NLEN
Home Knowledge Base ISO 27001 NIS2 DORA ISO 42001 ISO 27701 GDPR Web Pentest AI & LLM Security AI Governance GRC Platform About Careers Contact vCISO Netherlands DPO-as-a-service NIS2 Healthcare NEN 7510 Healthcare NIS2 Manufacturing NIS2 Accounting Case Studies ISO 27001 Pillar NIS2 Pillar DORA Pillar vs IRM360 vs Vanta vs Drata

GDPR Compliance Consultant for SMEs

As privacy experts we provide full GDPR compliance and DPO support: from Chief Data Protection Officer role as a service to advisory services on Data Protection Impact Assessment, processor agreements and data breaches. DPO support is scalable by company size.

GDPR compliance is more than maintaining a Processing Register. It means you can demonstrate every day how personal data is processed, secured and protected. The Dutch Data Protection Authority imposed fines totalling over €14 million in 2024 — on organisations that thought they had it under control. We conduct Privacy Impact Assessments, set up your Processing Register and provide support with data breach procedures.

GDPR compliance

On this page we discuss GDPR Compliance for Dutch organisations in detail — all relevant aspects are covered below.

Privacy Documents

Our privacy statement explains which personal data we collect, why, how long we retain it and what rights you have.

Privacy Policy — NL (PDF) Privacy Statement — EN (PDF)

GDPR — The Essentials

The General Data Protection Regulation (GDPR) is enforceable throughout the EU and applies to every organisation that processes personal data of EU residents. The Dutch Data Protection Authority (AP) actively enforces the regulation and can impose fines up to €20 million or 4% of global annual turnover. GDPR compliance is not a one-time project but an ongoing process. It requires governance, documentation, awareness and technical measures — embedded in your organisational processes.

Core Obligations

  • Processing Register: Documentation of all personal data processing activities — purpose, legal basis, retention periods and parties involved
  • Lawful basis: Every processing activity must have a valid legal basis (consent, contract, legal obligation, vital interest, public task or legitimate interest)
  • DPIA: Data Protection Impact Assessment required for high-risk processing activities
  • Data breach procedure: Notification to the Authority within 72 hours; notification to affected individuals if high risk
  • Processor agreements: Contractual safeguards for every external processor
  • Data subject rights: Processes for access, rectification, erasure and data portability

Our Approach

  • Privacy audit: Inventory of all personal data processing activities and assessment of current compliance status
  • Documentation: Creating or improving Processing Register, privacy policy, data breach procedure and processor agreements
  • DPIAs: Conducting Data Protection Impact Assessments for high-risk processing activities
  • Awareness: Training your employees on GDPR requirements and data breach recognition
  • Integration: Embedding privacy safeguards in your processes and systems (Privacy by Design & Default)

Relationship with ISO 27001 and ISO 27701

A certified ISO 27001 Information Security Management System covers a large portion of the technical and organisational GDPR security requirements. ISO 27701 adds the privacy-specific layer. We ensure that information security and privacy management function as a single integrated system.

GDPR demonstrably compliant?

Plan a consultation on your GDPR compliance. We audit your processing activities, create documentation and embed privacy systematically in your organisation.

Free Consultation

Knowledge Base: GDPR