Dutch and EU digital regulation

GDPR, technology and AI lawyers in the Netherlands

Practical legal support for international companies using data, software, cloud services and AI in the Netherlands and across the European Union.

Compliance connected to deployment

Turn digital regulation into workable decisions

International technology projects often combine several legal layers: GDPR roles, international data transfers, security obligations, intellectual-property rights, platform terms and the EU AI Act. A policy or processor agreement addresses only part of that picture.

We start with how the system is actually selected, configured and used. Who determines the purpose? Which data enters the system? Can the output affect employees, customers or access to services? Which supplier controls model changes? Which records can demonstrate that management made a responsible decision?

The AI Act timeline has changed. Prohibited-practice and AI-literacy rules have applied since February 2025; governance and general-purpose AI obligations followed in August 2025. Further provisions apply from August 2026, while the 2026 AI Omnibus moved important high-risk deadlines to December 2027 and August 2028 depending on the system. Every project therefore needs a role- and use-case-specific analysis rather than a generic compliance statement.

Digital legal support

From vendor selection to incident response

We help legal, privacy, security, procurement, HR and product teams create one defensible framework.

GDPR scope and accountability

Role allocation, lawful basis, transparency, retention, rights handling, records of processing and governance across entities.

DPIAs and high-risk processing

Structured assessment of necessity, proportionality, risks to individuals, mitigations, residual risk and management approval.

International data transfers

Adequacy, standard contractual clauses, transfer impact assessments, supplementary measures and vendor-chain documentation.

Technology and cloud contracts

Data use, security, service levels, IP, audit, subcontractors, business continuity, exit assistance and liability allocation.

AI Act classification and governance

Provider and deployer roles, prohibited uses, literacy, transparency, high-risk analysis, human oversight and compliance evidence.

Data and cyber incidents

Legal triage, contractual notifications, GDPR breach analysis, regulator strategy, evidence preservation and stakeholder communication.

Evidence-based compliance

Show what the organisation decided and why

Map

We map the use case, data, parties, systems, countries, affected people and decisions before selecting the legal instruments.

Decide

We classify the risks, compare safeguards and document the legal and operational reasons for the chosen design.

Maintain

We create ownership, approval, incident, monitoring and review processes that continue after the initial project launch.

Frequently asked questions

GDPR and AI law for international companies

Can the GDPR apply to a company outside the EU?

Yes. The GDPR can apply to non-EU organisations that offer goods or services to people in the EU or monitor their behaviour there. An EU establishment can also bring processing within scope.

When is a data processing agreement required?

A written agreement meeting Article 28 GDPR is required when a processor handles personal data on behalf of a controller. The actual allocation of roles and instructions matters more than the label used by the parties.

When is a DPIA required?

A DPIA is required before processing that is likely to result in a high risk to individuals. This may be relevant for systematic monitoring, sensitive data, large-scale processing and certain AI applications.

Which AI Act duties apply in August 2026?

AI literacy and prohibited-practice rules already apply, as do governance and general-purpose AI obligations for relevant actors. Further transparency and other provisions apply from August 2026. Following the 2026 AI Omnibus, important high-risk-system duties apply from December 2027 or August 2028, depending on the system. The exact position must be assessed for the organisation’s role and use case.

Can personal data be transferred outside the EEA?

Yes, but a valid transfer mechanism is required unless the destination benefits from an adequacy decision. Standard contractual clauses often require a transfer impact assessment and appropriate supplementary measures.

Before launch, audit or incident escalation

Build a digital-law position the business can explain and prove.

Contact our privacy and AI team