OutsourcingVN is operated by Netbase JSC, so this guide is written by a supplier that would like your project. It sets out what Netbase can evidence for a Dutch brief, points to the official references your own advisers should read in full, and names the decisions that stay with you. The guides index lists guides for other markets, and the market index compares the first question each one raises.
Contents
- Who enforces data protection for a Dutch-facing product?
- What can Netbase evidence for a Dutch brief?
- Which requirement sits with which decision owner?
- Which steps come before a Dutch-facing launch?
- Worked scenario: a Dutch customer asks for their data
- What has Netbase built for Dutch clients?
- Which questions should you ask a supplier?
- What usually goes wrong?
- How this guide is sourced and where it stops
- Common questions
- Plan the first release
Who enforces data protection for a Dutch-facing product?
GDPR applies across the European Union, and the Netherlands reaches it through its own national supervisory authority rather than a separate Dutch law layered on top. A controller must have a lawful basis for each use of personal data, honour access, correction, erasure and portability requests, and tell its supervisory authority of a qualifying breach within 72 hours of becoming aware of it. Fines can reach the higher of €20 million or 4% of global annual turnover.
None of that changes because the development team sits outside the Netherlands. What changes is who signs the processing agreement, who is named as controller or processor, and who answers the supervisory authority's questions if a Dutch user complains. A buyer should decide those three roles before discovery starts, not after a defect is found.
What can Netbase evidence for a Dutch brief?
Procurement, security and data protection reviewers tend to ask for the same four statements. These are the ones Netbase can give.
- Compliance practices. Netbase's compliance practices are GDPR alignment for data privacy in Europe, HIPAA-aligned methodologies for healthcare data handling, and CCPA compliance for clients with U.S. customer bases. Deciding how GDPR applies to your own product and who your Dutch data protection officer is remains your organisation's task.
- Security practices. Security practices include secure code review and version control, role-based access control, MFA for admin dashboards, contributors under NDA, and NDAs and DPAs on request. A data processing agreement for a Dutch-facing system sits on top of this baseline.
- Information security management. Netbase JSC holds ISO 27001 certification for information security management. The certification belongs to Netbase as a company; it is not extended to a product built for a client or to its hosting.
- Markets and language. Netbase clients are in the United States, Europe and Asia-Pacific, and most projects come from clients outside Vietnam. Delivery communication is in English, so a Dutch-facing product's own localisation into Dutch is scoped as a project task, with a named Dutch copy owner.
Which requirement sits with which decision owner?
A Dutch brief usually spans four separate owners inside the buying organisation. Splitting the requirement from the evidence from the decision keeps a proposal from promising more than one team can check.
| Decision area | What Dutch and EU rules expect | What a supplier can evidence | Who decides |
|---|---|---|---|
| Data protection | A lawful basis per use, a 72-hour breach report, honoured subject rights | A data processing agreement, an access matrix, a tested breach-response plan | Data protection lead |
| Accessibility | A published standard for public-sector sites; a widening private-sector duty under EU accessibility rules | Per-journey test results with assistive technology, a defect log | Product or service owner |
| E-invoicing | Public buyers receive invoices over Peppol in the structured EN 16931 format | A Peppol access-point connection and a tested invoice export | Finance systems owner |
| Payments | Dutch shoppers commonly expect their own bank's payment screen at checkout | iDEAL alongside card payments in the checkout flow | Product owner with payments provider |
| Language | Dutch copy for consumer journeys; English is common for B2B tools | A named Dutch copy owner and a tested translation workflow | Localisation owner |
Ask for this table filled in, not just a general compliance statement, before shortlisting a supplier.
Which steps come before a Dutch-facing launch?
-
Map the data flows and lawful basis
List what personal data the product collects, stores or shares, and the lawful basis for each use under GDPR.
-
Name the accessibility standard
Decide what a public-sector-facing service must meet, and what a private product will commit to for its own users.
-
Connect to Peppol for e-invoicing
If the product bills a Dutch public body, join the Peppol network so invoices reach the buyer in the EN 16931 format.
-
Add Dutch payment methods
Offer iDEAL alongside cards, since many Dutch shoppers expect to pay through their own bank's screen.
-
Decide go-live readiness
Check the data map, the accessibility test results, the Peppol connection and the payment and language scope against the plan, and record the decision with its owner.
-
Launch and keep the record current
Publish or update the accessibility statement, keep the breach-response plan rehearsed, and review the four items again at the next major release.
(opens the full-size diagram in a new tab)
Worked scenario: a Dutch customer asks for their data
A Dutch customer emails asking what personal data a loyalty programme holds about them and for a copy in a portable format.
