Home | About this website | Privacy Statement: Apeldoorn Municipal Council

Privacy Statement: Apeldoorn Municipal Council

The General Data Protection Regulation (GDPR) comes into force on 25 May 2018. This legislation, as well as other laws such as the Personal Data Basic Registration Act, the Telecommunications Act and the Public Records Act, sets out how organisations must handle personal data. This legislation not only contains rules on, for example, the protection of personal data, but also sets out the rights of data subjects.

In carrying out our duties and obligations as a local authority, we process personal data. We comply with the relevant legislation. In this privacy statement, you can read more about how Apeldoorn City Council handles your personal data.

The municipality also employs special investigating officers (BOAs). The special investigating officers of the municipality of Apeldoorn sometimes also process what is known as ‘police data’. This is personal data to which the Police Data Act (Wpg) applies. If you would like to know more about how we handle police data, please read our specific Wpg Privacy Policy.

The council uses CCTV to ensure the safety of visitors, residents and staff in and around council buildings. Personal data is processed for this purpose. This data is processed to prevent incidents, emergencies and unauthorised visitors, and to investigate such occurrences where necessary. If you would like to know more about CCTV surveillance at council premises, please read our specific Privacy Notice: CCTV Surveillance.

The municipality’s administrative bodies are responsible for the processing carried out by or on behalf of the municipality. They are referred to as ‘data controllers’. The municipality has a number of administrative bodies:

  • The mayor.
  • The Executive Committee (College van B&W).
  • The local council.

The Municipality of Apeldoorn has statutory duties and obligations. In order to carry out these duties and obligations, it is necessary to process personal data. For example, if you apply for a passport or move to Apeldoorn, we will process your personal data. You may also provide personal data to the municipality yourself, for example by filling in an appointment form on our website. We also process personal data in relation to matters such as licences, benefits, safety and care.

In some cases, the local authority processes special categories of personal data. Special categories of personal data include, for example, data relating to a person’s health or ethnic origin. Special categories of personal data are afforded extra protection under the GDPR due to the sensitive nature of this data. This is the case, for example, under the Youth Act, the Participation Act and the Social Support Act. Under these Acts, we are responsible for, for example, youth care within the local authority.

We must handle personal data responsibly. This applies not only to the personal data of our residents, but also to that of our partners and our own staff. We therefore adhere to a number of basic principles:

  • The processing of personal data must be lawful. This means that personal data may only be processed if there is a so-called legal basis for doing so. There are six such legal bases. These are briefly explained below.
  • The processing of personal data is carried out in a proper manner. This means that the processing is carried out fairly and honourably and is therefore not, for example, discriminatory.
  • The processing of personal data is transparent. This means that we are clear about how we handle personal data. This privacy statement is one of the ways in which we strive to be transparent about how we handle your personal data.

The local authority only processes personal data if there is a clear purpose. This is known as ‘purpose limitation’. In addition, the processing of personal data must also have a so-called legal basis.

The GDPR sets out six legal bases:

  • The processing is necessary for the performance of a contract.
  • There is a legal obligation with which the local authority must comply. This includes recording names and addresses for the Basic Register of Persons (BRP) or issuing official documents such as passports or ID cards.
  • To protect vital interests, for example when someone has lost consciousness and their identification details need to be shared.
  • The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority. For example, when the local authority is assigned a specific task by law, such as youth care, but also safety within the local authority’s area.
  • Consent has been given for the processing of personal data. Residents are never forced to give their consent.
  • Where there is a legitimate interest and this interest outweighs that of the data subjects. Where we are carrying out a statutory duty, we may never rely on this ground.

We process your personal data primarily because it is necessary for the performance of a statutory duty. For example, when providing care, registering a birth, or when applying for a benefit or grant. We do this because these are public sector duties. The local authority may also act as a private individual, for example when we purchase land or conduct business. In such cases, the processing of personal data takes place, for example, because it is necessary for the performance of a contract.

The local authority only processes personal data that is necessary for a pre-determined purpose. We endeavour to ensure that we process as little personal data as possible. This is known as the principle of data minimisation. Where it is possible to carry out a task without using personal data, or using data that cannot be traced back to individual persons, we will do so.

Personal data must be accurate. We take steps to delete or correct inaccurate personal data as soon as possible so that it is accurate.

In order to carry out our duties and responsibilities effectively, the local authority often works in partnership with other organisations. These may include other public sector organisations, such as the police, but sometimes also private companies. Whenever we exchange personal data with other parties, we agree on the requirements and conditions that this data exchange must meet. These agreements comply with the law, and we ensure that this is the case.

