Netherlands

Nine Eyes and Maximator member meshed into Europol, Schengen and Prüm data exchange, where voters rejected mass surveillance but the government proceeded anyway and now shares less with the United States

← Back to Privacy Law Directory

Overview

EU Member State: The Netherlands is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page. This page covers national laws, intelligence and surveillance, and the Netherlands’ role in international data sharing.

Two events define the Dutch privacy story. First, the Sleepwet referendum (March 2018): a majority of Dutch voters rejected a broad surveillance law, only for the government to implement it with minor amendments. Second, the childcare benefits scandal (toeslagenaffaire): the Dutch Tax Administration used nationality as an algorithmic risk indicator to wrongly accuse ~26,000 families of fraud, causing the resignation of the entire cabinet in January 2021.[1][2]

The Netherlands operates the JSCU (Joint Sigint Cyber Unit), a joint AIVD-MIVD venture conducting bulk cable interception at AMS-IX (one of the world’s largest internet exchanges, 900+ networks, 14 Tbps peak). As a Nine Eyes and Maximator member, the Netherlands has deep intelligence-sharing ties, but in October 2025, both Dutch intelligence directors confirmed they are sharing less intelligence with the United States, citing concerns about politicisation under the current US administration.[3][4]

The Netherlands’ outward data-sharing runs through its alliances and treaties, each detailed below. Beyond the Nine Eyes and Maximator signals-intelligence alliances, it is a party to the 1959 Council of Europe Mutual Assistance Convention and the Budapest Convention on Cybercrime, belongs to the Schengen and Prüm frameworks (it was an original 2005 Prüm signatory) and to Europol (whose headquarters it hosts in The Hague), and holds bilateral mutual legal assistance treaties including one of the first modern MLATs with the United States (1981) and the Benelux Treaty with Belgium and Luxembourg, with a domestic power to assist even absent a treaty. These are the channels through which the domestic protections described below are, in practice, bypassed.

International Data Sharing Agreements

Mutual Legal Assistance: Layered Framework

EU instruments: As an EU member state, the Netherlands cooperates with the other 26 EU states through the EU Mutual Legal Assistance Convention (2000) and the European Investigation Order. It was an original Prüm Convention signatory (2005); the Prüm framework now binds 31 states (all 27 EU members plus the non-EU Schengen associates Iceland, Liechtenstein, Norway, and Switzerland) in automated DNA, fingerprint, and vehicle-data exchange, and Prüm II (2024) adds facial images and police records.[38] The Benelux Treaty on Extradition and Mutual Assistance in Criminal Matters (1962, amended 1974) adds a streamlined framework among its three members, Belgium, the Netherlands, and Luxembourg.

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): With its Additional Protocols, this Council of Europe instrument has 51 parties as of July 2026: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[35]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): The Netherlands is a party to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[36]

Bilateral MLAT with the United States: Signed June 12, 1981, the Netherlands was one of the first three countries (alongside Switzerland and Turkey) to sign a modern MLAT with the US, including defence counsel evidence access. The Netherlands has also signed “many bilateral agreements with different countries all over the world” (per the UNODC G20 MLA Guide); the complete country-by-country set is searchable in the official Dutch treaty database (Verdragenbank). AIRS (Department of International Affairs and Legal Assistance in Criminal Matters, Ministry of Justice and Security) serves as central authority, also covering the Caribbean Netherlands (Bonaire, Sint Eustatius, Saba); Aruba, Curaçao, and Sint Maarten have their own central authorities.[23]

Non-treaty cooperation: The Netherlands can execute MLA requests even without a treaty, under Dutch domestic criminal procedure code. Non-treaty requests must be sent through diplomatic channels to AIRS. Dual criminality is only required if the applicable convention so requires.

Nine Eyes Alliance and the 2025 Intelligence-Sharing Shift

The Nine Eyes comprises the Five Eyes (Australia, Canada, New Zealand, the United Kingdom, and the United States) plus Denmark, France, the Netherlands, and Norway. The JSCU is the primary vehicle for Dutch Nine Eyes participation, sharing SIGINT with the NSA, GCHQ, and other Five Eyes partners. The framework creates reciprocal bypass: NSA can collect on Dutch persons and share with AIVD/MIVD; Dutch intelligence can collect on Five Eyes persons and share back.[24]

In October 2025, AIVD Director-General Akerboom and MIVD Director Reesink confirmed the Netherlands is sharing less intelligence with the United States, redirecting cooperation toward the UK, Germany, France, Poland, and Nordic services. Reesink: “That we sometimes no longer tell certain things, that’s true.” Concerns centre on potential “politicisation” of shared intelligence. A northern European intelligence group is now exchanging more data, including raw data, driven by Russia’s war in Ukraine.[3][4]

