[codicts-css-switcher id=”346″]

Global Law Experts Logo
nen 7510 requirements netherlands pdf

Our Expert in Netherlands

NEN 7510 Requirements Netherlands PDF, IGJ Enforcement, 7510-1 vs 7510-2, Wabvpz Duties

By Global Law Experts
– posted 54 minutes ago

Healthcare providers across the Netherlands are legally required to secure patient information in accordance with NEN 7510 requirements, a fact that drives significant search traffic for the NEN 7510 requirements Netherlands PDF and related compliance guidance. The obligation flows from the Wet aanvullende bepalingen verwerking persoonsgegevens in de zorg (Wabvpz), which has mandated adherence to this information security standard since 2008. The Inspectie Gezondheidszorg en Jeugd (IGJ) enforces compliance and can trigger inspections at any time, yet many providers remain unclear on the distinction between NEN 7510-1 (normative requirements) and NEN 7510-2 (implementation guidance), on what evidence IGJ inspectors expect, and on how the standard intersects with GDPR.

This guide maps every obligation, explains the enforcement landscape, and provides a practical evidence matrix so that hospitals, clinics, pharmacies and other care organisations can prepare for scrutiny with confidence.

Is NEN 7510 Mandatory for Healthcare Providers?

Yes, working according to NEN 7510 is a statutory duty for every healthcare provider that processes personal health information in the Netherlands. The obligation is not merely a recommendation; it carries the force of law and is actively overseen by a dedicated regulator.

Legal Basis, the Wabvpz in Plain Language

The Wabvpz (Wet aanvullende bepalingen verwerking persoonsgegevens in de zorg) is the sector-specific statute that supplements the GDPR for healthcare data processing. It requires care providers to implement recognised standards for information security. NEN 7510 is the standard that the Dutch government, the IGJ and the Autoriteit Persoonsgegevens (AP) all treat as the sector benchmark for fulfilling that obligation.

According to the IGJ, healthcare providers have been required by law to comply with NEN 7510 since 2008. The requirement applies to all organisations that fall under the Wabvpz, including:

  • Hospitals and university medical centres. All inpatient and outpatient care facilities.
  • General practitioners (huisartsen) and dental practices. Primary-care settings that hold patient records.
  • Pharmacies. Both hospital pharmacies and community pharmacies dispensing medication.
  • Mental health providers (GGZ). Psychologists, psychiatrists and addiction-care organisations.
  • Home-care and long-term-care organisations. Nursing homes, rehabilitation centres and domiciliary-care providers.
  • Physiotherapy, midwifery and allied-health practices. Any registered care provider processing patient data electronically.

A critical distinction must be understood: the Wabvpz demands that providers work according to the NEN 7510 standard. It does not, however, mandate that every provider hold a formal NEN 7510 certificate. Certification from an accredited body is a powerful way to demonstrate compliance, but the IGJ accepts other forms of evidence that prove an organisation has implemented the standard in practice. Industry observers expect this nuance to be tested more rigorously as IGJ inspection activity intensifies.

NEN 7510 Requirements: The Difference Between NEN 7510-1 and NEN 7510-2

NEN 7510 is published as a two-part standard. Understanding the distinction between NEN 7510-1 and NEN 7510-2 is essential for any compliance programme, because the two documents serve fundamentally different functions.

NEN 7510-1, Normative Requirements

NEN 7510-1 contains the normative requirements, the control objectives that healthcare organisations must meet. The current version, NEN 7510-1:2024, replaced the 2017 edition and aligns more closely with the ISO 27001:2022 structure. NEN 7510-1 sets out what must be achieved, covering areas such as:

  • Information security governance. Board-level accountability, defined roles and documented policies.
  • Risk assessment and treatment. Mandatory identification, evaluation and treatment of information security risks.
  • Access control. Rules for granting, reviewing and revoking access to health information systems.
  • Logging and monitoring. Requirements to record who accessed patient data, when and why.
  • Incident management. Procedures for detecting, reporting and resolving security incidents.
  • Physical and environmental security. Controls protecting server rooms, workstations and physical records.
  • Supplier and third-party management. Obligations to ensure that processors and sub-processors also meet NEN 7510 requirements.

When IGJ inspects a care organisation, it primarily assesses compliance against NEN 7510-1 control objectives. The standard’s normative language, using words such as “shall”, creates binding expectations that inspectors will measure against documented evidence.

NEN 7510-2, Implementation Guidance

NEN 7510-2 is the companion guidance document. It translates the normative requirements of NEN 7510-1 into practical implementation measures. While NEN 7510-2 is not itself mandatory in the same binding sense, it represents the recognised best practice for demonstrating that a provider has met its NEN 7510-1 obligations. In practical terms, organisations that deviate from NEN 7510-2 guidance should document why an alternative measure provides equivalent protection, a “comply or explain” approach that IGJ inspectors understand.

