The General Data Protection Regulation (GDPR) is a European law designed to protect people's privacy. The GDPR stipulates what businesses and organisations can and cannot do with the personal data of their customers, staff and other persons. For example, you must have a good reason for processing personal data. In this overview you find examples that may occur in your business: Example: to be able to carry out an agreement. Example: to send a newsletter, you do need an email address, but not a date of birth. Example: you have requested an email address to send an invoice. You may not use that email address for marketing purposes. Example: for your business administration, you must store your data for 7 or 10 years. After that, you no longer need it. Example: what data you store, why, and for how long. Example: by securing your website with https and by updating your software. The GDPR applies to all businesses and organisations that process personal data, including freelancers and SME entrepreneurs. You must take the GDPR into account when sending a price quotation, invoice, or newsletter. But also, for example, when you hire staff. When you store employees' personal data you must follow the GDPR. Personal data is data that directly concerns someone. Or that allows you to find out who it concerns. Such as name, address, and telephone number. Processing it includes everything an organisation can do with data. Think of collecting, storing, and forwarding it. This can be done manually or automatically, for yourself or for someone else. Read more about processing and passing on personal data. Are you unsure whether you are complying with the GDPR? Or would you like to know what the GDPR entails? Follow these steps to help you comply with the GDPR. Read more about the GDPR or get informed. Do you have staff? Then involve employees who process personal data. You cannot just process personal data. You must have at least one of these 6 reasons: It is necessary to carry out an agreement. For example, you must process address details to be able to deliver your product to someone. It is necessary to fulfil a legal obligation. There is a legitimate interest. For example, you must process personal data in your personnel administration to pay salaries. You have permission from the person in question. It is necessary to protect someone's life or health and you cannot ask that person for permission. It is necessary to perform a task in the public interest. Read more about the different reasons (in Dutch). Your customers have many rights when it comes to privacy. You must ensure that they can easily exercise these rights. For example, your customers may: view, modify, and delete their data restrict and withdraw consent they have previously given request their data so that they can easily switch to another business; this is called the right to data portability Your customers may file a complaint with the Dutch Data Protection Authority (DPA). The DPA is obliged to process these complaints. Record in a processing register which personal data you process and why. Make it clear where this data comes from and with whom you share it. In the register, you also record the date after which you must delete the data. You use the register when customers ask you to change or delete their data. You must also pass this on to the organisations with whom you have shared the data. This register falls under the so-called accountability principle. You must always be able to explain how you handle data. Do not process more personal data in your products or services than is necessary. This is also called ‘privacy by default’. Examples of this are: Do not allow an app to register the location of users without good reason. On your website, do not pre-check the box ‘yes, I want to receive offers’. When subscribing to a newsletter, do not ask for more data than is necessary. If you are designing new products or services, make sure that personal data is properly protected in the design phase. This is known as ‘privacy by design’. The GDPR states that you must properly secure the personal data you hold. However, personal data can get out without this being intentional. This is called a data breach. Examples of data leaks are: You lose a laptop, tablet, USB stick or paper with unencrypted personal data on it. You email personal data to the wrong person. The personal data you are processing is stolen in a cyberattack. Your system is infected with ransomware,making the personal data no longer accessible. You must report all data breaches immediately to the Dutch Data Protection Authority, DPA. You must also document all data breaches, including internal leaks that you do not have to report. Check the DPA website to see which data breaches you must report. You should only inform the persons whose personal data has been breached if the data breach has serious consequences for their rights and freedoms. Do you process privacy-sensitive data for your clients? Then you must report all data breaches to them so they can report them to the DPA. Do you work with businesses that process personal data on your behalf and according to your instructions? If so, make sure you have a processing agreement with them. This also applies if the processor is a subsidiary or is based abroad. An external helpdesk viewing your company’s personal data is already considered a form of processing. Do you process data that carries a high privacy risk? If so, you must conduct a Data Protection Impact Assessment (DPIA). This is an extensive investigation to identify the risks of data processing. Based on this DPIA, you can take measures to reduce the privacy risks. Does your company process a lot of personal data? If so, check whether you are required to appoint a data protection officer (DPO). This is someone who monitors whether you are doing everything according to the GDPR within your organisation. Your organisation may also voluntarily appoint a DPO. You are only allowed to transfer personal data to a country outside the EEA if that country observes the privacy rules. The EU has listed 14 countries as compliant. You can use this checklist for those countries. Do you want to exchange personal data with a country that is not on the list? The person processing the data in that country must make an official statement that they will process the data according to the GDPR. This is called ‘an appropriate safeguard’. You can use a model contract for this (pages 7 and onwards). Does your organisation have branch offices in non-EEA countries? You can draw up binding corporate rules on how to deal with personal data. Read more about the rules and exceptions for transferring personal data outside the EEA. Watch this video for an example of how to apply the GDPR. The video takes an e-commerce example, but gives a sense of how all entrepreneurs can think of their customer's data and privacy.What does the GDPR mean?