Maximator Alliance

The Netherlands joined Maximator in 1978 (founded 1976 by Denmark, Sweden, and Germany; France joined 1985), making its five members Denmark, France, Germany, the Netherlands, and Sweden. The five-nation encryption-defeat cooperative pooled cryptanalytic effort against third-country government communications. The alliance was not publicly revealed until 2020.[25]

EU and Multilateral Frameworks

SIS II: Real-time query and alerts across the Schengen Area (29 states: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland).[37] EU-US Umbrella Agreement: Dutch citizens get judicial redress before US courts. SWIFT/TFTP: International wire transfers subject to US Treasury subpoena. PNR: Passenger data for NL-US flights. Interpol I-24/7: 195-country network. Egmont Group: FIU-Nederland shares financial intelligence across 164+ FIUs.

Europol

The Netherlands hosts Europol’s headquarters in The Hague and is one of the 27 EU members that constitute the agency (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Dutch person data flowing through Europol is reachable onward.[39]

The Privacy Backdoor Effect

Despite the Wiv 2017’s judicial authorisation requirements, CTIVD/TIB oversight, and AP GDPR enforcement, international agreements create alternative access pathways:

Club de Berne and the Counter Terrorism Group

The Netherlands’ AIVD takes part in the Club de Berne (founded 1969), the forum of the heads of the domestic intelligence and security services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland. The Club is a broad, all-source intelligence-sharing body, not a counterterrorism-specific one; its separate offshoot, the Counter Terrorism Group (CTG), created in September 2001, shares terrorism intelligence among the same services plus the United Kingdom and has run a joint operational platform in The Hague with a common database and real-time information system since 2016.[41]

Surveillance and Intelligence

Wiv 2017 and the Sleepwet Referendum

The Wiv 2017 authorises bulk interception of cable-bound communications (earning it the “Sleepwet”/dragnet nickname), extended hacking powers (including third-party device compromise), DNA collection, raw intelligence data sharing with foreign services, and expanded metadata analysis. On March 21, 2018, 49.44% of voters voted against the law (51.5% turnout), but the government proceeded with implementation, passing 2021 amendments requiring operations be “as targeted as possible,” changes critics call cosmetic.[1][9]

Temporary Cyber Operations Act (July 2024)

Expanded AIVD/MIVD capabilities for investigating countries with offensive cyber programmes. Most controversially, weakened the oversight framework by shifting from binding prior authorisation (TIB) to binding supervision during/after deployment (CTIVD) for certain powers. Former TIB member Bert Hubert publicly warned this erodes civil liberties oversight.[10][11]

Intelligence Agencies

AIVD: Civilian intelligence (domestic/foreign) and SIGINT, headquartered in Zoetermeer. MIVD: Military intelligence under Ministry of Defence. JSCU (Joint Sigint Cyber Unit, ~350 employees): joint AIVD-MIVD SIGINT organisation, the Netherlands’ primary contribution to Nine Eyes.[12]

Oversight

CTIVD: Ex post oversight with binding powers; can “walk in, pull open drawers, and log into networks.” In 2024–2025, confirmed AIVD/MIVD had recruited journalists as paid agents and reprimanded AIVD for conducting organised crime investigations outside its mandate. TIB: Ex ante binding prior authorisation for special intelligence powers (partially weakened by the Temporary Cyber Operations Act).[13][14]

Commercial Surveillance Procurement

NSO Group Pegasus

The Netherlands is a confirmed Pegasus customer. Once deployed, Pegasus provides unrestricted access to all device data, with no technical mechanism to limit collection. This creates a layered surveillance approach: bulk cable interception at scale (Wiv 2017/JSCU) combined with targeted endpoint exploitation (Pegasus) when targets use end-to-end encryption.[18]

Palantir Technologies

The Netherlands has a long-standing Palantir relationship dating to 2010 (Ministry of Defence) and 2011 (National Police, contract signed by then-Police Commissioner Henk Schoof, who became Prime Minister in 2024). Additional customers include the NCTV (National Coordinator for Security and Counterterrorism) and the Openbaar Ministerie (Public Prosecution Service). A 2023 court ruling forced partial disclosure of 45,000 procurement documents, the overwhelming majority heavily redacted or entirely blacked out. Palantir’s US corporate structure creates CLOUD Act exposure for all data processed through its platforms.[19]

