Social Domain

Privacy in the social domain

Lawyers and legal experts for GDPR in the social domain

Municipalities process a great deal of sensitive data in the social domain. Our lawyers and in-house counsel help you organize this processing lawfully, securely, and humanely.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner

What we do

Municipalities are responsible for carrying out tasks in the social domain. These
tasks relate to the Youth Act, the Social Assistance Act (Wmo), the Participation Act, the Municipal Debt Assistance Act, and the Appropriate Education Act. To this end, municipalities process a large amount of data. This includes sensitive data, such as medical and criminal records. This entails a privacy risk.

Municipalities carry out their tasks in the social domain in various ways and collaborate with different organizations. This new way of working creates new privacy risks.

The importance of privacy in the social sphere lies in guaranteeing free access to basic services. The threshold for asking for help must not be too high. Maintaining trust in the government and assistance is a fundamental prerequisite.

Questions regarding privacy? Please contact us!

Privacy in the social domain as part of the Social Domain

This page is part of our broader expertise in the Social Domain. Within the social domain, municipalities perform tasks based on the Youth Act, the Social Support Act 2015 (Wmo 2015), the Participation Act, and the Municipal Debt Assistance Act. In virtually all of these tasks, personal data is processed, often concerning vulnerable residents and frequently of a particularly sensitive nature. Consequently, privacy is not an afterthought, but a common thread running through the entire social domain. Our lawyers and in-house counsel take a look precisely from this perspective: how does assistance remain humane and effective, while data processing is demonstrably lawful?

The legal framework: GDPR, UAVG and the sector laws

The processing of personal data in the social domain is governed by the General Data Protection Regulation (GDPR) and the GDPR Implementation Act. In addition, sectoral laws contain their own provisions regarding data processing: the Youth Act (including Chapter 7), the Social Support Act 2015 (including Chapter 5), and the Participation Act. These sectoral laws often form the legal basis for processing operations that the municipality cannot simply rely on consent.

Pursuant to Article 6 of the GDPR, every processing operation requires a legal basis. In the social domain, the most commonly used legal bases are compliance with a statutory obligation (Article 6, paragraph 1, point c, GDPR) and the performance of a task in the public interest or the exercise of public authority (Article 6, paragraph 1, point e, GDPR). As a rule, the Municipal Executive is the controller. Whether you are a municipality, a care provider, a welfare organisation, or an entrepreneur collaborating with the municipality: determining the correct legal basis is the first step we take with you.

Special personal data: medical and criminal data

In the social domain, special categories of personal data are regularly processed, such as health data and data of a criminal nature. Under Article 9 of the GDPR, there is a prohibition on the processing of special categories of personal data, which may only be overridden if a specific exception applies. Criminal data are subject to a separate regime in Article 10 of the GDPR and the UAVG. For youth care, debt assistance, and Wmo customized provisions, this means that the municipality must provide extra due substantiation as to why and how this sensitive data is processed. Our legal experts assess whether such a ground for exception actually exists, as this is where things often go wrong in practice. See also our expertise on GDPR in healthcare.

Purpose limitation and data minimization: need to know, not nice to know

Two GDPR principles clash most sharply with the practice of integrated working in the social domain: purpose limitation and data minimization (Article 5 GDPR). Purpose limitation means that data collected for one purpose may not simply be used for another purpose. Sharing between domains or neighborhood teams therefore requires a renewed assessment of the legal basis and purpose in each case. Data minimization means that only those data that are necessary are processed: the distinction between ' need to know' and 'nice to know'. We help organizations make this principle concrete based on subsidiarity (the least intrusive route), proportionality (the means fit the end), and effectiveness.

Data sharing in neighborhood teams and partnerships

Municipalities collaborate with care providers, welfare organizations, the education sector, and sometimes the police and the justice system. It is precisely this collaboration that creates new privacy risks. A common misconception is that the GDPR prohibits data sharing; however, the Dutch Data Protection Authority emphasizes that sharing is often permitted under certain conditions, provided the legal basis is correct and the purpose of the sharing is concrete. Importantly, during intake and referral, consent is usually not a valid legal basis, because the resident does not feel free to refuse when dealing with the government. Working with anonymous case discussions, a clear division of roles (which "hat" the professional wears), and sound agreements in a covenant or cooperation agreement are therefore the right approach. To formalize agreements with data processors, we draft a comprehensive data processing agreement .

DPIA, DPO, data breaches and the rights of residents

Processing activities in the social domain are often large-scale and involve special categories of personal data; consequently, a Data Protection Impact Assessment (DPIA) pursuant to Article 35 of the GDPR is frequently required before a new system or work process is put into use. As a public authority, municipalities are required to appoint a Data Protection Officer (DPO) (Article 37 of the GDPR). If things do go wrong, the rules regarding data breaches apply : notification to the Dutch Data Protection Authority within 72 hours (Article 33 of the GDPR) and, in cases of high risk, also to the data subjects (Article 34 of the GDPR). Furthermore, residents have rights such as access, rectification, and erasure (Articles 15 to 22 of the GDPR), which in the social domain sometimes conflict with record-keeping obligations under sector-specific laws.