GDPR in practice
Who is subject to the GDPR rules?
When do you process personal data?
Steps to help you comply with the GDPR
Transferring personal data outside the EEA
Video GDPR: Privacy and personal data
How to comply with the GDPR in the Netherlands (2025)
References
- https://business.gov.nl/running-your-business/legal-matters/how-to-make-your-business-gdpr-compliant/
- https://videolab.eu/gdpr-and-hipaa-compliance/
- https://www.mondaq.com/turkey/data-protection/1584044/key-differences-between-gdpr-and-kvkk
- https://legalvision.co.uk/data-privacy-it/uk-gdpr-legislation/
- https://www.jetico.com/blog/how-right-erasure-applied-under-gdpr-complete-guide-organizational-compliance
- https://usercentrics.com/knowledge-hub/gdpr-sensitive-personal-data/
- Mysterious Blue Volcanic Goo: Scientists Discover Signs of Life in Extreme Ocean Depths
- OPPO Find X9 Series: Unlocking the Ultimate Flagship Experience with Premium Services
- Rashmika Mandanna's 'The Girlfriend' Box Office Challenge: Will It Pass the Weekday Test?
- AI Revolutionizes Fast Radio Burst Detection: 600x Faster with NVIDIA Holoscan
- Gucci Play Watch Revival: Interchangeable Bezel Fashion Icon Back in Style
- Transform Your Gut Health: 3 Affordable Veggies vs. $40 Supplements
- Mysterious Blue Volcanic Goo: Scientists Discover Signs of Life in Extreme Ocean Depths
- Bobby Deol's New Collaboration: Teaming Up with Ahaan Panday in Ali Abbas Zafar's Action Drama
- Super Typhoon Uwan: President Marcos' Swift Response to Flood Victims
- Dude: The OTT Release - A Pradeep Ranganathan & Mamitha Baiju Film
- Breaking Through Fuel Cell Barriers: A New Approach to High-Efficiency PEMFCs
- RANDOMICE Release Date Announced! - Procedural Metroidvania Exploration Gameplay
- 7 Easy Privacy Tips for a Safer Online Experience (Linux Focus)
- Tanzania Political Crisis 2025: Hundreds Charged with Treason After Disputed Elections
- UAE's Iceberg Project: What Happened to the Ambitious Plan to Tow an Antarctic Iceberg?
- Sung Si Kyung's Hiatus: Singer Thanks Fans After Manager's Embezzlement Scandal
- Bobby Deol's New Collaboration: Teaming Up with Ahaan Panday in Ali Abbas Zafar's Action Drama
- 7 Easy Privacy Tips for a Safer Online Experience (Linux Focus)
- Where is The Hangover's Stun Gun Kid Now? | Nicolas Furu's Transformation
- EastEnders Nigel Bates Court Hearing Shock: Dementia Verdict Revealed!
- Chinese Woman Pays 280x Room Rate After Flooding Hotel Over Denied Cancellation | Viral Story
- Surrealist Artist Henry Orlik's Missing Paintings: A Violation of His Life's Work
- Revolutionary Cell Levitation Breakthrough: Electro-LEV System for Cancer Treatment
- Oil and Gas Price Predictions: Will Prices Hold Amid Sanctions?