If we have your personal data processed by a company, we will enter into a data processing agreement. In this data processing agreement, we set out arrangements regarding how the other party must handle personal data appropriately. In this way, we ensure an adequate level of security and that your personal data remains confidential. These data processors include, for example, debt collection agencies, cloud and hosting providers, and IT service providers. We remain ultimately responsible for your personal data at all times.

The municipality of Apeldoorn only engages external parties within the European Union or the European Economic Area (EEA). Exceptions to this rule are made only in exceptional circumstances. When we transfer personal data to parties outside the EEA, this is done in accordance with the requirements of the GDPR, such as making appropriate arrangements regarding the level of data protection in that country. On the the Dutch Data Protection Authority’s website You can find more information about this there.

We do not retain personal data for longer than is necessary. Many of the tasks we carry out are set out in laws and regulations. These laws and regulations often specify retention periods, which we adhere to. In addition, the local authority must also comply with the Public Records Act. If no retention periods are specified in the law, we retain personal data only for as long as is necessary. In doing so, we consider the purpose for which the personal data is being processed.

Whenever we process your personal data, we will inform you of the reasons for doing so. For example, through this general privacy statement. In addition to this right to information, you have other rights. You may exercise the following rights:

  • Right of access

You may ask the local authority to show you what personal data it holds about you. This means that we will provide you with a list of the personal data we process about you.

  • Right to rectification

You can ask the local authority to amend or supplement your personal data. For example, if the information is incorrect or incomplete.

  • Right to have data erased

You can ask the local authority to delete your personal data. As there is sometimes a strict retention period in place, we cannot always delete all personal data.

  • Right to restriction of processing

Under certain circumstances, you may ask the local authority to use your data less frequently or to suspend its use temporarily.

  • Right to data portability

Under certain conditions, this right allows you to have your personal data sent (digitally) to another organisation that requires your personal data.

  • The right to a human perspective when a decision is made

The local authority does not use automated decision-making based on your personal data. For example, you can indicate in an appeal procedure that you wish to invoke this right.

  • Right to object

Under certain circumstances, you may object to the processing of your personal data.

In addition, you may withdraw your consent if we have processed your personal data on the basis of your consent.

On the page Submitting a request under the GDPR and the Wpg You can find more information about your rights here. You can submit a request to Apeldoorn Council using the online form on this page.

Would you like to know more about these privacy rights? For example, when you can exercise them? On the the Dutch Data Protection Authority’s website You can also find a lot of information there.

The Municipality of Apeldoorn handles your personal data with care and treats it as confidential. We never grant access to just anyone and take both technical and organisational measures to protect your personal data. For example, only individuals bound by a duty of confidentiality process your personal data, and staff only have access to the personal data necessary for their work.

The Municipality of Apeldoorn processes personal data solely for the purpose for which it was collected. In doing so, we also ensure that appropriate technical security measures are in place to protect personal data. This safeguards personal data against destruction or damage. In doing so, we comply with the Information Security Baseline (BIO) and the Cybersecurity Act. These regulations have been established by the national government and set out a wide range of measures to maintain information security standards.

The municipality of Apeldoorn is no the use of fully automated decision-making. This means that no decisions are taken without the involvement of a municipal employee.

Despite our best efforts, data breaches can unfortunately occur. Examples include an email or letter being sent to the wrong address, a website containing too much information, or a file going missing. In such cases, a data breach may have occurred. It is important that you report this to the local authority. We can then take measures to prevent and/or minimise any damage and, if necessary, inform the individuals concerned about the breach.

If you suspect that a data breach has occurred, please report it immediately to Apeldoorn City Council via datalek@apeldoorn.nl or by telephone on 14055. We will then take immediate action.

The municipality of Apeldoorn has appointed a Data Protection Officer (DPO). The DPO is the independent, internal supervisor responsible for ensuring compliance with data protection legislation. The DPO monitors whether the municipality is complying with this legislation and can provide independent advice.

Do you have a question or complaint regarding the municipality of Apeldoorn’s implementation of the General Data Protection Regulation or the Police Data Act? If so, please contact our Data Protection Officer via email at FG@apeldoorn.nl or via our postal address.

You can also ask questions about the protection of your personal data by contacting us directly via privacy@apeldoorn.nl.

Do you have a complaint about the way your request has been handled by the local authority? You can do so via the complaints-handling procedure submit a complaint to the municipality of Apeldoorn.

You have the right to lodge a complaint with the national data protection supervisory authority: the Dutch Data Protection Authority.

Amend the privacy statement

Due to new legislation or other developments, the municipality of Apeldoorn regularly updates its processes. This may also include changes to the way in which personal data is processed. We therefore recommend that you check this page regularly. We update this page on an ongoing basis.

This privacy notice was last updated on 6 May 2026.