MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
A privacy statement is mandatory for every website or service that processes personal data under the GDPR. Content: who processes which data, for what purposes, how long it is stored, with whom it is shared, and what the rights of data subjects are. In case of non-compliance: a fine by the Dutch Data Protection Authority of up to 4% of global turnover (or €20 million). Almost always mandatory for SMEs — even a simple contact form requires a privacy statement. Below are the legal requirements, template structure, and pitfalls.
The short answer
- What: Mandatory declaration for websites/services that process personal data.
- Legal basis: Art. 13-14 GDPR.
- Mandatory content: identity of processor, purposes, legal basis, retention periods, rights of data subject.
- Location: easily found on website (footer link).
- Sanctions: AP fine of up to 4% of global turnover or €20 million.
What should it contain?
- Identity of data controller: BV name, address, contact.
- Purposes of processing: e.g. customer service, marketing, account management.
- Legal basis: consent, contract, legitimate interest, statutory obligation.
- Categories of personal data: name, address, and place of residence, email, payment details, etc.
- Recipients: with whom data is shared (processors, partners).
- Retention periods: how long per category of data.
- Rights of data subjects: access, rectification, deletion, objection, data portability.
- DPA complaint procedure: link to the Dutch Data Protection Authority.
- Data Protection Officer (DPO): contact if available.
- Automated decision-making and profiling: if applicable.
- Transfer outside the EU: if applicable, with safeguards.
Placement and findability
The privacy statement must be “easy to find”:
- Link in website footer (general section).
- Link in forms where data is entered.
- Link in account settings.
- Text in readable Dutch (no legal jargon).
Plus cookie notification on homepage for cookies and tracking.
Cookies and privacy statement
Cookies require separate consent (cookie notification) plus mention in the privacy statement. Distinction:
- Functional cookies: necessary for operation — no consent required.
- Analytical cookies: consent required (anonymous, privacy-friendly, often exempt).
- Marketing/tracking cookies: explicit opt-in required.
Cookiebot, Onetrust, and CookieFirst are standard cookie tools for compliance.
Legal foundations
Under the GDPR, you can process personal data on six legal grounds:
- Consent: explicit, freely given, revocable.
- Contract: required for execution of customer agreement.
- Statutory obligation: e.g. accounting obligation.
- Legitimate interest: after balancing of interests — often used for marketing.
- Vital interest: life or safety — rarely applicable.
- Public interest: for government tasks.
Specify the legal basis for each processing operation.
Common pitfalls
- Too general: “for various purposes” — not specific enough.
- No retention periods: the AP wants concrete periods per category.
- Forgot cookies: separate cookie statement or full statement.
- Outdated: not updated after changes to services or partners.
- English template: translation not adapted to Dutch practice.
- No data processing agreements:hoster, marketing tool, payment provider — all “processors” that require a contract.
In the event of a data breach
The privacy statement must explain what the customer can expect in the event of a data breach — notification obligation (72 hours to the Dutch Data Protection Authority), and potential communication to data subjects. See data breach.
Honest recommendation
For SMEs with a website or customer data: privacy statement mandatory — not optional. Start with a template (Chamber of Commerce, NLdigital), adapt to the specific situation. For more complex situations (e-commerce, app, international presence): draft or review GDPR legal expert (€500-€2,500). Update with every change in services. Combine with a cookie tool and data processing agreements for a complete compliance package.
For other topics: data breach, UBO declaration and cyber insurance.
Frequently Asked Questions
Mandatory statement (Art. 13-14 GDPR) for websites and services that process personal data. Contains information about which data, for what purposes, for how long, and what the rights of data subjects are.
Almost always for SME limited companies. Even a simple contact form processes personal data (email) — privacy statement mandatory. Exceptions are very limited (purely B2B business without customer contact).
Identity of processor, purposes, legal basis, categories of data, recipients, retention periods, rights of the data subject, right to lodge a complaint with the Dutch Data Protection Authority (AP), and possibly the Data Protection Officer (DPO), automated decision-making, transfer outside the EU.
The Dutch Data Protection Authority can impose fines of up to 4% of global turnover or €20 million (whichever is higher). In practice, for SMEs, this is often €10,000–€250,000 for serious violations.
Cookies require separate consent (cookie notification) plus mention in the privacy statement. Functional: no consent. Analytical: often yes. Marketing/tracking: explicit opt-in required.
Six under the GDPR: consent, contract, statutory obligation, legitimate interest, vital interest, public interest. Specify the legal basis for each processing activity — not generically “all applicable”.
With every change in processing: new partner, new service, different retention period, new processor location (within/outside the EU). Plus an annual review for up-to-date status.