Our Expert in Netherlands
No results available
Healthcare providers across the Netherlands are legally required to secure patient information in accordance with NEN 7510 requirements, a fact that drives significant search traffic for the NEN 7510 requirements Netherlands PDF and related compliance guidance. The obligation flows from the Wet aanvullende bepalingen verwerking persoonsgegevens in de zorg (Wabvpz), which has mandated adherence to this information security standard since 2008. The Inspectie Gezondheidszorg en Jeugd (IGJ) enforces compliance and can trigger inspections at any time, yet many providers remain unclear on the distinction between NEN 7510-1 (normative requirements) and NEN 7510-2 (implementation guidance), on what evidence IGJ inspectors expect, and on how the standard intersects with GDPR.
This guide maps every obligation, explains the enforcement landscape, and provides a practical evidence matrix so that hospitals, clinics, pharmacies and other care organisations can prepare for scrutiny with confidence.
Yes, working according to NEN 7510 is a statutory duty for every healthcare provider that processes personal health information in the Netherlands. The obligation is not merely a recommendation; it carries the force of law and is actively overseen by a dedicated regulator.
The Wabvpz (Wet aanvullende bepalingen verwerking persoonsgegevens in de zorg) is the sector-specific statute that supplements the GDPR for healthcare data processing. It requires care providers to implement recognised standards for information security. NEN 7510 is the standard that the Dutch government, the IGJ and the Autoriteit Persoonsgegevens (AP) all treat as the sector benchmark for fulfilling that obligation.
According to the IGJ, healthcare providers have been required by law to comply with NEN 7510 since 2008. The requirement applies to all organisations that fall under the Wabvpz, including:
A critical distinction must be understood: the Wabvpz demands that providers work according to the NEN 7510 standard. It does not, however, mandate that every provider hold a formal NEN 7510 certificate. Certification from an accredited body is a powerful way to demonstrate compliance, but the IGJ accepts other forms of evidence that prove an organisation has implemented the standard in practice. Industry observers expect this nuance to be tested more rigorously as IGJ inspection activity intensifies.
NEN 7510 is published as a two-part standard. Understanding the distinction between NEN 7510-1 and NEN 7510-2 is essential for any compliance programme, because the two documents serve fundamentally different functions.
NEN 7510-1 contains the normative requirements, the control objectives that healthcare organisations must meet. The current version, NEN 7510-1:2024, replaced the 2017 edition and aligns more closely with the ISO 27001:2022 structure. NEN 7510-1 sets out what must be achieved, covering areas such as:
When IGJ inspects a care organisation, it primarily assesses compliance against NEN 7510-1 control objectives. The standard’s normative language, using words such as “shall”, creates binding expectations that inspectors will measure against documented evidence.
NEN 7510-2 is the companion guidance document. It translates the normative requirements of NEN 7510-1 into practical implementation measures. While NEN 7510-2 is not itself mandatory in the same binding sense, it represents the recognised best practice for demonstrating that a provider has met its NEN 7510-1 obligations. In practical terms, organisations that deviate from NEN 7510-2 guidance should document why an alternative measure provides equivalent protection, a “comply or explain” approach that IGJ inspectors understand.
| NEN 7510-1 Clause Area | NEN 7510-2 Guidance Example | Typical Evidence |
|---|---|---|
| Information security policy | Draft board-approved policy with annual review cycle | Signed policy document, board minutes |
| Risk assessment | Use standardised risk-assessment methodology | Risk register, residual-risk acceptance forms |
| Access control | Role-based access with quarterly review | Access-review reports, RBAC configuration |
| Logging | Automated logging of access to patient records | Audit-trail exports, log-retention policy |
| Supplier management | Include NEN 7510 clauses in processor agreements | Signed contracts, supplier attestations |
Two principal supervisory bodies share responsibility for enforcing NEN 7510 requirements in the Netherlands: the IGJ and the Autoriteit Persoonsgegevens (AP). Their mandates overlap in places but differ in legal basis and sanction type.
