GDPR Implementation Act (UAVG), Netherlands
Law. Placed at the Netherlands. Read 30 Sep 2026; 2 provisions cited by the planner.
UAVG Art. 33(3)Process criminal-offence data about staff only under rules adopted through the works council procedure Criminal-offence data about personnel in the controller's service may be processed only in accordance with rules adopted following the procedure of the Works Councils Act, that is with the works council's consent under WOR art. 27(1)(k) (or the equivalent employee representation route). This covers internal fraud and theft investigations, covert camera footage used to establish an offence and incident registers about employees; the Autoriteit Persoonsgegevens' DPIA list names covert camera surveillance by employers against theft or fraud (a DPIA is required even in incidental cases) and staff blacklists (art. 33(4)(c) permit).
UAVG Art. 29Use biometric identification (fingerprint or face) only where necessary for authentication or security for a weighty public-interest access need Under GDPR art. 9(2)(g), biometric data for uniquely identifying a person may be processed only where necessary for authentication or for security purposes, and (since the Verzamelwet gegevensbescherming, in force 1 September 2026) only insofar as necessary because of a weighty public interest in lawful access to particular places, buildings, services, products, information systems or work process systems. Convenience, cost saving and time registration are not such an access need (the AP has fined an employer for fingerprint-based time registration); outside this exception, explicit consent under art. 22(2)(a), rarely freely given by employees, is the only route. The Autoriteit Persoonsgegevens' DPIA list (Staatscourant 2019, 64418) requires a DPIA for large-scale or systematic biometric processing.