Netherlands Cookie Compliance in 2026
Dutch cookie rules run on two laws at once — the Telecommunicatiewet and the AVG (the Dutch name for GDPR). The Autoriteit Persoonsgegevens now scans roughly 10,000 Dutch websites a year with dedicated government funding, and warns 500 organisations annually. If your site reaches Dutch visitors, here is exactly what it must do.
Why Dutch cookie compliance runs on two laws
The Netherlands applies GDPR plus a national implementation of the ePrivacy Directive — but the split is unusually explicit, and reading Dutch guidance correctly depends on knowing which law is speaking.
The Telecommunicatiewet (Dutch Telecommunications Act), Article 11.7a, governs the act of placing or reading anything on a visitor's device. It applies whenever you store or access information on that device — regardless of whether the data is personal. This is the Dutch implementation of ePrivacy Article 5(3), and it is often called the cookiewet.
The AVG — Algemene verordening gegevensbescherming, simply the Dutch name for GDPR — governs what happens to personal data once collected. Alongside it sits the UAVG (Uitvoeringswet AVG), the Dutch implementation act that fills in national details GDPR left to member states.
| Telecommunicatiewet art. 11.7a | AVG (GDPR) | |
|---|---|---|
| What it governs | Placing & reading cookies on a device | Processing of personal data |
| When it applies | Any time you store or access anything on the user's device | Only when the data collected is personal data |
| Formal supervisor | Autoriteit Consument & Markt (ACM) | Autoriteit Persoonsgegevens (AP) |
| Maximum penalty | Up to €900,000 per violation (art. 15.4), or in some cases 1–10% of turnover | Up to €20M or 4% of global annual turnover |
| Territorial scope | Netherlands | Whole EU/EEA |
In practice, the AP enforces cookies — not the ACM
Although the Telecommunicatiewet formally sits under the ACM, it is the Autoriteit Persoonsgegevens that runs cookie enforcement in the Netherlands. The reason is simple: nearly every tracking cookie processes personal data, which pulls it into the AVG and therefore the AP's remit. Most Dutch cookie failures breach both laws simultaneously. When you read about Dutch cookie enforcement, you are almost always reading about the AP.
Does this apply if my business isn't Dutch?
Yes. The AVG applies to any organisation established in the Netherlands regardless of where processing happens, and to organisations outside the EU that offer goods or services to people in the Netherlands or monitor their behaviour. Running analytics or advertising pixels on a site that Dutch residents visit is monitoring behaviour. A foreign company targeting Dutch residents must comply with both the AVG and the UAVG.
What valid toestemming requires in the Netherlands
The Dutch word for consent is toestemming, and the standard is the AVG's: freely given, specific, informed, and unambiguous. Article 11.7a's core obligation is a sequence — inform first, then ask permission, and only then place the cookie. The AP's 2025 guidance sharpened four points that Dutch banners routinely fail.
Reject must sit on layer one
If an "Accept all" button appears on the first layer of the banner, a "Reject all" button must appear there too — at the same prominence. Burying refusal one click deeper is the single most-cited Dutch violation.
Nothing fires before the click
Trackers must be technically blocked until the visitor actively consents. The A.S. Watson case turned on cookies firing both before and after the consent flow — the banner existed, the blocking didn't.
No pre-ticked boxes
Pre-ticked advertising or analytics categories are not consent — settled EU case law, and the exact finding in both the A.S. Watson and Coolblue decisions. Every non-essential category starts unchecked.
No cookiemuur
The AP prohibits cookie walls that condition site access on accepting tracking. Consent conditioned on access is not freely given. The Dutch position aligns with France's CNIL and Belgium's APD.
A banner is not blocking — and the AP checks the difference
Independent research on 150 large Dutch corporate websites found 42.7% of homepages loaded high-risk trackers before the visitor consented — Meta, Hotjar, LinkedIn Ads and similar, all processing personal data on page load while the banner was still on screen. Every one of those sites had a cookiebanner. The banner was never the issue.
What a compliant Dutch cookiebanner must and must not do
✕ NON-COMPLIANT
- Trackers load on page load, before consent is given
- "Accept all" on layer one, "Reject" only in a sub-menu
- Pre-ticked boxes for analytics or advertising
- Rejecting takes more clicks than accepting
- A cookiemuur blocking access until you accept
- Colour or size making "Accept" visually dominant
- "Continue browsing" treated as agreement
- No log of who consented, to what, and when
✓ COMPLIANT
- All non-essential trackers blocked until active consent
- "Accept all" and "Reject all" both on layer one, equal weight
- Every non-essential category unchecked by default
- Refusing is exactly as easy as accepting — one click
- Full site access regardless of the visitor's choice
- Buttons visually equivalent in size, colour and contrast
- Clear affirmative action required — a click
- Timestamped consent log, produced on request
All Dutch cookie requirements for website operators
Beyond the banner itself, these are the obligations Dutch websites must address — with the provision each one rests on.