NEN 7510-1 Clause Area NEN 7510-2 Guidance Example Typical Evidence
Information security policy Draft board-approved policy with annual review cycle Signed policy document, board minutes
Risk assessment Use standardised risk-assessment methodology Risk register, residual-risk acceptance forms
Access control Role-based access with quarterly review Access-review reports, RBAC configuration
Logging Automated logging of access to patient records Audit-trail exports, log-retention policy
Supplier management Include NEN 7510 clauses in processor agreements Signed contracts, supplier attestations

Who Enforces NEN 7510 in the Netherlands and How?

Two principal supervisory bodies share responsibility for enforcing NEN 7510 requirements in the Netherlands: the IGJ and the Autoriteit Persoonsgegevens (AP). Their mandates overlap in places but differ in legal basis and sanction type.

IGJ Inspections, What Triggers an Inspection

The IGJ (Inspectie Gezondheidszorg en Jeugd) is the primary enforcer of NEN 7510 for healthcare providers. The IGJ treats information security as a patient-safety issue. Inspections may be triggered by:

  • Routine thematic reviews. The IGJ periodically selects sectors or themes (e.g., information security in mental health) for proactive inspection rounds.
  • Incident reports. A data breach, ransomware attack or patient-safety incident that involves information systems.
  • Complaints and signals. Whistleblower reports, patient complaints or media coverage that raises concern about data security practices.
  • Follow-up inspections. Where previous inspections identified deficiencies and the IGJ returns to verify remediation.

During an inspection, IGJ staff typically request documented evidence that the provider is “working according to” NEN 7510-1. The likely practical effect of failing to produce this evidence is an escalation pathway that may include administrative orders (aanwijzing), enhanced supervision, or, in serious cases, a directive to cease certain processing activities until compliance is achieved.

Role of the Autoriteit Persoonsgegevens (AP) and GDPR Enforcement

The Autoriteit Persoonsgegevens enforces the GDPR across all sectors, including healthcare. Where a healthcare organisation suffers a personal data breach involving patient data, both the AP and the IGJ may become involved, but through separate channels. The AP focuses on data-protection compliance and can impose significant administrative fines under Article 83 of the GDPR. The AP has publicly stated that NEN 7510 is an example of an appropriate standard for information security in healthcare.

Enforcement Body Legal Basis Typical Sanction or Action
IGJ Wabvpz, Wkkgz (healthcare quality legislation) Administrative order (aanwijzing), enhanced supervision, directive to remediate
Autoriteit Persoonsgegevens (AP) GDPR (Regulation (EU) 2016/679), UAVG Administrative fine, enforcement order, binding instructions

Practical Enforcement Outcomes

Early indications suggest that IGJ enforcement activity related to information security is increasing. Where a provider cannot demonstrate structured NEN 7510 compliance, the IGJ has historically issued improvement measures requiring the organisation to complete a gap analysis and remediation plan within a defined timeline. For providers, the reputational and operational consequences of a public IGJ enforcement action can be at least as significant as any financial penalty issued by the AP. Maintaining audit-ready evidence is therefore not merely a legal obligation, it is a governance priority.

Wabvpz Duties and GDPR Intersection, What Healthcare Providers Must Do

The Wabvpz and the GDPR impose parallel but distinct obligations on healthcare providers. Understanding where they overlap, and where NEN 7510 fits, is essential for building a compliant information security programme.

The Wabvpz requires care providers to implement “appropriate technical and organisational measures” when processing personal health data. NEN 7510 is the sector-standard framework that satisfies this requirement. Simultaneously, the GDPR (Article 32) imposes a technology-neutral obligation to implement security measures “appropriate to the risk.” The AP treats NEN 7510 as a recognised way to fulfil this Article 32 duty for healthcare providers.

DPIA and High-Risk Processing in Healthcare

Under Article 35 of the GDPR, a Data Protection Impact Assessment (DPIA) is mandatory when processing is “likely to result in a high risk” to individuals. Processing of health data at scale, which describes virtually every hospital and most GP practices, meets this threshold. A DPIA should map data flows, identify risks, and reference NEN 7510-1 controls as mitigating measures. The AP has published guidance listing healthcare processing among the categories that require a DPIA, and NEN 7510 provides the natural control framework against which to assess residual risk.

