ConsentPixel – Privacy · Verified

🇳🇱 EU Member State · Cookie Law

Netherlands Cookie Compliance in 2026

Dutch cookie rules run on two laws at once — the Telecommunicatiewet and the AVG (the Dutch name for GDPR). The Autoriteit Persoonsgegevens now scans roughly 10,000 Dutch websites a year with dedicated government funding, and warns 500 organisations annually. If your site reaches Dutch visitors, here is exactly what it must do.

Updated July 2026 14 min read Includes 2026 AP enforcement data
AP cookie enforcement — the numbers
10,000
Dutch websites scanned by the AP each year
500
Organisations the AP intends to warn annually
€500k
Per year, ring-fenced by government for cookie supervision
42.7%
Of large Dutch homepages load high-risk trackers before consent
€600k
A.S. Watson (Kruidvat) — tracking cookies without valid consent (2024, reduced to €50k on objection in 2025)
€290M
Uber — unlawful EU-US transfers of driver data (2024, AP)
€40k
Coolblue — pre-ticked boxes; "continue" treated as consent (Dec 2025)
200+
Websites warned — retailers, media and insurers in the AP's 2025 cookie campaign
Background

Why Dutch cookie compliance runs on two laws

The Netherlands applies GDPR plus a national implementation of the ePrivacy Directive — but the split is unusually explicit, and reading Dutch guidance correctly depends on knowing which law is speaking.

The Telecommunicatiewet (Dutch Telecommunications Act), Article 11.7a, governs the act of placing or reading anything on a visitor's device. It applies whenever you store or access information on that device — regardless of whether the data is personal. This is the Dutch implementation of ePrivacy Article 5(3), and it is often called the cookiewet.

The AVGAlgemene verordening gegevensbescherming, simply the Dutch name for GDPR — governs what happens to personal data once collected. Alongside it sits the UAVG (Uitvoeringswet AVG), the Dutch implementation act that fills in national details GDPR left to member states.

 Telecommunicatiewet art. 11.7aAVG (GDPR)
What it governsPlacing & reading cookies on a deviceProcessing of personal data
When it appliesAny time you store or access anything on the user's deviceOnly when the data collected is personal data
Formal supervisorAutoriteit Consument & Markt (ACM)Autoriteit Persoonsgegevens (AP)
Maximum penaltyUp to €900,000 per violation (art. 15.4), or in some cases 1–10% of turnoverUp to €20M or 4% of global annual turnover
Territorial scopeNetherlandsWhole EU/EEA
⚖️

In practice, the AP enforces cookies — not the ACM

Although the Telecommunicatiewet formally sits under the ACM, it is the Autoriteit Persoonsgegevens that runs cookie enforcement in the Netherlands. The reason is simple: nearly every tracking cookie processes personal data, which pulls it into the AVG and therefore the AP's remit. Most Dutch cookie failures breach both laws simultaneously. When you read about Dutch cookie enforcement, you are almost always reading about the AP.

Does this apply if my business isn't Dutch?

Yes. The AVG applies to any organisation established in the Netherlands regardless of where processing happens, and to organisations outside the EU that offer goods or services to people in the Netherlands or monitor their behaviour. Running analytics or advertising pixels on a site that Dutch residents visit is monitoring behaviour. A foreign company targeting Dutch residents must comply with both the AVG and the UAVG.

Core requirement

The Dutch word for consent is toestemming, and the standard is the AVG's: freely given, specific, informed, and unambiguous. Article 11.7a's core obligation is a sequence — inform first, then ask permission, and only then place the cookie. The AP's 2025 guidance sharpened four points that Dutch banners routinely fail.

1

Reject must sit on layer one

If an "Accept all" button appears on the first layer of the banner, a "Reject all" button must appear there too — at the same prominence. Burying refusal one click deeper is the single most-cited Dutch violation.

2

Nothing fires before the click

Trackers must be technically blocked until the visitor actively consents. The A.S. Watson case turned on cookies firing both before and after the consent flow — the banner existed, the blocking didn't.

