In our June newsletter, you will find the following topics: |
|
|
|
|
|
|
|
Public Consultation on the Health Information System Act (EHDS) |
On May 27, the European Commission (the Commission) published a consultation on the draft Health Information System Act (GIS Act), which constitutes the first phase of implementation of the European Health Data Space (EHDS).
At this stage, the bill focuses primarily on the structure of the Dutch health information system and the designation of competent authorities for the implementation and supervision of the EHDS. For example, a new Health Data Authority will be established to consolidate various tasks, including facilitating access to health data and supervising its use.
In addition, the oversight and enforcement framework is being prepared, in line with existing regimes under the Act on Electronic Data Exchange in Healthcare (Wegiz) and the Act on Supplementary Provisions for the Processing of Personal Data in Healthcare (Wabvpz). The conformity system for electronic patient records will also be aligned with the system prescribed by the EHDS. |
|
|
|
| |
|
|
Commission Seeks Input on Guidelines for “Trusted Flaggers” Under the DSA |
On May 29, the Commission launched a consultation on draft guidelines for so-called trusted flaggers under the Digital Services Act (DSA).
Trusted flaggers are organizations with specific expertise in identifying illegal content online; reports from these organizations must be given priority by platforms under Article 22 of the DSA. At the same time, the platform remains responsible for the final assessment of whether the content is illegal.
The draft guidelines provide further details on the criteria and procedure for the designation of trusted flaggers by national Digital Services Coordinators. In addition, they contain guidelines for the technical processing of reports and safeguards to ensure the independence, objectivity, and accountability of trusted flaggers. Attention is also given to the misuse of the mechanism, including through transparency obligations and the possibility of suspending or revoking the status of a trusted flagger.
The consultation runs until July 10, 2026, after which the Commission intends to adopt the final guidelines in the second half of 2026. |
|
|
|
| |
|
|
ESAs Publish First Report on Major ICT Incidents Under DORA |
On June 3, the European supervisory authorities EBA, EIOPA, and ESMA (collectively: the ESAs) published their first annual report on major ICT-related incidents in the financial sector, pursuant to Article 22(2) of the Digital Operational Resilience Act (DORA).
The report shows that in 2025, a total of 3,383 major ICT incidents were reported by financial institutions in the EU, with approximately one-third having cross-border implications. The main causes of these incidents were system failures and external events, with a significant portion also related to dependencies on third-party ICT providers (outsourcing and cloud).
Although the number of incidents is high, the impact on clients and transactions remained limited in many cases, which, according to the ESAs, is partly due to effective detection and response mechanisms. At the same time, the report emphasizes that ICT risks are becoming increasingly cross-border and systemically relevant, underscoring the importance of harmonized reporting and supervisory systems under DORA.
In practice, this report confirms that DORA focuses not only on technical security measures but also explicitly on governance and third-party risk management. In particular, financial institutions will be expected to identify and manage their dependencies on IT suppliers, in line with the obligations set forth in Chapter IV of DORA (incident management and reporting). |
|
|
|
| |
|
|
Dutch Senate Adopts Omnibus Data Protection Act |
On June 9, the Dutch Senate adopted the Data Protection Omnibus Act bill as a so-called ‘hammer piece’ (without debate).
The Omnibus Act contains a broad range of amendments to the GDPR Implementation Act (UAVG) and related legislation, with the aim of updating data protection law and clarifying certain aspects of it. Among other things, the Act introduces additional, sector-specific legal bases for data processing, including for trustees, administrators, and accountants. In addition, the bill contains amendments regarding the status of minors, transaction monitoring by financial institutions, and the processing and transfer of medical data.
The nature of an omnibus bill means that the amendments are largely technical and scattered, with no single central change to the regulations. At the same time, it is notable that the legislature is increasingly opting to explicitly include sector-specific legal bases for processing alongside the general framework of Articles 6 and 9 of the GDPR, thereby further refining data protection law.
This development is in line with broader legislative trends in the areas of digitization and data protection. Various regulations in this area are becoming increasingly interconnected. Examples include the GDPR, sector-specific regulations, and the emergence of new European regulatory frameworks in the areas of AI and cybersecurity. For organizations, this means that compliance can no longer be managed solely on a law-by-law basis but requires an integrated approach to data governance, risk management, and oversight.
It has not yet been determined when the Data Protection Omnibus Act will take effect.