Contracts with Processors, Minimum Clauses Aligning to NEN 7510

Where a healthcare provider uses external IT suppliers, cloud platforms or managed service providers, the Wabvpz and GDPR (Article 28) require a written processor agreement. For NEN 7510 compliance, these contracts should include:

  • Obligation to comply with NEN 7510. The processor must commit to implementing measures that meet or exceed the controls in NEN 7510-1 and NEN 7510-2.
  • Audit rights. The provider must retain the right to audit the processor’s NEN 7510 compliance or receive third-party attestation reports.
  • Incident-notification obligations. The processor must notify the provider without undue delay upon discovering any security incident affecting patient data.
  • Sub-processor controls. The processor must obtain prior written authorisation before engaging sub-processors and ensure equivalent security measures.

When to Notify AP vs IGJ

Following a data breach involving personal health data, the notification routes are distinct. The AP must be notified within 72 hours under Article 33 of the GDPR, unless the breach is unlikely to result in a risk to individuals’ rights. The IGJ should be notified where the breach constitutes a care-quality incident that could affect patient safety, for example, where unavailability of health information systems delays treatment. In practice, a significant ransomware attack on a hospital would typically trigger notifications to both bodies simultaneously.

How to Evidence NEN 7510 Compliance, IGJ-Ready Checklist and Evidence Matrix

Demonstrating compliance requires more than an information security policy on a shelf. IGJ inspectors assess whether the NEN 7510 requirements are embedded in daily operations, governance structures and technical controls. The following evidence matrix and NEN 7510 checklist provide a practical framework for inspection readiness.

Essential Documents IGJ Will Ask to See

Based on publicly available IGJ guidance and sector experience, the following categories of evidence are routinely requested during information security inspections:

  • Board-approved information security policy. Demonstrates governance commitment; must be reviewed at least annually.
  • Formal risk register. Shows systematic identification and treatment of information security risks.
  • Access-control records. Evidence that access to patient data follows the need-to-know principle and is reviewed regularly.
  • Incident-response plan and incident logs. Documented procedures for managing security incidents, plus records of past incidents and remediation actions.
  • Training records. Proof that staff receive regular information security awareness training.
  • Supplier and processor agreements. Contracts with IT vendors that include NEN 7510 obligations and audit rights.
  • Internal or external audit reports. Findings from assessments against NEN 7510-1 and remediation trackers.

Evidence Format, What Is Acceptable

The IGJ does not prescribe a single format. Acceptable evidence includes signed PDF documents, board meeting minutes, configuration screenshots from identity-management systems, automated audit-trail exports, and formal attestation letters from processors. The critical requirement is traceability: every piece of evidence must identify who approved it, when, and how it maps to a specific NEN 7510-1 clause.

NEN 7510 Checklist, Sample IGJ-Ready Evidence Matrix

NEN 7510-1 Clause (Summary) Example Evidence to Present Where to Store / Who Signs Off
Information security policy and governance Board-approved policy, annual review minutes, assigned CISO or information security officer role Document management system / Board secretary
Risk assessment and treatment Formal risk register, residual-risk acceptance forms, remediation tracker with deadlines GRC tool or spreadsheet / CISO
Access control and user management User access logs, quarterly access-review reports, privileged-access inventory IAM system / IT manager
Logging and monitoring Audit-trail configuration documentation, sample log extracts, log-retention policy SIEM or logging platform / IT security lead
Incident management Incident-response plan, incident register with root-cause analyses, post-incident review reports Incident-management tool / CISO
Physical and environmental security Server-room access logs, environmental monitoring reports, visitor-registration procedures Facilities management system / Facilities manager
Supplier and processor management Signed processor agreements with NEN 7510 clauses, supplier audit reports or attestations Contract repository / Legal or procurement lead
Staff awareness and training Training attendance records, phishing-simulation results, competency-assessment outcomes HR / Learning management system
Business continuity and disaster recovery BCP/DRP documentation, test results, recovery-time objectives per system Business continuity coordinator / IT director

A prioritised approach to building this evidence portfolio begins with governance documents (policy and risk register), proceeds to access-control and logging evidence, and concludes with supplier attestations and training records. Industry observers expect that providers with a fully populated evidence matrix will significantly reduce the time and stress associated with any IGJ inspection.

NEN 7510 vs ISO 27001, A Practical Comparison for Healthcare

Many healthcare organisations ask whether ISO 27001 certification is sufficient or whether NEN 7510 compliance is also needed. The short answer: NEN 7510 is the legally required standard under the Wabvpz, while ISO 27001 is a general-purpose international framework. The two are closely related but not interchangeable.