3

No pre-ticked boxes

Pre-ticked advertising or analytics categories are not consent — settled EU case law, and the exact finding in both the A.S. Watson and Coolblue decisions. Every non-essential category starts unchecked.

4

No cookiemuur

The AP prohibits cookie walls that condition site access on accepting tracking. Consent conditioned on access is not freely given. The Dutch position aligns with France's CNIL and Belgium's APD.

🚫

A banner is not blocking — and the AP checks the difference

Independent research on 150 large Dutch corporate websites found 42.7% of homepages loaded high-risk trackers before the visitor consented — Meta, Hotjar, LinkedIn Ads and similar, all processing personal data on page load while the banner was still on screen. Every one of those sites had a cookiebanner. The banner was never the issue.

What a compliant Dutch cookiebanner must and must not do

✕ NON-COMPLIANT

  • Trackers load on page load, before consent is given
  • "Accept all" on layer one, "Reject" only in a sub-menu
  • Pre-ticked boxes for analytics or advertising
  • Rejecting takes more clicks than accepting
  • A cookiemuur blocking access until you accept
  • Colour or size making "Accept" visually dominant
  • "Continue browsing" treated as agreement
  • No log of who consented, to what, and when

✓ COMPLIANT

  • All non-essential trackers blocked until active consent
  • "Accept all" and "Reject all" both on layer one, equal weight
  • Every non-essential category unchecked by default
  • Refusing is exactly as easy as accepting — one click
  • Full site access regardless of the visitor's choice
  • Buttons visually equivalent in size, colour and contrast
  • Clear affirmative action required — a click
  • Timestamped consent log, produced on request
Full requirements

All Dutch cookie requirements for website operators

Beyond the banner itself, these are the obligations Dutch websites must address — with the provision each one rests on.

Inform before you ask

Tell visitors what is being stored or accessed and why, before requesting permission. Information first, consent second, cookie third — in that order.

Telecommunicatiewet art. 11.7a

Two narrow exemptions only

Cookies strictly necessary to transmit a communication, and cookies strictly necessary for a service the user explicitly requested (session cookies, shopping carts), need no consent — but must still be disclosed.

Telecommunicatiewet art. 11.7a(3)

Analytics: a partial Dutch exemption

The Netherlands grants analytical cookies a partial exemption where their privacy impact is minimal and results are used only for the site itself. This is more generous than France, but it does not cover Google Analytics in a standard configuration sharing data with Google.

Dutch practice under art. 11.7a

A lawful basis for the processing

Placing the cookie is one question; processing the data is another. The A.S. Watson fine was issued under AVG Article 6(1) with 5(1)(a) — no lawful basis for the processing, not merely a bad banner.

AVG art. 6(1) + art. 5(1)(a)

Withdrawal as easy as consent

Visitors must be able to change or revoke their choice at any time, through a route no harder than the one that granted it — a persistent link, not a buried policy page.

AVG art. 7(3)

Demonstrable, logged consent

Accountability means you must be able to show valid consent: what was shown, what was chosen, and when. The AP asks for this during investigations; a banner with no log proves nothing.

AVG art. 5(2) + art. 7(1)

Pixels and fingerprinting count

EDPB Guidelines 2/2023 (final October 2024) extended ePrivacy Article 5(3) beyond HTTP cookies to tracking pixels, device fingerprinting, local storage and URL tracking. The Meta Pixel and TikTok Pixel need prior toestemming.

EDPB Guidelines 2/2023

Privacyverklaring, current and specific

Your privacy statement must name every tool and third party, the purpose and legal basis for each, and retention periods — in plain Dutch or English. The AP treats a three-year-old privacyverklaring as a sign of neglect.

AVG art. 13–14

Context can aggravate the penalty

In A.S. Watson the AP treated drugstore browsing data — pregnancy tests, contraception, medication — as revealing sensitive information. The category of cookie matters less than what the browsing reveals.