Inform before you ask
Tell visitors what is being stored or accessed and why, before requesting permission. Information first, consent second, cookie third — in that order.
Telecommunicatiewet art. 11.7aTwo narrow exemptions only
Cookies strictly necessary to transmit a communication, and cookies strictly necessary for a service the user explicitly requested (session cookies, shopping carts), need no consent — but must still be disclosed.
Telecommunicatiewet art. 11.7a(3)Analytics: a partial Dutch exemption
The Netherlands grants analytical cookies a partial exemption where their privacy impact is minimal and results are used only for the site itself. This is more generous than France, but it does not cover Google Analytics in a standard configuration sharing data with Google.
Dutch practice under art. 11.7aA lawful basis for the processing
Placing the cookie is one question; processing the data is another. The A.S. Watson fine was issued under AVG Article 6(1) with 5(1)(a) — no lawful basis for the processing, not merely a bad banner.
AVG art. 6(1) + art. 5(1)(a)Withdrawal as easy as consent
Visitors must be able to change or revoke their choice at any time, through a route no harder than the one that granted it — a persistent link, not a buried policy page.
AVG art. 7(3)Demonstrable, logged consent
Accountability means you must be able to show valid consent: what was shown, what was chosen, and when. The AP asks for this during investigations; a banner with no log proves nothing.
AVG art. 5(2) + art. 7(1)Pixels and fingerprinting count
EDPB Guidelines 2/2023 (final October 2024) extended ePrivacy Article 5(3) beyond HTTP cookies to tracking pixels, device fingerprinting, local storage and URL tracking. The Meta Pixel and TikTok Pixel need prior toestemming.
EDPB Guidelines 2/2023Privacyverklaring, current and specific
Your privacy statement must name every tool and third party, the purpose and legal basis for each, and retention periods — in plain Dutch or English. The AP treats a three-year-old privacyverklaring as a sign of neglect.
AVG art. 13–14Context can aggravate the penalty
In A.S. Watson the AP treated drugstore browsing data — pregnancy tests, contraception, medication — as revealing sensitive information. The category of cookie matters less than what the browsing reveals.
AP boetebeleidsregelsInternational transfers
Sending Dutch visitors' data to US-based tools requires SCCs or another valid transfer mechanism. The AP's €290M Uber fine was for exactly this failure — transfers without adequate safeguards.
AVG Chapter VThe EU AI Act is live for Dutch sites too
Article 50 requires disclosure of AI-powered features to EU visitors from 2 August 2026. We built the disclosure into the consent banner — enable the toggle, publish, done.
AP enforcement: from warnings to fines
Dutch cookie enforcement changed character in 2025. For years the AP published guidance and acted on complaints. Then the government ring-fenced money to hunt cookie violations — €500,000 per year for three years, plus a permanent €350,000 annual increase from 2027. That funding bought a scanning operation with a schedule.
| When | What happened |
|---|---|
| 15 April 2025 | The AP sends warning letters to an initial 50 organisations — webshops, media companies and insurers — for misleading cookiebanners or placing trackers without valid consent. Three months to fix. |
| Through 2025 | The campaign expands to 200+ websites warned. |
| Jul–Sep 2025 | First deadlines expire. Roughly three-quarters of warned organisations adjust their banners. |
| Oct 2025 | Formal investigations open against the quarter that did not respond. AP Vice-Chair Monique Verdier confirms: organisations that fail to adjust can expect an investigation or a fine. |
| Dec 2025 | Coolblue fined €40,000 — pre-ticked boxes and treating "continue" as consent. Public campaign "Ga slim om met cookies" invites consumers to complain. |
| 2026 onward | Automated scanning of ~10,000 Dutch websites annually; target of 500 warnings a year; investigations and fines for those who ignore them. |
Doubles if a similar violation occurred within the previous five years. Applies to the act of placing or reading without valid consent.
Applies to consent failures and unlawful processing. A lower tier of €10M or 2% covers less severe breaches. This is the tier the AP actually uses for cookies.
The case that shows how this actually plays out
In A.S. Watson — the parent of drugstore chain Kruidvat — the AP found that kruidvat.nl placed tracking cookies both before and after the consent flow, with advertising cookies pre-ticked. Even visitors who completed the toestemming procedure without agreeing to advertising cookies still had them placed. The AP treated the browsing data as especially sensitive: a drugstore's product mix reveals pregnancy tests, contraception and medication, and combined with a visitor ID and IP-derived location it builds what the AP called a highly specific and invasive profile.