Internet Infrastructure and Cable Surveillance

AMS-IX (Amsterdam Internet Exchange): one of the world’s largest IXPs, 900+ connected networks, 14 Tbps peak traffic. Also operates exchanges in Mumbai, Hong Kong, Chicago, and the Caribbean. NL-ix provides a commercial alternative. Submarine cables land at Beverwijk, Katwijk, and Zandvoort, connecting the Netherlands to the UK and beyond.[20][21]

The Wiv 2017 authorises JSCU bulk cable interception, and the Temporary Cyber Operations Act (2024) further expanded cable access for investigating state cyber threats while weakening TIB prior authorisation. AMS-IX’s massive traffic volume gives Dutch intelligence access to a significant portion of European internet traffic, a key reason the Netherlands maintains Nine Eyes membership despite its small population.[1]

Recent Developments

Intelligence-Sharing Pivot (October 2025): AIVD and MIVD directors confirmed reduced US intelligence sharing, redirecting cooperation toward European partners. A geopolitically significant development within the Nine Eyes framework.[3]

Odido Data Breach (February 2026): Potentially the largest Dutch breach in history, exposing 6.2 million customers (~one-third of population), including names, IBANs, and government ID numbers. Reporting revealed Odido retained data “much longer than claimed.”[26]

Expanded Espionage Law (May 2025): Broadened criminal definition to cover digital espionage and diaspora espionage (targeting diaspora communities for foreign states), penalties up to 8–12 years.[27]

Chat Control Opposition Strengthened: Dutch opposition to mandatory encrypted scanning under the CSA Regulation (see Encryption above) helped force the November 2025 compromise.[28]

Digital Sovereignty Push (March–December 2025): Parliament voted to move away from US cloud services and establish national cloud infrastructure. The Netherlands joined the Digital Commons EDIC (December 2025) with eight other EU states for open-source European digital infrastructure.[29]

CTIVD: Journalist Recruitment Confirmed (2024–2025): AIVD and MIVD recruited journalists as paid agents, raising serious press freedom concerns.[14]

Wiv 2017 Reform Discussion: Independent evaluation concluded the law is “too restrictive” in certain operational aspects, recommending greater flexibility, in tension with civil liberties advocates who argue the Sleepwet already grants overly broad surveillance powers.

Cyberbeveiligingswet (NIS2 Transposition), Eerste Kamer Review (May 2026): The Cyberbeveiligingswet (Cbw) and the Wet weerbaarheid kritieke entiteiten (Wwke, CER Directive transposition) were adopted by the Tweede Kamer on April 15, 2026 and forwarded to the Eerste Kamer. The Eerste Kamer committees for Digitalisation (DIGI) and Justice & Security (J&V) took committee input on May 19, 2026, reported on June 2, received the government’s response on June 17, issued a second report on June 26, and received a second government response on June 29. Some uncertainty arose from an EU simplification proposal (COM(2026)13, January 2026) that could affect NIS2 implementation across all member states.[30][31][32]

Senate adoption, July 7, 2026, and a CJEU referral two days later: The Eerste Kamer adopted the Cyberbeveiligingswet on July 7, 2026 by a standing vote, with nineteen groups in favour and only the FVD opposed. The government had targeted July 1 for entry into force and missed it: the Act takes effect on a date to be set by royal decree, which may differ article by article, and it had not entered into force as of mid-July 2026. That distinction proved consequential. On July 9, 2026, two days after the Senate vote, the European Commission referred the Netherlands, together with France, Ireland, and Spain, to the Court of Justice of the European Union for failing to transpose NIS2, more than twenty months after the October 17, 2024 deadline, asking the Court to impose a lump sum and ongoing daily financial penalties until each state formally notifies full transposition. Parliamentary adoption does not stop the clock; notification does. The royal decree followed within the day: signed July 8, 2026 (Staatsblad 2026, 189) together with the implementing Cyberbeveiligingsbesluit, it sets entry into force of both the Cbw and the Wwke at August 15, 2026, from which date the new obligations bind more than 8,000 organisations.[32][34][40]

Operation Saffron, Netherlands co-leads First VPN takedown (May 2026): The Netherlands, jointly with France and supported by Europol, Eurojust, and Bitdefender, led Operation Saffron (May 19–20, 2026), dismantling the criminal anonymisation service “First VPN” used by 25+ ransomware groups since 2014. Authorities seized 33 servers across 27 countries and obtained the service’s complete user database of 5,000+ accounts, with intelligence on hundreds of users shared internationally. The operation reflects the Dutch police and OM’s prominent role in EU cybercrime-infrastructure takedowns (continuing the lineage of the EncroChat and Sky ECC operations).[33]