AP boetebeleidsregels

International transfers

Sending Dutch visitors' data to US-based tools requires SCCs or another valid transfer mechanism. The AP's €290M Uber fine was for exactly this failure — transfers without adequate safeguards.

AVG Chapter V
🇪🇺

The EU AI Act is live for Dutch sites too

Article 50 requires disclosure of AI-powered features to EU visitors from 2 August 2026. We built the disclosure into the consent banner — enable the toggle, publish, done.

Learn more →
Enforcement

AP enforcement: from warnings to fines

Dutch cookie enforcement changed character in 2025. For years the AP published guidance and acted on complaints. Then the government ring-fenced money to hunt cookie violations — €500,000 per year for three years, plus a permanent €350,000 annual increase from 2027. That funding bought a scanning operation with a schedule.

WhenWhat happened
15 April 2025The AP sends warning letters to an initial 50 organisations — webshops, media companies and insurers — for misleading cookiebanners or placing trackers without valid consent. Three months to fix.
Through 2025The campaign expands to 200+ websites warned.
Jul–Sep 2025First deadlines expire. Roughly three-quarters of warned organisations adjust their banners.
Oct 2025Formal investigations open against the quarter that did not respond. AP Vice-Chair Monique Verdier confirms: organisations that fail to adjust can expect an investigation or a fine.
Dec 2025Coolblue fined €40,000 — pre-ticked boxes and treating "continue" as consent. Public campaign "Ga slim om met cookies" invites consumers to complain.
2026 onwardAutomated scanning of ~10,000 Dutch websites annually; target of 500 warnings a year; investigations and fines for those who ignore them.
Telecommunicatiewet — cookie placement
€900,000
per violation (art. 15.4) — or 1–10% of turnover in certain cases

Doubles if a similar violation occurred within the previous five years. Applies to the act of placing or reading without valid consent.

AVG — unlawful processing
€20M
or 4% of global annual turnover — whichever is higher

Applies to consent failures and unlawful processing. A lower tier of €10M or 2% covers less severe breaches. This is the tier the AP actually uses for cookies.

How the AP actually calculates a fine. The AP works from published boetebeleidsregels (fine policy rules). Breaches of AVG Articles 5 and 6 fall in category III, with a bandwidth of €300,000 to €750,000 as the starting range — before aggravating or mitigating factors such as the number of people affected, the sensitivity of the data, duration, and how quickly you fixed it. The €600,000 A.S. Watson figure sits inside that band, not at the theoretical €20M ceiling.

The case that shows how this actually plays out

In A.S. Watson — the parent of drugstore chain Kruidvat — the AP found that kruidvat.nl placed tracking cookies both before and after the consent flow, with advertising cookies pre-ticked. Even visitors who completed the toestemming procedure without agreeing to advertising cookies still had them placed. The AP treated the browsing data as especially sensitive: a drugstore's product mix reveals pregnancy tests, contraception and medication, and combined with a visitor ID and IP-derived location it builds what the AP called a highly specific and invasive profile.

The fine was €600,000, issued 2 May 2024. Three details matter more than the headline:

  • It was reduced to €50,000 on objection in June 2025 — but the violation was upheld. The AP's interpretation stands; only the amount moved.
  • The conduct was from 2019–2020. The AP's investigation began in October 2019; the violation ended in October 2020; the fine landed in 2024. Cookie liability has a long tail.
  • The company had a cookiebanner throughout. The banner was never the defect. What fired behind it was.
Live compliance check — fresh Dutch session, no cookies
Meta Pixel (connect.facebook.net)BLOCKED
Google Analytics (gtag / ga.js)BLOCKED
Hotjar (static.hotjar.com)BLOCKED
LinkedIn Insight Tag (snap.licdn.com)BLOCKED
TikTok Pixel (analytics.tiktok.com)BLOCKED
Cookiebanner — Accept & Reject, layer one✓ DISPLAYED
Consent log entry✓ PENDING CHOICE
This is the DevTools network view the AP's scanner reproduces. After the visitor clicks Accept, scripts release and the choice is logged with a timestamp. After Reject, everything above stays blocked. A banner that displays while these rows read "LOADED" is the exact configuration behind the Dutch warning letters.
📌

2026 EU-wide priority: transparency

The European Data Protection Board launched its Coordinated Enforcement Framework for 2026 on transparency obligations under Articles 12–14 — and the AP participates. That puts privacyverklaringen, consent documentation and disclosure clarity under active review across every EU jurisdiction, the Netherlands included. A vague or outdated privacy statement is now a live risk, not a housekeeping item.