Supervision, enforcement and objection

The Dutch Data Protection Authority exercises supervision and can impose fines and orders subject to a penalty payment; it previously warned municipalities that they collect too much personal data in the implementation of the Social Support Act (Wmo) and the Youth Act. In addition, much decision-making in the social domain takes place via administrative law: objections and appeals are available against decisions regarding provisions, up to and including the Central Appeals Board. Privacy and administrative law intersect here. Our lawyers assist municipalities as well as residents and businesses in enforcement processes and proceedings. See also our expertise regarding the Dutch Data Protection Authority and our broad expertise in privacy and data protection.

What MKB Juristen does for you

MKB Juristen works with mixed teams of lawyers and in-house counsel. This means you can turn to us at all levels: from strategic advice and litigation to the practical structuring of work processes and drafting agreements. We serve the entire spectrum, from an international corporation collaborating with government bodies to the baker on the corner dealing with a municipal regulation. Specifically, we assist with: determining the correct legal basis, drafting and reviewing DPIAs, privacy protocols, covenants, and data processing agreements, setting up secure data sharing in neighborhood teams, handling data breaches and access requests, and conducting proceedings during supervision or objections.

Frequently asked questions about privacy in the social domain

May a municipality share personal data between neighborhood teams?
Yes, it may, but not automatically. Each time, it must be assessed whether there is a valid legal basis and whether sharing is necessary for a specific purpose. Purpose limitation and data minimization take precedence.

Is consent the appropriate legal basis in the social domain?
Usually not. Because residents do not feel free to refuse the government, consent is often not a valid legal basis during intake and referral. A statutory task or legal obligation is more appropriate in such cases.

When is a DPIA mandatory?
For processing activities involving a high privacy risk, such as large-scale processing of special categories of personal data. This is often the case in the social domain, meaning that a DPIA is regularly required pursuant to Article 35 of the GDPR.

What should I do in the event of a data breach?
Assess the risk, document the breach, and report it to the Dutch Data Protection Authority within 72 hours if necessary. In cases of high risk, the data subjects must also be informed. We guide you through this process.

Contact us

Do you have questions about privacy in the social domain, or would you like to have your data processing reviewed? Our lawyers and in-house counsel are happy to assist you, drawing on our expertise in the Social Domain. Please feel free to contact us for an initial, no-obligation consultation.

Mr. Jaime Boogaers
Mr. Jaime Boogaers
Corporate Law · Lawyer

In specialized legal cases, it is not just about the legal rule. It is also about evidence, timing, negotiating position, and the business implications of every step.

Our services

We support you at every level, from strategic advice to practical implementation.

  • Determining the correct GDPR legal basis
  • Drafting and assessing DPIAs
  • Drafting privacy protocols and covenants
  • Drafting and reviewing Data Processing Agreements
  • Setting up secure data sharing in neighborhood teams
  • Handling data breaches and access requests
  • Litigation regarding supervision, enforcement, and objection

Risks and pitfalls

Privacy is often an afterthought in the social domain, even though a great deal of special personal data is processed. The biggest pitfalls lie in the legal basis and in unnecessary data sharing.

  • Wrongly using consent as a legal basis
  • Collecting too much data (nice to know instead of need to know)
  • Sharing data between domains without a renewed goal test
  • Omit the DPIA for high-risk processing
  • Reporting data breaches too late or not at all

Our approach

We combine privacy law with knowledge of sector-specific laws and administrative law. This ensures that assistance remains effective and humane, while data processing is demonstrably lawful. Thanks to mixed teams of lawyers and in-house counsel, you can turn to us for both advice and litigation.

This is how we work

From initial assessment to a workable, GDPR-compliant setup.

01

Intake and initial assessment

We will briefly discuss the situation, the available documents, and your primary interests.

02

Analysis of position and risks

We assess your legal position, supporting documents, deadlines, and possible next steps.

03

Strategic advice

You will receive concrete advice on the best course of action: responding, negotiating, settling, or litigating.

04

Execution

We assist with correspondence, negotiation, litigation strategy, or further legal assistance.

Specialists for entrepreneurs

We combine legal analysis with practical experience in cases for entrepreneurs, directors, and organizations.

All our legal experts and lawyers possess broad legal knowledge in the fields of healthcare, youth, employment, participation, education, asylum, culture, and sports. In addition, they have specialized in one or more areas of law within the social domain. We have organized several areas of focus into different practice groups. Each lawyer is part of one or more practice groups based on his or her specialism(s). Clients can go directly to the appropriate practice group for each case. Here, they are assisted by the lawyer or legal expert most suitable for the case. Where necessary, we draw upon the expertise and experience of our specialist colleagues from other practice groups.

Frequently Asked Questions

The questions we receive most often about privacy in the social domain.

When is legal advice advisable?

Legal advice is wise as soon as pressure arises, deadlines are running, an opposing party takes a position, or when the financial or strategic interests are significant.

Can MKB Juristen also help if there is already a conflict?

Yes. We assess your legal position, advise on strategy, and can assist with correspondence, negotiation, defense, or further legal steps.

How much does specialist legal advice cost?

Specialist advice is provided on an hourly basis in principle. Where possible, we provide clarity in advance regarding the expected approach, costs, and next steps.

Can I have a no-obligation consultation first?

Yes. You can request a free consultation. We will briefly discuss your situation and indicate which course of action is likely the sensible one.

Questions about privacy in the social domain?

Our lawyers and in-house counsel are happy to think along with you. Please contact us for a no-obligation initial consultation.

Contact us

Contact us

Leave your details. We will contact you to briefly discuss your situation.

Contact us

Jaime Boogaers

Want to know more about our services?
Then contact our specialists.

Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation