Skip to content

Evidence request lists

Netherlands GDPR Implementation Act (UAVG - Uitvoeringswet AVG, 2018)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Accountability

UAVG-6
Records of Processing, DPIA, and Security of Processing

Maintain Records of Processing Activities (Verwerkingsregister) per GDPR Article 30. Conduct Data Protection Impact Assessments (DPIA / Gegevensbeschermingseffectbeoordeling DPIA) for high-risk processing per GDPR Article 35 + AP DPIA list (publication October 2018 + revisions including biometric processing + employee monitoring + healthcare processing + connected vehicles). Consult AP for prior consultation per GDPR Article 36 where DPIA indicates high residual risk. Implement security of processing per GDPR Article 32 + AP Cybersecurity guidance (Richtsnoeren).

Artefacts an auditor will ask for
  • Verwerkingsregister with all GDPR Art 30 elements
  • DPIA register
  • AP prior consultation requests (where applicable)
  • Security of processing measures
  • Annual review and updates
  • Penetration testing
Where this commonly fails
  • Incomplete Verwerkingsregister
  • Missing DPIAs
  • No prior consultation despite high risk
  • Inadequate security measures

Breach and Transfers

UAVG-7
Personal Data Breaches and International Transfers

Notify Autoriteit Persoonsgegevens (AP) of personal data breaches per GDPR Article 33 within 72 hours via online breach notification portal (Datalek Meldformulier). Notify affected data subjects per GDPR Article 34 where high risk. Document all breaches in internal register per GDPR Article 33(5). Conduct international data transfers per GDPR Chapter V using adequacy decisions + 2021 EU Standard Contractual Clauses + Binding Corporate Rules approved by AP + Schrems II Transfer Impact Assessments + EU-US Data Privacy Framework (where applicable). UAVG Article 41 provides additional national export restrictions for specific data categories.

Artefacts an auditor will ask for
  • AP breach notification template
  • 72-hour notification capability
  • Internal breach register
  • Transfer mechanism inventory
  • Schrems II TIA register
  • 2021 SCCs with annexes
  • BCR approval evidence
Where this commonly fails
  • Late AP notification
  • Missing breach register
  • Outdated SCCs
  • No Schrems II TIA

Lawful Basis

UAVG-2
Lawful Basis for Processing under National Provisions

Establish lawful basis per GDPR Article 6(1) supplemented by UAVG national provisions including: UAVG Article 22 (processing of national identification numbers limited to specific purposes), UAVG Article 30 (processing of special categories with consent or specific national grounds), UAVG Article 31 (processing of criminal conviction data), UAVG Article 32 (processing for journalistic + academic + artistic + literary purposes). Document the specific lawful basis at processing-activity level with reference to both GDPR and UAVG provisions.

Artefacts an auditor will ask for
  • Lawful basis matrix per processing activity
  • UAVG Article 22/30/31/32 application records
  • Public interest task documentation
  • Consent records where applicable
  • Annual lawful basis review
Where this commonly fails
  • No UAVG Article references
  • Mixing lawful bases
  • Inadequate public interest documentation
  • Stale lawful basis matrix

Rights and DPO

UAVG-5
Data Subject Rights and Data Protection Officer

Honour data subject rights per GDPR Articles 12-22 supplemented by UAVG provisions on: right of access (Art 15 + UAVG Article 35), rectification (Art 16), erasure right to be forgotten (Art 17), restriction (Art 18), portability (Art 20), objection (Art 21), and rights related to automated decision-making (Art 22). Respond within one month (extendable by two months for complex requests). Appoint Data Protection Officer (DPO/FG Functionaris voor Gegevensbescherming) where required per GDPR Article 37 + UAVG Article 36 supplements. Notify AP of DPO appointment via online portal.

