires it; newsletter subscribers, until they unsubscribe plus a short grace period; website analytics, twenty-six months or less.
The important part is that deletion actually happens. A retention policy that exists only in the privacy statement is worse than none, because it documents a rule you are visibly breaking.
Frequently asked questions
We are a small company. Does this really apply to us?
Yes. The GDPR has no small-business exemption. Company size affects some record-keeping obligations, but the core requirements around consent, transparency, and lawful basis apply to a two-person business exactly as they do to a multinational.
What are the realistic consequences of ignoring it?
Headline fines are reserved for serious cases, but they are not the common outcome. What actually happens is a complaint from a visitor or a competitor, followed by questions from the regulator, followed by a period of consuming and expensive remediation. There is also the commercial cost: business customers increasingly ask about data handling during procurement, and a weak answer costs contracts.
Do we need a Data Protection Officer?
Most small and medium businesses do not. A DPO is required if you are a public body, if your core activity involves large-scale systematic monitoring, or if you process special categories of data at scale. A normal service business with a website and a customer database usually falls outside this.
Can our web agency handle this for us?
An agency can implement the technical side properly: a genuinely compliant consent mechanism, self-hosted fonts, gated embeds, secure forms, EU hosting. What an agency cannot do is decide your retention periods or replace legal advice on your specific processing. We build the technical foundation correctly and tell you plainly where you need a lawyer.
A practical starting point
You do not need to solve everything at once. In order of impact: fix the cookie banner so refusal genuinely blocks non-essential cookies, rewrite the privacy statement so it describes what you actually do, list your processors and collect the agreements, remove third-party embeds that load before consent, and write down your retention periods.
Every website we build includes GDPR foundations as standard rather than as an extra. You can see what that covers on our business website page, read our own privacy statement and cookie policy as working examples, or ask us to look at where your current site stands.
This article is general information, not legal advice. For questions specific to your processing, consult a lawyer specializing in privacy law.