Privacy Framework

The Autoriteit Persoonsgegevens (AP) has imposed significant fines including Uber EUR 290M (US data transfers), Clearview AI EUR 30.5M (biometric scraping), Dutch Tax Administration EUR 6.45M (toeslagenaffaire discrimination + FSV fraud blacklist), and Experian EUR 2.7M (unlawful credit scoring, October 2025). 2024 budget: EUR 45.2M; ~320 FTE; the AP says it needs EUR 100M+ to fulfill all statutory tasks. The AP is also designated as the Dutch EU AI Act supervisory authority.[5][6]

The UAVG (2018) supplements the GDPR with strict BSN (Burgerservicenummer) processing restrictions (functionally stricter than GDPR special category data), age of consent maintained at 16 (GDPR default), and specific rules on criminal conviction data. The Telecommunications Act implements ePrivacy with cookie consent and breach notification requirements.[7]

The Childcare Benefits Scandal (Toeslagenaffaire)

The Tax Administration used automated risk models where dual nationality or “foreign-sounding names” served as fraud indicators, processing nationality data of 1.4 million citizens that should have been deleted in 2014. Repayment demands averaged EUR 20,000–60,000; 2,000+ children were placed in foster care. Amnesty International’s Xenophobic Machines report concluded it constituted institutional racism. The scandal influenced the EU AI Act’s provisions on high-risk AI in public administration and remains a defining reference point for algorithmic accountability in Europe.[2][8]

Encryption Policy

The Netherlands has maintained a consistently pro-encryption stance. In January 2016, the government formally stated it would not take restrictive legal measures on encryption, even as Five Eyes partners pushed for backdoors. Dutch law provides no general compelled decryption authority; intelligence agencies use targeted hacking (Wiv 2017 endpoint exploitation) to bypass encryption rather than mandating providers to build backdoors.[15]

The Netherlands is among only six EU member states explicitly opposing mandatory scanning of encrypted communications under the EU CSA Regulation (Chat Control). Dutch opposition was instrumental in forcing the November 2025 compromise removing mandatory client-side scanning. The AIVD, together with TNO and CWI, published a Post-Quantum Cryptography Migration Handbook (2024) to prepare for quantum computing threats.[16][17]

This creates a paradox: the Netherlands protects encryption architecturally while simultaneously deploying targeted hacking to bypass it at the endpoint and conducting bulk cable interception under the Wiv 2017 to capture communications before or after encryption is applied.

Data Retention

The Dutch data retention law was declared inoperative by The Hague District Court on March 11, 2015, following the CJEU’s Digital Rights Ireland ruling. The Netherlands has not enacted replacement legislation. Proposed revisions requiring prior judicial authorisation and limiting access to offences carrying 4+ years imprisonment remain unadopted. Intelligence services access communications data through Wiv 2017 bulk interception, effectively bypassing restrictions that would apply to law enforcement.[22]