Where the Netherlands sits among EU regulators

The Netherlands sits at the stricter end of the EU spectrum, though not the extreme: the cookiemuur ban mirrors France's CNIL and Belgium's APD, while the analytics exemption is more generous than France's. What distinguishes it is structural. Germany's enforcement is split across sixteen state authorities and is correspondingly uneven; the Dutch model is centralised with earmarked, multi-year funding — predictable, sustained pressure rather than sporadic action. A site that satisfies the AP will generally satisfy most of the EU.

Free tool

Scan your site for Dutch cookie violations

Every Dutch enforcement action above began the same way: someone loaded the site with a fresh session and watched what fired before consent — exactly what the AP's scanner does across 10,000 Dutch websites a year. Our free scanner does the same in about ten seconds: it opens your homepage with no cookies, records every tracker that transmits before consent, and tells you which would put you in the AP's warning queue. No account needed.

Action plan

How to make your website compliant for Dutch visitors

1

Install a CMP that blocks, not just displays

This is the whole game. A compliant platform technically prevents non-essential trackers from firing until toestemming is given, presents Accept and Reject with equal prominence on layer one, and logs every decision with a timestamp. ConsentPixel — Privacy · Verified does all three from one script tag — the blocking, the banner, and the log.

2

Put Reject on the first layer, at equal weight

The AP's 2025 guidance is explicit: if "Accept all" is on layer one, "Reject all" must be too — same prominence, same visual weight. This single fix resolves the most-cited violation in the Dutch warning campaign. Check colour, size and contrast, not just presence.

3

Verify what actually fires — don't assume

Open your site in a private window, open DevTools → Network, reload, and watch what transmits before you touch the banner. 42.7% of large Dutch sites fail here while displaying a banner. If Meta, Hotjar or GA4 appear before your click, the banner is decoration.

4

Remove any cookiemuur

If refusing cookies restricts access to your content, that consent is not freely given under the AP's position. Full access must survive a Reject click. This includes soft variants — nagging modals that reappear, or degraded functionality for those who decline.

5

Update the privacyverklaring and name your tools

List every third party that receives visitor data, the purpose, the legal basis and the retention period, in plain language. With the EDPB's 2026 transparency focus and the AP participating, an outdated privacy statement is an active risk — and the AP reads it as evidence of neglect.

6

Keep a consent log you can actually produce

When the AP asks how you obtained consent, "we had a banner" is not an answer. You need per-visitor records: what banner version was shown, which categories were accepted or declined, and when. This is the accountability principle in practice, and it is the difference between a warning and a fine.

7

Check your international transfers

If Dutch visitors' data reaches US-based tools — GA4, HubSpot, Mailchimp, Salesforce — you need Standard Contractual Clauses in place and a signed DPA. The AP fined Uber €290 million for getting this wrong. Verify the DPA is signed, not merely available.

Compliance checklist

Dutch cookie compliance checklist 2026

Tick each item to assess where you stand against what the AP actually checks.