The fine was €600,000, issued 2 May 2024. Three details matter more than the headline:
- It was reduced to €50,000 on objection in June 2025 — but the violation was upheld. The AP's interpretation stands; only the amount moved.
- The conduct was from 2019–2020. The AP's investigation began in October 2019; the violation ended in October 2020; the fine landed in 2024. Cookie liability has a long tail.
- The company had a cookiebanner throughout. The banner was never the defect. What fired behind it was.
2026 EU-wide priority: transparency
The European Data Protection Board launched its Coordinated Enforcement Framework for 2026 on transparency obligations under Articles 12–14 — and the AP participates. That puts privacyverklaringen, consent documentation and disclosure clarity under active review across every EU jurisdiction, the Netherlands included. A vague or outdated privacy statement is now a live risk, not a housekeeping item.
Where the Netherlands sits among EU regulators
The Netherlands sits at the stricter end of the EU spectrum, though not the extreme: the cookiemuur ban mirrors France's CNIL and Belgium's APD, while the analytics exemption is more generous than France's. What distinguishes it is structural. Germany's enforcement is split across sixteen state authorities and is correspondingly uneven; the Dutch model is centralised with earmarked, multi-year funding — predictable, sustained pressure rather than sporadic action. A site that satisfies the AP will generally satisfy most of the EU.
Scan your site for Dutch cookie violations
Every Dutch enforcement action above began the same way: someone loaded the site with a fresh session and watched what fired before consent — exactly what the AP's scanner does across 10,000 Dutch websites a year. Our free scanner does the same in about ten seconds: it opens your homepage with no cookies, records every tracker that transmits before consent, and tells you which would put you in the AP's warning queue. No account needed.
How to make your website compliant for Dutch visitors
Install a CMP that blocks, not just displays
This is the whole game. A compliant platform technically prevents non-essential trackers from firing until toestemming is given, presents Accept and Reject with equal prominence on layer one, and logs every decision with a timestamp. ConsentPixel — Privacy · Verified does all three from one script tag — the blocking, the banner, and the log.
Put Reject on the first layer, at equal weight
The AP's 2025 guidance is explicit: if "Accept all" is on layer one, "Reject all" must be too — same prominence, same visual weight. This single fix resolves the most-cited violation in the Dutch warning campaign. Check colour, size and contrast, not just presence.
Verify what actually fires — don't assume
Open your site in a private window, open DevTools → Network, reload, and watch what transmits before you touch the banner. 42.7% of large Dutch sites fail here while displaying a banner. If Meta, Hotjar or GA4 appear before your click, the banner is decoration.
Remove any cookiemuur
If refusing cookies restricts access to your content, that consent is not freely given under the AP's position. Full access must survive a Reject click. This includes soft variants — nagging modals that reappear, or degraded functionality for those who decline.
Update the privacyverklaring and name your tools
List every third party that receives visitor data, the purpose, the legal basis and the retention period, in plain language. With the EDPB's 2026 transparency focus and the AP participating, an outdated privacy statement is an active risk — and the AP reads it as evidence of neglect.
Keep a consent log you can actually produce
When the AP asks how you obtained consent, "we had a banner" is not an answer. You need per-visitor records: what banner version was shown, which categories were accepted or declined, and when. This is the accountability principle in practice, and it is the difference between a warning and a fine.
Check your international transfers
If Dutch visitors' data reaches US-based tools — GA4, HubSpot, Mailchimp, Salesforce — you need Standard Contractual Clauses in place and a signed DPA. The AP fined Uber €290 million for getting this wrong. Verify the DPA is signed, not merely available.
Dutch cookie compliance checklist 2026
Tick each item to assess where you stand against what the AP actually checks.
Netherlands cookie compliance — frequently asked questions
Which laws govern cookies in the Netherlands?
Does the reject button need to be on the first layer of the banner?
Are cookie walls (cookiemuur) allowed in the Netherlands?
Do analytics cookies require consent in the Netherlands?
What fines has the AP actually issued for cookies?
What happens if I ignore an AP warning letter?
Does Dutch cookie law apply to my business if I'm not based in the Netherlands?
Is the Netherlands stricter than other EU countries on cookies?
Compliant for Dutch visitors in 10 minutes
ConsentPixel — Privacy · Verified blocks every non-essential tracker until toestemming is given, puts Accept and Reject on layer one at equal weight, logs every decision with a timestamp, and generates your privacyverklaring. One script tag. AVG, Telecommunicatiewet, and the rest of the EU.
No credit card required · Setup in 10 minutes · Cancel anytime