- Tragic Drowning in Dandenong Creek: Woman and Child Lose Their Lives
- UAE's Iceberg Project: What Happened to the Ambitious Plan to Tow an Antarctic Iceberg?
- US Deepens Involvement in East Med Energy & Geopolitics
- OPPO Find X9 Series: Unlocking the Ultimate Flagship Experience with Premium Services
- Unveiling China's Market Potential: Insights from the Shanghai CIIE Salon
- Hopkins Center for the Arts by Snøhetta | Iconic Performing Arts Expansion
- 7 Easy Privacy Tips for a Safer Online Experience (Linux Focus)
- Shakti Shalini Casting: Kiara Advani Rumors Debunked by Amar Kaushik
- Father Turns Grief into Hope: Writing Children's Books on Loss After Son's Cancer Battle
- Shakti Shalini Casting: Kiara Advani Rumors Debunked by Amar Kaushik
- OPPO Find X9: Elevating the Flagship Experience with Unparalleled Customer Service
- Stolen iPhones: The Global Resale Pipeline & How It Impacts You
- The UK's End-of-Life Care Crisis: A Palliative Care Specialist's Perspective
- Unveiling the Microbiome Mystery: AI's Role in Decoding Gut Bacteria Communication
- How Plastics Grip Metals: Atomic Insights for Lighter Vehicles
- Mysterious Blue Volcanic Goo: Scientists Discover Signs of Life in Extreme Ocean Depths
- Breast Cancer Awareness: ADB's Pink Ladies Soirée and Donation to Flames of Hope Foundation
- Infosys Equinox Now Available on Microsoft Marketplace | Accelerate Digital Commerce
- Tragic Drowning in Dandenong Creek: Woman and Child Lose Their Lives
- Mobile Money: The New Hub for Illegal Transactions? | FIC CEO Speaks Out
- Uncovering the Secrets of Bacterial Motion: Swashing, Gliding, and Molecular Gear-Shifting
- Tanzania Political Crisis 2025: Hundreds Charged with Treason After Disputed Elections
- Promasidor's New Group CEO: Meet Festus Tettey and His Journey to the Top
- Stock Market Reacts: Senate's Progress on Ending the Historic Shutdown
- How Plastics Grip Metals: Atomic Insights for Lighter Vehicles
- Transform Your Gut Health: 3 Affordable Veggies vs. $40 Supplements
- AI Revolutionizes Fast Radio Burst Detection: 600x Faster with NVIDIA Holoscan
- Tragic Drowning in Dandenong Creek: Woman and Child Lose Their Lives
- 7 Easy Privacy Tips for a Safer Online Experience (Linux Focus)
- Promasidor's New Group CEO: Meet Festus Tettey and His Journey to the Top
- Uncovering the Secrets of Bacterial Motion: Swashing, Gliding, and Molecular Gear-Shifting
- Tanzania Political Crisis 2025: Hundreds Charged with Treason After Disputed Elections
- BIMP-EAGA 2025: Davao City Hosts ASEAN Growth Summit
- Mysterious Blue Volcanic Goo: Scientists Discover Signs of Life in Extreme Ocean Depths
- Legal Battle: PIC's Attempt to Recover R400m BEE Lanseria Payment
- Legal Battle: PIC's Attempt to Recover R400m BEE Lanseria Payment
- Thuraya-4: Revolutionizing Satellite Communications in South Africa
- Dude: The OTT Release - A Pradeep Ranganathan & Mamitha Baiju Film
- BIMP-EAGA 2025: Davao City Hosts ASEAN Growth Summit
- BIMP-EAGA 2025: Davao City Hosts ASEAN Growth Summit
- Tragic Drowning in Dandenong Creek: Woman and Child Lose Their Lives
- Successful Sunday for Lions, Bears, Blackhawks & Pistons
- Tragic Drowning in Dandenong Creek: Woman and Child Lose Their Lives
- AI Revolutionizes Fast Radio Burst Detection: 600x Faster with NVIDIA Holoscan
- Tragic Drowning in Dandenong Creek: Woman and Child Lose Their Lives
- Bobby Deol's New Collaboration: Teaming Up with Ahaan Panday in Ali Abbas Zafar's Action Drama
- How Plastics Grip Metals: Atomic Insights for Lighter Vehicles
- Breaking Through Fuel Cell Barriers: A New Approach to High-Efficiency PEMFCs
- Rosalía’s ‘LUX’ Shatters Records: Most Streamed Album in a Day by a Spanish Female Artist on Spotify
- Father Turns Grief into Hope: Writing Children's Books on Loss After Son's Cancer Battle
- JWST's Revolutionary Discovery: Frozen Life Ingredients in a Distant Galaxy
- Bobby Deol's New Collaboration: Teaming Up with Ahaan Panday in Ali Abbas Zafar's Action Drama
- Do Planets Survive When Stars Die? Shocking Evidence Revealed!