Common questions

Netherlands cookie compliance — frequently asked questions

Which laws govern cookies in the Netherlands?
Two apply together. The Telecommunicatiewet (Dutch Telecommunications Act), Article 11.7a — often called the cookiewet — governs placing or reading information on a visitor's device, and carries penalties up to €900,000 per violation under Article 15.4. The AVG (the Dutch name for GDPR), alongside the UAVG implementation act, governs the processing of personal data and carries penalties up to €20 million or 4% of global turnover. Most Dutch cookie failures breach both at once. Although the Telecommunicatiewet formally falls under the ACM, in practice the Autoriteit Persoonsgegevens enforces cookie rules because nearly all tracking cookies process personal data.
Does the reject button need to be on the first layer of the banner?
Yes. The AP's 2025 guidance states that if an "Accept all" button appears on the first layer, a "Reject all" button must appear on that same layer, at the same prominence level. Making refusal harder than acceptance — an extra click, a sub-menu, or a visually weaker button — is the most frequently cited violation in the AP's warning campaign, which has reached more than 200 Dutch websites.
Are cookie walls (cookiemuur) allowed in the Netherlands?
No. The AP prohibits cookie walls that condition access to a website on accepting tracking cookies, on the basis that consent given under that condition is not freely given. The Dutch position aligns with the French CNIL and the Belgian APD. Visitors must retain full access to your site whether they accept or reject.
Do analytics cookies require consent in the Netherlands?
Analytical cookies receive a partial exemption in the Netherlands where their privacy impact is minimal and the results are used only for the site itself — more generous than France's approach. However, this exemption does not cover a standard Google Analytics configuration that shares data with Google for its own purposes. If your analytics tool transmits data to a third party, treat it as requiring prior consent. Even exempt cookies must still be disclosed.
What fines has the AP actually issued for cookies?
The AP fined A.S. Watson, the parent of drugstore chain Kruidvat, €600,000 in May 2024 for placing tracking cookies on kruidvat.nl without a valid legal basis — including advertising cookies that fired even when visitors declined them. The fine was reduced to €50,000 on objection in June 2025, though the violation itself was upheld. Coolblue was fined €40,000 in December 2025 for pre-ticked boxes and treating "continue" as consent. Separately, the AP fined Uber €290 million in 2024 for unlawful transfers of European driver data to US servers.
What happens if I ignore an AP warning letter?
You can expect a formal investigation or a fine. The AP sent warning letters to more than 200 organisations from April 2025, giving each three months to fix their banner. About three-quarters complied; formal investigations opened against the rest from October 2025. AP Vice-Chair Monique Verdier confirmed that organisations failing to adjust after a warning can expect an investigation or a fine, with administrative penalties reaching €20 million or 4% of global turnover under the AVG.
Does Dutch cookie law apply to my business if I'm not based in the Netherlands?
Yes, if you target Dutch residents. The AVG applies to organisations established in the Netherlands regardless of where processing occurs, and to organisations outside the EU that offer goods or services to people in the Netherlands or monitor their behaviour — which includes running analytics or advertising pixels on a site Dutch residents visit. Foreign companies targeting Dutch residents must comply with both the AVG and the UAVG.
Is the Netherlands stricter than other EU countries on cookies?
The Netherlands sits at the stricter end of the EU spectrum, broadly comparable to France and Belgium — particularly on the cookie wall ban. What sets it apart is structural rather than substantive: the Dutch government ring-fenced €500,000 per year for three years specifically for cookie supervision, with a permanent €350,000 annual increase from 2027. Compared with Germany's enforcement split across sixteen state authorities, the centralised Dutch model with dedicated funding means sustained, predictable pressure. A site that satisfies the AP will generally satisfy most EU regulators.

Compliant for Dutch visitors in 10 minutes

ConsentPixel — Privacy · Verified blocks every non-essential tracker until toestemming is given, puts Accept and Reject on layer one at equal weight, logs every decision with a timestamp, and generates your privacyverklaring. One script tag. AVG, Telecommunicatiewet, and the rest of the EU.

No credit card required · Setup in 10 minutes · Cancel anytime

Not legal advice. This page is an educational summary of Dutch and EU privacy law based on published AP decisions, guidance and reputable reporting. It is not legal advice, and enforcement positions evolve. Verify current requirements with the Autoriteit Persoonsgegevens and consult a qualified Dutch privacy lawyer about your specific situation.
Scroll to Top