Pending Legislation

Sources

[1] Wikipedia: Wiv 2017 – Sleepwet, bulk interception, referendum, JSCU
[2] Wikipedia: Childcare Benefits Scandal – Toeslagenaffaire, ~26,000 families, cabinet resignation
[4] The Guardian: Dutch Intelligence Reduces US Sharing – Akerboom and Reesink statements, politicisation concerns
[5] AP: About Us – EUR 45.2M budget, 320 FTE, EUR 100M+ needed
[6] GDPRhub: AP (Netherlands) – Enforcement record, Clearview AI, Uber, Tax Administration fines
[7] ICLG: Data Protection – Netherlands – UAVG, BSN restrictions, age of consent 16
[8] Amnesty International: Xenophobic Machines – Institutional racism, discriminatory algorithms
[9] Freedom House: Netherlands 2024 – Wiv 2017 concerns, Sleepwet cosmetic amendments
[10] Eerste Kamer: Temporary Cyber Operations Act – Senate adoption March 2024, weakened TIB oversight
[11] Bert Hubert: Temporary Cyber Operations Act Concerns – Former TIB member warning on civil liberties erosion
[12] Wikipedia: JSCU – ~350 employees, AIVD-MIVD joint SIGINT, operational since 2014
[13] CTIVD – Binding ex post oversight, “walk in, pull open drawers”
[14] CTIVD: Journalist Recruitment Investigation – AIVD/MIVD recruited journalists as paid agents
[15] Carnegie Endowment: Encryption Debate in Netherlands – 2016 government statement, no restrictive measures
[16] EDRi: Chat Control – Netherlands among six states opposing mandatory scanning
[18] Amnesty: Pegasus Project – Netherlands confirmed customer
[19] Platform Overheid: Palantir Netherlands Contracts – 2010 MoD, 2011 Police (Schoof), NCTV, OM, 45,000 redacted documents
[20] AMS-IX – 900+ networks, 14 Tbps peak, exchanges in Mumbai/HK/Chicago/Caribbean
[21] Submarine Cable Map – Beverwijk, Katwijk, Zandvoort landing stations
[22] EDRi: Netherlands Data Retention Inoperative (2015) – No replacement legislation
[23] DOJ Office of International Affairs – NL-US MLAT, one of first three modern MLATs
[24] Privacy International: Five Eyes / Nine Eyes – Reciprocal surveillance bypass
[25] Bart Jacobs: Maximator (2020) – Netherlands joined 1978, encryption-defeat cooperative
[26] DutchNews: Odido Data Breach (February 2026) – 6.2 million customers, one-third of population
[27] Government.nl: Expanded Espionage Law (May 2025) – Digital and diaspora espionage, 8–12 year penalties
[28] Government.nl: Chat Control Opposition – One of six EU states explicitly opposing mandatory scanning
[29] Digital Commons EDIC – Netherlands joined December 2025 with eight EU states for open-source European digital infrastructure
[30] NCTV: Debat in Tweede Kamer over Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten (March 24, 2026) – Plenary debate on NIS2 and CER transposition; government targets Q2 2026 entry into force
[31] Rijksoverheid: Tweede Kamer stemt in met Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten (April 15, 2026) – Both bills adopted by the House of Representatives; now forwarded to Eerste Kamer; simultaneous Q2 2026 entry into force targeted subject to Senate scheduling
[32] Eerste Kamer: Cyberbeveiligingswet (36.764) – Senate proceedings page; DIGI and J&V committee input May 19, 2026; committee report June 2, 2026; government response June 17; second report June 26; second government response June 29; Senate adopted the bill July 7, 2026 by standing vote (19 groups in favour, FVD against); entry into force on a date to be set by royal decree, potentially staged by article
[34] The Record: EU Takes Member States to Court over Unimplemented Cybersecurity Law (July 9, 2026) – European Commission referred the Netherlands, Ireland, Spain and France to the Court of Justice of the European Union for failing to transpose NIS2 more than 20 months after the October 2024 deadline; Commission asked the Court to impose a lump sum and ongoing daily financial penalties until each state formally notifies full transposition; only 6 of 27 member states had transposed NIS2 by January 2025
[33] Help Net Security: Authorities Dismantle First VPN, Used by Ransomware Actors (May 21, 2026) – Operation Saffron (May 19–20, 2026) led by the Netherlands and France with Europol, Eurojust, and Bitdefender; 33 servers seized across 27 countries; complete user database of 5,000+ accounts obtained; intelligence on 506 users shared with partner countries; continues the Dutch lineage of EncroChat/Sky ECC takedowns
[35] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) – Chart of signatures and ratifications; 51 parties as of July 2026 (all 46 Council of Europe member states plus Chile, Israel, Mongolia, the Republic of Korea and Russia), the Netherlands among them
[36] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states), the Netherlands among them
[37] European Commission: Schengen Area – The 29 states of the Schengen Area (all EU members except Ireland and Cyprus, plus the non-EU associates Iceland, Liechtenstein, Norway and Switzerland; Bulgaria and Romania became full members January 1, 2025), the Netherlands among them
[38] Wikipedia: Prüm Convention – The Prüm framework for automated DNA, fingerprint and vehicle-data exchange; binds all 27 EU member states plus the non-EU Schengen associates Iceland, Liechtenstein, Norway and Switzerland (31 in all); the Netherlands was an original 2005 signatory; Prüm II (2024) adds facial images and police records
[39] Europol: Operational Agreements – Europol (headquartered in The Hague) is constituted by the 27 EU member states (the Netherlands among them) and maintains operational cooperation agreements permitting exchange of personal data with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, the United States) plus Denmark under a separate agreement, and with Eurojust, Frontex and Interpol
[40] Rijksoverheid: Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van kracht (July 2026) – royal decree of July 8, 2026 (Staatsblad 2026, 189, with the Cyberbeveiligingsbesluit) sets entry into force of both Acts at August 15, 2026; obligations apply to more than 8,000 organisations
[41] Wikipedia: Club de Berne – informal forum (founded 1969) of the heads of the domestic intelligence and security services of the 27 EU member states plus Norway and Switzerland; its separate post-9/11 offshoot the Counter Terrorism Group (September 2001) additionally includes the United Kingdom and has operated a joint platform in The Hague with a common database and real-time information system since 2016
← Back to Privacy Law Directory