- Lando Norris Dominates Sao Paulo GP! Stats, Records & F1 Trivia Breakdown
- Father Writes Book on Grief After Losing Son to Cancer: A Story of Hope and Healing
- Dude: The OTT Release - A Pradeep Ranganathan & Mamitha Baiju Film
- Unveiling the Microbiome Mystery: AI's Role in Decoding Gut Bacteria Communication
- UAE's Iceberg Project: What Happened to the Ambitious Plan to Tow an Antarctic Iceberg?
- Why Do We Love Spicy Food? The Science Behind the Burn!
- Super Typhoon Uwan: President Marcos' Swift Response to Flood Victims
- Tanzania Political Crisis 2025: Hundreds Charged with Treason After Disputed Elections
- Uncovering the Secrets of Bacterial Motion: Swashing, Gliding, and Molecular Gear-Shifting
- Flight Cancellations Surge: Travelers Turn to Trains, Rental Cars, and Creative Solutions
- Infosys Equinox Now Available on Microsoft Marketplace | Accelerate Digital Commerce
- Bobby Deol's New Collaboration: Teaming Up with Ahaan Panday in Ali Abbas Zafar's Action Drama
- Lab-Grown Liver Organoid: Revolutionizing Fibrosis Research
- OPPO Find X9 Series: Unlocking the Ultimate Flagship Experience with Premium Services
- Nokia Appoints Kristen Pressner as Chief People Officer: Leading the AI-Empowered Future
- Lab-Grown Liver Organoid: Revolutionizing Fibrosis Research
- Unveiling the Mystery of Odd Radio Circles (ORCs) in the Universe
- Booker Prize 2023 Favorites: Andrew Miller vs Kiran Desai - Who Wins Fiction's Top Award?
- Revolutionary Cancer Treatment: How Bacteria Are Being Engineered to Kill Tumors
- A Father's Journey: Turning Grief into Hope with 'The Bravest Little Bear'
- Brightest Black Hole Flare Ever Recorded: 10 Trillion Suns' Power Explained!
- Asteroid Mining: Future Missions, Resources, and Challenges Explained
- Pakistan's 27th Amendment: Senate Deliberations, Opposition Protests, and Military Reforms Explained
Author: Kareem Mueller DO
Last Updated:
Views: 6327
Rating: 4.6 / 5 (46 voted)
Reviews: 85% of readers found this page helpful
Name: Kareem Mueller DO
Birthday: 1997-01-04
Address: Apt. 156 12935 Runolfsdottir Mission, Greenfort, MN 74384-6749
Phone: +16704982844747
Job: Corporate Administration Planner
Hobby: Mountain biking, Jewelry making, Stone skipping, Lacemaking, Knife making, Scrapbooking, Letterboxing
Introduction: My name is Kareem Mueller DO, I am a vivacious, super, thoughtful, excited, handsome, beautiful, combative person who loves writing and wants to share my knowledge and understanding with you.