The IGJ (Inspectie Gezondheidszorg en Jeugd) is the primary enforcer of NEN 7510 for healthcare providers. The IGJ treats information security as a patient-safety issue. Inspections may be triggered by:
During an inspection, IGJ staff typically request documented evidence that the provider is “working according to” NEN 7510-1. The likely practical effect of failing to produce this evidence is an escalation pathway that may include administrative orders (aanwijzing), enhanced supervision, or, in serious cases, a directive to cease certain processing activities until compliance is achieved.
The Autoriteit Persoonsgegevens enforces the GDPR across all sectors, including healthcare. Where a healthcare organisation suffers a personal data breach involving patient data, both the AP and the IGJ may become involved, but through separate channels. The AP focuses on data-protection compliance and can impose significant administrative fines under Article 83 of the GDPR. The AP has publicly stated that NEN 7510 is an example of an appropriate standard for information security in healthcare.
| Enforcement Body | Legal Basis | Typical Sanction or Action |
|---|---|---|
| IGJ | Wabvpz, Wkkgz (healthcare quality legislation) | Administrative order (aanwijzing), enhanced supervision, directive to remediate |
| Autoriteit Persoonsgegevens (AP) | GDPR (Regulation (EU) 2016/679), UAVG | Administrative fine, enforcement order, binding instructions |
Early indications suggest that IGJ enforcement activity related to information security is increasing. Where a provider cannot demonstrate structured NEN 7510 compliance, the IGJ has historically issued improvement measures requiring the organisation to complete a gap analysis and remediation plan within a defined timeline. For providers, the reputational and operational consequences of a public IGJ enforcement action can be at least as significant as any financial penalty issued by the AP. Maintaining audit-ready evidence is therefore not merely a legal obligation, it is a governance priority.
The Wabvpz and the GDPR impose parallel but distinct obligations on healthcare providers. Understanding where they overlap, and where NEN 7510 fits, is essential for building a compliant information security programme.
The Wabvpz requires care providers to implement “appropriate technical and organisational measures” when processing personal health data. NEN 7510 is the sector-standard framework that satisfies this requirement. Simultaneously, the GDPR (Article 32) imposes a technology-neutral obligation to implement security measures “appropriate to the risk.” The AP treats NEN 7510 as a recognised way to fulfil this Article 32 duty for healthcare providers.
Under Article 35 of the GDPR, a Data Protection Impact Assessment (DPIA) is mandatory when processing is “likely to result in a high risk” to individuals. Processing of health data at scale, which describes virtually every hospital and most GP practices, meets this threshold. A DPIA should map data flows, identify risks, and reference NEN 7510-1 controls as mitigating measures. The AP has published guidance listing healthcare processing among the categories that require a DPIA, and NEN 7510 provides the natural control framework against which to assess residual risk.
Where a healthcare provider uses external IT suppliers, cloud platforms or managed service providers, the Wabvpz and GDPR (Article 28) require a written processor agreement. For NEN 7510 compliance, these contracts should include:
Following a data breach involving personal health data, the notification routes are distinct. The AP must be notified within 72 hours under Article 33 of the GDPR, unless the breach is unlikely to result in a risk to individuals’ rights. The IGJ should be notified where the breach constitutes a care-quality incident that could affect patient safety, for example, where unavailability of health information systems delays treatment. In practice, a significant ransomware attack on a hospital would typically trigger notifications to both bodies simultaneously.
Demonstrating compliance requires more than an information security policy on a shelf. IGJ inspectors assess whether the NEN 7510 requirements are embedded in daily operations, governance structures and technical controls. The following evidence matrix and NEN 7510 checklist provide a practical framework for inspection readiness.