Topic NEN 7510 (Healthcare-Specific) ISO 27001 (General-Purpose)
Scope Healthcare-specific controls for processing personal health information in the Netherlands Generic information security management system (ISMS) applicable across all sectors worldwide
Legal mandate in NL Required under Wabvpz for healthcare providers; enforced by IGJ No sector-specific legal mandate in NL; widely adopted voluntarily
Certification Certification available from accredited bodies; law requires “working according to” the norm, not necessarily holding a certificate International certification through accredited certification bodies; globally recognised
Control catalogue Contains healthcare-focused controls (patient data flows, Wabvpz alignment, health-specific logging) Annex A control catalogue; broader but not sector-specific
Relationship NEN 7510-1:2024 is structured to align with ISO 27001:2022, with healthcare-specific additions Serves as the structural foundation that NEN 7510 builds upon

The practical recommendation for Dutch healthcare providers is to adopt a combined approach: use ISO 27001 as the ISMS framework and supplement it with NEN 7510-specific controls. Providers that hold only ISO 27001 certification should conduct a gap analysis against NEN 7510-1 to identify healthcare-specific requirements that ISO 27001 does not address, such as NEN 7513 (logging of access to patient data) and NEN 7512 (data exchange).

Practical Next Steps, Sample Contractual Clauses and Risk Priorities

Healthcare providers seeking to establish or strengthen NEN 7510 compliance should take three immediate actions:

  1. Conduct a gap analysis against NEN 7510-1:2024. Map current controls to each clause and identify shortfalls.
  2. Launch an evidence-collection sprint. Populate the evidence matrix above with existing documentation and flag gaps for remediation.
  3. Obtain governance sign-off. Secure board-level approval of the information security policy and residual-risk acceptance.

For processor agreements, consider including language such as:

  • Security obligation clause: “The Processor shall implement and maintain technical and organisational measures in accordance with NEN 7510-1:2024 and NEN 7510-2:2024, or demonstrably equivalent measures, for the duration of the Agreement.”
  • Audit-rights clause: “The Controller shall have the right, on reasonable notice, to audit the Processor’s compliance with NEN 7510, or to receive an independent third-party attestation report, at least annually.”

Conclusion

Meeting the NEN 7510 requirements Netherlands PDF obligations is not optional for Dutch healthcare providers, it is a statutory duty under the Wabvpz, actively enforced by the IGJ and reinforced by the Autoriteit Persoonsgegevens under the GDPR. Providers that understand the distinction between NEN 7510-1 and NEN 7510-2, maintain a populated evidence matrix, and embed information security governance at board level will be well positioned for any inspection. For organisations seeking tailored guidance on NEN 7510 compliance, gap analyses or IGJ-readiness reviews, qualified legal counsel with healthcare governance expertise can make the difference between audit confidence and enforcement risk.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Bob van der Kamp at Coupry B.V., a member of the Global Law Experts network.

Sources

  1. NEN, NEN 7510-1:2024 Documentation
  2. Inspectie Gezondheidszorg en Jeugd (IGJ), Questions about NEN 7510
  3. Autoriteit Persoonsgegevens, Securing Health Data
  4. EUR-Lex, Regulation (EU) 2016/679 (GDPR)
  5. Rijksoverheid, Healthcare (Gezondheidszorg)

FAQs

Is NEN 7510 mandatory for Dutch healthcare providers?
Yes. The Wabvpz requires healthcare providers to work according to NEN 7510 when processing personal health data. This obligation has been in force since 2008 and is enforced by the IGJ.
NEN 7510-1 contains the normative requirements, the control objectives that providers must meet. NEN 7510-2 provides implementation guidance explaining how to satisfy those requirements in practice. Both are published by NEN and the current versions date from 2024.
The law requires working according to the standard, not necessarily holding a formal certificate. However, certification from an accredited body is a recognised way to demonstrate compliance and can simplify IGJ inspections considerably.
The Wabvpz supplements the GDPR for healthcare and specifically requires providers to implement recognised security standards. NEN 7510 is the standard the regulator and supervisory bodies recognise. Compliance with both the Wabvpz and GDPR Article 32 is effectively demonstrated through NEN 7510 adherence.
NEN 7510 is a healthcare-specific standard structured to align with ISO 27001 but containing additional controls for processing health data. ISO 27001 alone does not satisfy the Wabvpz requirement, providers should supplement ISO 27001 with NEN 7510-specific controls.
The normative text of NEN 7510-1:2024 and NEN 7510-2:2024 can be purchased from the Royal Netherlands Standardization Institute (NEN) at nen.nl. The 2024 editions replace the 2017 versions and should be used for all new compliance programmes.
IGJ inspectors commonly request a board-approved information security policy, a formal risk register, access-control records, incident logs, staff training evidence, supplier agreements with NEN 7510 clauses, and internal or external audit reports. All evidence should be traceable to specific NEN 7510-1 clauses.
how to compute overtime pay in saudi arabia
By Global Law Experts

posted 3 hours ago

digital asset business bermuda
By Jonathon Richards

posted 3 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

NEN 7510 Requirements Netherlands PDF, IGJ Enforcement, 7510-1 vs 7510-2, Wabvpz Duties

Send welcome message

Custom Message