Skip to content
Dutch DPA Issues GDPR Compliance
Nemko DigitalAug 26, 2026, 10:30:02 AM3 min read

Dutch Regulator Publishes GDPR Self-Assessment Framework for Generative AI Deployment

This development follows the AP's broader strategy, which includes its Annual Plan 2026-2028 and previous consultations on GDPR preconditions for AI. The new framework provides a three-phase approach for organizations to navigate the complexities of generative AI data privacy when integrating generative AI models and new generative AI tools into their businesses processes.

 

Phase 1: Establishing Foundational Data Governance

Before selecting or deploying a generative AI system, the AP emphasizes the necessity of "getting the basics right." Organizations are expected to implement robust data governance measures. This includes maintaining an accurate record of processing activities, establishing clear visibility into the personal data and customer data involved, and enforcing stringent access and authorization controls. Furthermore, organizations utilizing cloud-based AI services must ensure that appropriate processor agreements and necessary compliance controls are in place. These foundational privacy safeguards help address AI privacy risks and establish effective governance frameworks.

 

Phase 2: Selecting a GDPR-Compliant AI System

The second phase focuses on the critical decision-making process of choosing a specific generative AI system. The AP outlines several core GDPR principles that must guide this selection:

Purpose Limitation: Deploying generative AI requires clear, specific, and legitimate objectives. Vague goals such as "improving efficiency" are deemed insufficient. Organizations must be capable of explaining the necessity of personal data processing, including any personal information or created personal data, and how the AI model will be utilized.

Transparency and Explainability: Organizations must ensure they can adequately explain the system's operations, the data it processes, and how its outputs are generated. Transparency remains a cornerstone of responsible AI regulation, meaningful information, and data subject rights compliance.

Privacy by Design: The framework strongly advocates for selecting systems with built-in technical and organizational safeguards, such as ongoing data filtering and output monitoring, to protect personal data throughout the AI lifecycle. Organizations should also consider privacy assessments and employee privacy considerations where employee monitoring or workplace use is involved.

Data Minimization and Storage Limitation: Only personal data strictly necessary for the intended use case should be processed. Organizations are required to define clear retention periods and curate training datasets to minimize privacy risks. These measures should apply to such data as well as other data processed by generative AI systems.

 

Phase 3: Ongoing Deployment and Governance

 

GDPR Compliance for generative AI

 

The final phase addresses the continuous governance required once a generative AI system is active. The AP stresses that GDPR compliance is not a one-time assessment but an ongoing obligation, particularly as regulations and AI-specific regulations continue shaping deployment practices.

Key requirements during deployment include conducting thorough vendor due diligence to ensure models were trained lawfully. Organizations must also implement technical measures to prevent the reproduction of personal data in AI outputs, acknowledging the challenges of executing individual rights requests - such as access or erasure - when data is embedded in model parameters. The AP suggests output filtering as a current best practice to mitigate these risks. Organizations should also assess whether explicit user consent is required and maintain clear privacy notices explaining how a personal data subject's information is used.

 

What Organizations Should Watch For Next

The AP's guidance serves as its leading interpretation of GDPR application to generative AI, pending further direction from the European Data Protection Board (EDPB) or finalization of the proposed Digital Omnibus reform. Organizations should monitor the ICO, UK GDPR developments, and other compliance regulations as global regulations continue to evolve.

Organizations deploying generative AI should proactively utilize the AP's self-assessment tool as a baseline for evaluating their systems. Additionally, they should verify the need for a Data Protection Impact Assessment (DPIA) prior to deployment and establish robust processes for continuous monitoring and handling data subject rights requests. In the early stages of generative AI use, organizations should consider the eight GDPR questions that guide lawful and fair processing, including whether a use case is high risk and whether it could affect individuals' freedoms. As regulatory expectations evolve, maintaining a dynamic approach to AI trust and compliance will be essential for navigating the intersection of innovation, fairness, and data protection.

avatar
Nemko Digital
Nemko Digital is formed by a team of experts dedicated to guiding businesses through the complexities of AI governance, risk, and compliance. With extensive experience in capacity building, strategic advisory, and comprehensive assessments, we help our clients navigate regulations and build trust in their AI solutions. Backed by Nemko Group’s 90+ years of technological expertise, our team is committed to providing you with the latest insights to nurture your knowledge and ensure your success.

RELATED ARTICLES