Based on publicly available IGJ guidance and sector experience, the following categories of evidence are routinely requested during information security inspections:
The IGJ does not prescribe a single format. Acceptable evidence includes signed PDF documents, board meeting minutes, configuration screenshots from identity-management systems, automated audit-trail exports, and formal attestation letters from processors. The critical requirement is traceability: every piece of evidence must identify who approved it, when, and how it maps to a specific NEN 7510-1 clause.
| NEN 7510-1 Clause (Summary) | Example Evidence to Present | Where to Store / Who Signs Off |
|---|---|---|
| Information security policy and governance | Board-approved policy, annual review minutes, assigned CISO or information security officer role | Document management system / Board secretary |
| Risk assessment and treatment | Formal risk register, residual-risk acceptance forms, remediation tracker with deadlines | GRC tool or spreadsheet / CISO |
| Access control and user management | User access logs, quarterly access-review reports, privileged-access inventory | IAM system / IT manager |
| Logging and monitoring | Audit-trail configuration documentation, sample log extracts, log-retention policy | SIEM or logging platform / IT security lead |
| Incident management | Incident-response plan, incident register with root-cause analyses, post-incident review reports | Incident-management tool / CISO |
| Physical and environmental security | Server-room access logs, environmental monitoring reports, visitor-registration procedures | Facilities management system / Facilities manager |
| Supplier and processor management | Signed processor agreements with NEN 7510 clauses, supplier audit reports or attestations | Contract repository / Legal or procurement lead |
| Staff awareness and training | Training attendance records, phishing-simulation results, competency-assessment outcomes | HR / Learning management system |
| Business continuity and disaster recovery | BCP/DRP documentation, test results, recovery-time objectives per system | Business continuity coordinator / IT director |
A prioritised approach to building this evidence portfolio begins with governance documents (policy and risk register), proceeds to access-control and logging evidence, and concludes with supplier attestations and training records. Industry observers expect that providers with a fully populated evidence matrix will significantly reduce the time and stress associated with any IGJ inspection.
Many healthcare organisations ask whether ISO 27001 certification is sufficient or whether NEN 7510 compliance is also needed. The short answer: NEN 7510 is the legally required standard under the Wabvpz, while ISO 27001 is a general-purpose international framework. The two are closely related but not interchangeable.
| Topic | NEN 7510 (Healthcare-Specific) | ISO 27001 (General-Purpose) |
|---|---|---|
| Scope | Healthcare-specific controls for processing personal health information in the Netherlands | Generic information security management system (ISMS) applicable across all sectors worldwide |
| Legal mandate in NL | Required under Wabvpz for healthcare providers; enforced by IGJ | No sector-specific legal mandate in NL; widely adopted voluntarily |
| Certification | Certification available from accredited bodies; law requires “working according to” the norm, not necessarily holding a certificate | International certification through accredited certification bodies; globally recognised |
| Control catalogue | Contains healthcare-focused controls (patient data flows, Wabvpz alignment, health-specific logging) | Annex A control catalogue; broader but not sector-specific |
| Relationship | NEN 7510-1:2024 is structured to align with ISO 27001:2022, with healthcare-specific additions | Serves as the structural foundation that NEN 7510 builds upon |
The practical recommendation for Dutch healthcare providers is to adopt a combined approach: use ISO 27001 as the ISMS framework and supplement it with NEN 7510-specific controls. Providers that hold only ISO 27001 certification should conduct a gap analysis against NEN 7510-1 to identify healthcare-specific requirements that ISO 27001 does not address, such as NEN 7513 (logging of access to patient data) and NEN 7512 (data exchange).
Healthcare providers seeking to establish or strengthen NEN 7510 compliance should take three immediate actions:
For processor agreements, consider including language such as:
Meeting the NEN 7510 requirements Netherlands PDF obligations is not optional for Dutch healthcare providers, it is a statutory duty under the Wabvpz, actively enforced by the IGJ and reinforced by the Autoriteit Persoonsgegevens under the GDPR. Providers that understand the distinction between NEN 7510-1 and NEN 7510-2, maintain a populated evidence matrix, and embed information security governance at board level will be well positioned for any inspection. For organisations seeking tailored guidance on NEN 7510 compliance, gap analyses or IGJ-readiness reviews, qualified legal counsel with healthcare governance expertise can make the difference between audit confidence and enforcement risk.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Bob van der Kamp at Coupry B.V., a member of the Global Law Experts network.
posted 7 minutes ago
posted 30 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
No results available
Find the right Legal Expert for your business
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message