Read more about the bill and view the report from the Senate meeting, during which the bill was adopted without debate (Dutch only). |
|
|
|
| |
|
|
Dutch Supreme Court on the Identification Requirement and Processing of Passport Photos by Payment Service Providers |
On 12 June, the Dutch Supreme Court handed down a ruling in a case concerning the obligation of payment service providers to (re)identify customers.
The case concerns a cardholder who refuses to cooperate with re-identification as part of customer due diligence under the Money Laundering and Terrorist Financing (Prevention) Act (Wwft), in particular due to the requirement to provide and allow the storage of a copy of her identity document, including a passport photograph
In the interim judgment of 13 March, the Supreme Court held that a passport photograph does not automatically qualify as biometric data within the meaning of Article 4(14) of the GDPR. For this to be the case, there must be specific technical processing of physical, physiological or behavioural characteristics for the purpose of uniquely identifying a natural person. In this context, an ordinary passport photograph may serve as the source for biometric processing, but is not automatically a biometric data element in itself.
In the referral judgment of 12 June, the Supreme Court has not yet definitively ruled on this matter, but has nevertheless referred questions regarding the classification and lawfulness of the processing of photographs for identification purposes. This is partly in light of the Comdribus judgment, in which the Court of Justice of the European Union (CJEU) ruled that the taking of fingerprints and photographs for identification purposes in a criminal justice context may involve the processing of special categories of personal data and is permitted only under strict conditions, including strict necessity and a sufficiently specific justification.
The Supreme Court has referred questions for a preliminary ruling concerning the classification and lawfulness of the processing of passport photographs, including the question of whether the capture and storage of a facial photograph for identification purposes may, under certain circumstances, be regarded as the processing of biometric data. In addition, the Supreme Court asks whether photographs in which a person is recognisably depicted can qualify as personal data revealing racial or ethnic origin within the meaning of Article 9 of the GDPR, and under what conditions this is the case.
The Supreme Court has also referred the key question regarding the retention obligation under the Wwft to the Court of Justice of the European Union. It asks whether the AML Directive, which forms the basis of the Wwft, obliges Member States to require financial institutions to retain a copy of proof of identity. In this context, the follow-up question is explicitly raised as to whether such a retention obligation also encompasses the retention of a full copy, including a passport photograph.
The key questions regarding the classification of passport photographs under Article 9 of the GDPR and the scope of the retention obligation under the Wwft therefore remain unresolved. The answers to the questions referred for a preliminary ruling will determine the future structure of customer identification and KYC processes. |
|
|
|
| |
|
|
Public Consultation on the Cybersecurity Regulation for Higher Education |
On 12 June, the Government launched an online consultation on the Higher Education Cybersecurity Regulations, which set out further details of the Cybersecurity Act and the Cybersecurity Decree.
The regulations classify publicly funded universities and universities of applied sciences as ‘critical entities’ and impose obligations on them regarding information security and the reporting of significant cyber incidents. In addition, they provide for sector-specific supervision by the Education Inspectorate and support from a sectoral CSIRT.
This regulation must be viewed in the context of the implementation of the NIS2 Directive, which obliges Member States to achieve a high common level of cybersecurity. Essential and important entities must, amongst other things, take appropriate technical and organisational measures (duty of care) and report incidents (duty to report).
Sector-specific measures such as this scheme provide an increasingly concrete interpretation of the open standards set out in the NIS2 Directive and the Cybersecurity Act. Institutions are therefore expected to organise their information security and incident management in a sector-specific manner, partly in light of further regulations and supervision by the designated authorities. |
|
|
|
| |
|
|
|
|
Marc Elshof attorney-at-law | partner
T: +31 70 376 06 87 M:+31 6 46 37 61 08 marc.elshof@barentskrans.nl
|
|
|
|
|
Lars Groeneveld attorney-at-law | senior associate
T: +31 70 376 06 48 M:+31 6 46 11 04 57 lars.groeneveld@barentskrans.nl
|
|
|
|
|
Job Julicher attorney-at-law
T: +31 70 376 08 10 M:+31 6 27 42 99 77 job.julicher@barentskrans.nl
|
|
|
|
|
Julius Louter attorney-at-law
T: +31 70 376 06 40 M:+31 6 15 43 37 52 julius.louter@barentskrans.nl
|
|
|
|
|
|
BarentsKrans
The Hague | Amsterdam +31 70 376 06 06 communicatie@barentskrans.nl www.barentskrans.nl |
| |
|
|
| |
|
|
|