-
Request logged
The request is recorded with the channel it arrived on and the date
- Owner
- Support
-
Identity confirmed
The requester's identity is checked through the account's existing sign-in, not a new method invented for the request
- Owner
- Support
-
Data assembled
Engineering exports the account's personal data, excluding anything that belongs to another customer
- Owner
- Engineering
-
Format checked
The export uses a structured, commonly used format rather than a screenshot or a support note
- Owner
- Engineering
-
Response sent
The data protection lead sends the export and a short note on what it contains, inside the response window the business has set
- Owner
- Data protection lead
-
Request closed
The request and response are logged, so the next one does not start from a blank page
- Owner
- Data protection lead
A proposal that cannot describe step 3, specifically how the export keeps one customer's data separate from another's, has not yet scoped data portability for this product.
What has Netbase built for Dutch clients?
The nearest published evidence for a Dutch brief is commerce work: Netbase has built a web-to-print store with an online design tool for an interior and furnishing panels business in the Netherlands, and a Magento store with companion Android and iOS apps for a women's fashion retailer in the Netherlands, for clients that are not named. The web-to-print stores record covers the design-tool scope across four countries including the Netherlands; the Dutch fashion retailer's app work sits outside that record's print-commerce scope.
Which questions should you ask a supplier?
- Who signs the data processing agreement, and who is named controller? Expect a clear answer before contract, not during a breach.
- What exactly does your security and compliance statement cover? A precise answer says what it does not cover as well as what it does.
- Can you show a Peppol invoice export from a past project? Ask for the structure, not just a claim that it exists.
- Who owns the Dutch copy, and how does a change reach production? Translation drift is easiest to catch before launch, not after.
- How is iDEAL integrated, and who holds the merchant relationship? The payment provider relationship usually stays with the buyer.
- Who decides if an accessibility defect blocks release? It should be your product or service owner, not the supplier.
What usually goes wrong?
- A company-level compliance statement read as project proof. Signal: nobody has tested this product's own data flows or access controls. Owner: the data protection lead.
- Accessibility treated as a launch-week task. Signal: a long defect list appears days before release. Owner: the product owner, testing each journey during the build.
- iDEAL added after checkout is already built around cards. Signal: a late, disruptive change to the payment flow. Owner: the product owner, scoping payment methods at discovery.
- Dutch copy translated once and never re-tested. Signal: error messages and generated documents drift out of Dutch after the first release. Owner: the localisation owner.
How this guide is sourced and where it stops
This guide draws on the European Commission's Your Europe business pages on GDPR and e-invoicing, the Peppol network's own description of itself, the Dutch government's digital accessibility site, and iDEAL's own description of its payment scheme, all checked on 2026-10-03, together with company statements and a delivery record approved in the OutsourcingVN claim register. It is written for product, procurement and operations leads scoping a Dutch-facing brief. It does not decide which accessibility standard or data protection role fits your organisation; your own advisers make that call.
Plan the next step for your project
Common questions
The regulation itself is the same across the European Union; what differs by country is which national authority enforces it and how it runs its own guidance and complaint process. Check your national authority's current guidance rather than assuming every member state applies it identically.
No. The clearest mandate is for invoices to public-sector buyers, which travel over the Peppol network in a structured format. Business-to-business e-invoicing is a separate commercial decision until further EU rules extend the mandate.
Not always. Many buyers ship the journeys Dutch customers use most in Dutch and keep less-used screens in English, provided the boundary is written down and a named owner reviews Dutch copy before each release.
Yes, when the payment provider relationship, the checkout flow and the reconciliation process are scoped with the same care as any other payment method, and tested against the provider's own sandbox before launch.
That depends on who operates the service and who it is built for, which your own advisers should confirm; the distinction changes which standard is a legal duty and which is a commitment you choose to make.
Plan the first release
Bring your data protection role split, your accessibility standard, your Peppol and payment decisions, and your Dutch-language scope. The data security and compliance guide lists the contract questions behind the data protection row, and the time zone and collaboration guide covers how overlap and handoff are agreed for a European working day. For neighbouring markets, the UK guide covers UK-specific accessibility duties and the Germany guide covers works-council consultation and German e-invoicing formats; the France guide covers CNIL guidance and the French e-invoicing reform.
Custom Product Engineering is the service for a bounded build, and global delivery explains how remote delivery is organised. OutsourcingVN is Netbase's own outsourcing-services platform: submit a project with your Dutch-facing scope, and a person will reply with whether discovery or a bounded implementation is the right next step.
Related services and solutions
Custom product engineering for a bounded release outcome
One defined release of your product, built to named outcomes and handed over with acceptance evidence.
Learn More