Artefacts an auditor will ask for
  • Data subject rights procedure
  • Rights request log with response times
  • DPO appointment evidence
  • AP notification of DPO
  • DPO independence assurance
  • FG (DPO) annual report
Where this commonly fails
  • Late responses
  • No DPO where required
  • Missing AP DPO notification
  • No FG annual report

Scope and Lex Specialis

UAVG-1
UAVG Scope and Relationship to GDPR

Comply with the Uitvoeringswet Algemene verordening gegevensbescherming (UAVG) effective 25 May 2018 as Dutch national implementation of EU GDPR Regulation 2016/679. Apply UAVG as lex specialis where the GDPR opening clauses (Articles 6(2) + 6(3) + 9(2)(b)(g)(h)(i)(j) + 88) permit national derogations. Reference Dutch Constitution Article 10 (right to privacy) + Article 13 (correspondence secrecy) + Wet Politiegegevens (Wpg) for law enforcement processing + Wet justitiele en strafvorderlijke gegevens (Wjsg) for judicial processing.

Artefacts an auditor will ask for
  • UAVG applicability analysis
  • GDPR + UAVG cross-walk
  • Dutch Constitution Art 10/13 reference
  • Wpg + Wjsg applicability for LE/judicial processing
  • Annual UAVG review
Where this commonly fails
  • No UAVG analysis
  • GDPR-only reliance ignoring UAVG
  • Missing constitutional anchor
  • No Wpg/Wjsg consideration

Sensitive Data and BSN

UAVG-3
Processing of National Identification Numbers (BSN) and Sensitive Categories

Process Burgerservicenummer (BSN) Dutch citizen service number only where explicitly required by Dutch law per UAVG Article 46 + Algemene wet bestuursrecht (Awb). Apply enhanced protections for special categories per GDPR Article 9 + UAVG Articles 22 to 30 including racial/ethnic origin + political opinions + religious or philosophical beliefs + trade union membership + genetic data + biometric data + health data + sex life + sexual orientation. Maintain registers of BSN use cases with legal basis citation.

Artefacts an auditor will ask for
  • BSN authorisation per process
  • UAVG Article 46 compliance evidence
  • Special category processing register
  • UAVG Article 22-30 application records
  • BSN/sensitive data review
Where this commonly fails
  • Unauthorised BSN use
  • Missing special category evidence
  • No UAVG Article 46 reference
  • Stale BSN register

Supervision and Enforcement

UAVG-8
AP Supervision, Enforcement, and Class Actions

Cooperate with Autoriteit Persoonsgegevens (AP) supervisory authority + Chair Aleid Wolfsen (succeeded by future chairs) + headquartered in The Hague. Respond to AP inquiries + audits + investigations. Acknowledge administrative fines per GDPR Article 83 (up to EUR 20 million or 4% global turnover) + UAVG Article 19 administrative fines for UAVG-specific violations. Acknowledge criminal penalties per UAVG Article 48 for serious violations. Engage with class actions (massaschadeclaims) per Wet afwikkeling massaschade in collectieve actie (WAMCA) 2020 which expanded class action availability for GDPR/UAVG damages.

Artefacts an auditor will ask for
  • AP inquiry response procedures
  • Audit cooperation evidence
  • Administrative fine register
  • Compliance attestation
  • WAMCA class action risk assessment
  • Insurance coverage for GDPR/UAVG
Where this commonly fails
  • No AP cooperation procedures
  • Missing audit readiness
  • No WAMCA assessment
  • Inadequate insurance

Vulnerable Categories

UAVG-4
Processing of Criminal Convictions, Childrens Data, and Employee Data

Process criminal conviction data per UAVG Article 31 only where authorised by Dutch national law + with appropriate safeguards. Process children personal data per GDPR Article 8 with parental consent for children under 16 in Netherlands (UAVG Article 5 confirms 16 threshold rather than lower limit). Process employee data per UAVG Article 27 with workplace privacy considerations + Works Council (Ondernemingsraad) consultation for monitoring under Wet op de ondernemingsraden (WOR).

Artefacts an auditor will ask for
  • Criminal conviction processing authorisation
  • Parental consent records (under 16)
  • Works Council consultation minutes
  • Employee monitoring policies
  • Workplace privacy impact assessments
Where this commonly fails
  • No criminal conviction authorisation
  • Below 16 without parental consent
  • No Works Council consultation
  • Missing workplace PIAs
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.