GDPR Compliance for US Entrepreneurs in the Netherlands
GDPR was the regulation we'd heard the most fear-mongering about before moving to the Netherlands. Massive fines. Complex requirements. An army of lawyers needed.
In reality, for small businesses operating under the Dutch-American Friendship Treaty (DAFT), GDPR compliance is manageable. You won't need a legal team. But you do need to understand the basics, because the rules apply to you from day one of your KVK registration.
Here's what US entrepreneurs actually need to do.
What GDPR Actually Requires
The General Data Protection Regulation (GDPR) governs how businesses collect, store, and use personal data. It applies to every business operating in the EU, regardless of size.
Personal data means any information that identifies a person: names, email addresses, phone numbers, IP addresses, even cookie data.
If your business touches personal data in any way—and it almost certainly does—GDPR applies to you. Client emails, contact forms, invoices with names, newsletter subscribers: all personal data.
The good news: for small businesses, GDPR compliance is mostly about common-sense data handling with some documentation.
The Six Principles
GDPR boils down to six principles. Understand these and everything else follows:
- Lawfulness. You need a legal reason to process personal data (consent, contract, legal obligation, or legitimate interest).
- Purpose limitation. Collect data for a specific purpose and don't use it for something else.
- Data minimization. Only collect what you actually need.
- Accuracy. Keep data correct and up to date.
- Storage limitation. Don't keep data longer than necessary.
- Security. Protect data from breaches with appropriate measures.
For a freelance consultant, this means: collect client contact information for your contract (lawful), use it only for the project (purpose limited), don't ask for unnecessary info (minimized), keep it current (accurate), delete it when the contract ends (storage limited), and don't leave client data on unprotected devices (security).
What Small Businesses Must Do
1. Know What Data You Collect
Make a simple list of all personal data your business handles:
- Client names and contact details
- Email newsletter subscribers
- Website visitor data (analytics, cookies)
- Invoicing information
- Contractor or employee data
This doesn't need to be a formal document. A spreadsheet listing what data, where it's stored, and why you have it is sufficient.
2. Have a Legal Basis
For each type of data, you need a legal basis:
- Contract: Client data needed to deliver your services. This is the most common basis for freelancers.
- Consent: Newsletter signups, marketing emails. People must actively opt in.
- Legal obligation: Tax records you're required to keep for the Belastingdienst (seven-year retention).
- Legitimate interest: Analytics data to improve your website. Use carefully and document your reasoning.
3. Create a Privacy Policy
Required if you have a website (and recommended even if you don't). Your privacy policy should be in plain language and cover:
- What data you collect and why
- Your legal basis for each type
- How long you keep it
- Who you share it with (third parties, cloud services)
- How people can access, correct, or delete their data
- Your contact information
For website-specific requirements, see our business website legal requirements guide.
4. Get Proper Consent for Marketing
If you send marketing emails or newsletters, you need:
- Active opt-in. No pre-checked boxes. People must deliberately subscribe.
- Clear description of what they're signing up for.
- Easy unsubscribe in every email.
- Records of consent. Keep proof of when and how each person subscribed.
This applies to email marketing tools like Mailchimp, ConvertKit, and similar platforms. Most of these tools have GDPR consent features built in.
5. Secure Your Data
You don't need enterprise security, but you do need reasonable measures:
- Password-protect all devices
- Use two-factor authentication on business accounts
- Encrypt sensitive files
- Keep software updated
- Use secure cloud storage (Google Workspace, Microsoft 365)
- Don't store client data on unencrypted USB drives
6. Handle Data Requests
People have the right to:
- Access their data (you must provide it within one month)
- Correct inaccurate data
- Delete their data ("right to be forgotten")
- Export their data in a portable format
- Object to processing based on legitimate interest
As a small business, you probably won't get many requests. But if you do, you need to respond within one month. Have a process ready, even if it's just an email workflow.
Data Processing Agreements
If you use third-party services that process personal data on your behalf (cloud storage, email marketing, CRM, accounting software), you technically need a Data Processing Agreement (verwerkersovereenkomst) with each provider.
The good news: most major services (Google, Microsoft, Mailchimp, Stripe) already have standard DPAs available. You just need to accept them. Check the "legal" or "privacy" sections of each service you use.
For services without a standard DPA, you can use a template from the Autoriteit Persoonsgegevens (AP).
What You Probably Don't Need
A Data Protection Officer (DPO). Only required for organizations that process large-scale sensitive data. A freelance consultant doesn't need one.
A formal Data Protection Impact Assessment (DPIA). Only required for high-risk processing activities (large-scale profiling, systematic monitoring, sensitive data processing). Most DAFT businesses don't qualify.
Extensive documentation. Organizations with fewer than 250 employees are exempt from some record-keeping requirements, unless they process sensitive data or high-risk data regularly.
Pro Tip: The Autoriteit Persoonsgegevens website (autoriteitpersoonsgegevens.nl) has excellent guides in English specifically for small businesses. Their GDPR checklist for SMEs is free and practical.
Common Mistakes US Entrepreneurs Make
Treating email lists casually. In the US, you can buy email lists and cold-email with minimal restrictions (CAN-SPAM). In the Netherlands, unsolicited marketing emails without consent can result in fines. Don't import your US email list and start blasting.
Ignoring cookie consent. Cookie banners aren't optional, and they need to actually block cookies until consent is given. A banner that says "We use cookies" while already tracking visitors doesn't comply. See our guide on website legal requirements.
Over-collecting data. Don't ask for a phone number, address, and company name on a simple contact form. Only collect what you need for the stated purpose.
Keeping data forever. Set retention periods. Client data from a project that ended three years ago should be deleted (unless you need it for tax records). Newsletter subscribers who haven't opened an email in two years should be cleaned from your list.
Enforcement and Fines
The Autoriteit Persoonsgegevens (AP) enforces GDPR in the Netherlands. Fines can reach €20 million or 4% of annual revenue for serious violations.
In practice, the AP focuses enforcement on:
- Large companies and data processors
- Organizations handling sensitive data (health, financial)
- Repeat offenders
- Complaints from individuals
A small DAFT business following reasonable data protection practices is unlikely to face enforcement action. But a complaint from a client or newsletter subscriber can trigger an investigation, so compliance matters.
For your overall business compliance checklist, see our annual requirements guide.
Frequently Asked Questions
Q: Does GDPR apply if all my clients are in the US? A: Yes. GDPR applies to your business because you're established in the EU (registered at KVK in the Netherlands). It doesn't matter where your clients are located. Your data processing activities in the EU are covered.
Q: Do I need to register with the Autoriteit Persoonsgegevens? A: No general registration requirement. You only need to notify the AP if you appoint a Data Protection Officer (which most small businesses don't need) or if you experience a data breach that poses a risk to individuals.
Q: What happens if I have a data breach? A: If a breach poses a risk to people's rights and freedoms (leaked client financial data, exposed personal information), you must notify the AP within 72 hours and inform affected individuals without undue delay. For low-risk breaches (encrypted laptop stolen, no data accessed), you document it internally but don't need to notify.
Digital Guide — $99
We're not immigration lawyers—just Americans who did this. Requirements change, so verify with official sources.