Cookie Policy Generator Netherlands
GDPR through the UAVG, cookie rules in the Telecommunicatiewet, and an AP with firm views on cookie walls.
Dutch cookie rules come from Article 11.7a of the Telecommunicatiewet, not from GDPR, and the AP enforces them with published expectations about what a compliant banner does. The cookie policy has to describe the banner you actually run.
The Netherlands applies GDPR through the Uitvoeringswet AVG, with the Autoriteit Persoonsgegevens as regulator. Cookies are governed separately by Article 11.7a of the Telecommunicatiewet, which predates GDPR and which the AP enforces on its own terms.
The AP has been unusually direct about banner design. Its published position is that continuing to browse is not consent, that a cookie wall forcing acceptance in exchange for access generally fails the freely-given test, and that tracking cookies require consent obtained before they are placed. It has run sweeps and published the results.
Dutch employment law adds a second layer for staff data. Works councils have co-determination rights over systems capable of monitoring employees, which means a monitoring tool can be lawful under GDPR and still not deployable without agreement.
What a cookie policy in the Netherlands has to cover
A per-cookie table naming the provider, purpose, category and lifetime of each entry
Article 11.7a as the basis for the consent requirement, distinct from the GDPR basis
Whether you rely on the narrow analytics exemption, and the configuration that supports it
That nothing non-essential is placed before consent, and that browsing on is not treated as consent
Any paid alternative to accepting tracking, described accurately
How the Netherlands actually moves personal data
iDEAL and Dutch payment rails
iDEAL payments route through the customer’s bank and return an identity confirmation, which is a disclosure to a financial institution as well as a payment step.
Analytics under the narrow exemption
The AP accepts a limited consent exemption for analytics configured with no data sharing, no profiling and no advertising use. Standard configurations do not qualify.
Cookie walls and paid alternatives
The AP treats a hard cookie wall as invalidating consent. Any paid alternative model has to be described honestly in the policy.
Employee monitoring tools
Ticketing, analytics and productivity tools capable of individual monitoring, which trigger works council rights.
Transfers to US vendors
The AP expects a documented transfer mechanism per destination, and has been explicit that a Data Privacy Framework certification must actually be current.
Third parties the draft will ask you about
Mollie · Adyen · iDEAL · PostNL · Exact · AWS eu-west-1 · TransIP · Matomo
The rules that apply
GDPR + Uitvoeringswet AVG
The Dutch implementation, including national rules on identification numbers, criminal data and the digital age of consent set at sixteen.
Telecommunicatiewet Article 11.7a
Consent before placing or reading information on a device, with an exemption limited to what is strictly necessary and to certain analytics with no or little privacy impact.
Autoriteit Persoonsgegevens
The named supervisory authority, active on cookie banners, data broking and the security of personal data.
BSN restrictions
The Dutch citizen service number may only be processed where a statutory basis exists, which rules it out for most commercial purposes.
Works council co-determination
Systems capable of monitoring staff need works council agreement, independent of the GDPR basis.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
Dutch compliance essentials
Configure the banner to place nothing before consent
And record the consent with a timestamp and the banner version.
Test whether your analytics really fits the exemption
If it shares data with the provider, it does not.
Set the digital age of consent to sixteen
With a parental consent route below it.
Take monitoring tools to the works council
Before deployment, not after.
Publish the AP as the complaint route
With its website, alongside your own contact for privacy requests.
Where this usually goes wrong
Consent inferred from continued browsing
The AP has said plainly this is not consent, and it is the finding its sweeps report most often.
A hard cookie wall
Blocking access unless a visitor accepts tracking generally fails the freely-given requirement in the AP’s view.
Claiming the analytics exemption without meeting its conditions
It requires no sharing with the provider for its own purposes and no use for profiling or advertising.
Processing the BSN without a statutory basis
It is restricted to specific legal purposes and cannot be used as a general customer reference.
Deploying monitoring tools without works council agreement
A GDPR basis does not substitute for co-determination.
Frequently asked questions
Are cookie walls legal in the Netherlands?
The Autoriteit Persoonsgegevens takes the position that a wall forcing acceptance in exchange for access does not produce freely given consent. Models offering a genuine paid alternative are contested rather than clearly permitted.
Do I need consent for analytics in the Netherlands?
Usually yes. There is a narrow exemption for analytics with no data sharing, no profiling and no advertising use, but standard configurations of the common tools do not meet it.
What is the digital age of consent in the Netherlands?
Sixteen. Below that, consent for information society services must come from a parent or guardian.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator Netherlands
Answer a short questionnaire and get a draft written for the Netherlands. Free to start, no card required.
Generate your cookie policyOther documents for the Netherlands
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.