Home | About this website | Privacy Statement: Apeldoorn Municipal Council | Privacy Statement under the Police Data Act (Wpg)

Privacy Statement under the Police Data Act (Wpg)

The municipality of Apeldoorn employs special investigating officers (BOAs). In the course of their work, BOAs are authorised to record personal data and share it with others. Special investigating officers process what is known as ‘police data’ in the course of carrying out their police duties. When a special investigating officer employed by the municipality carries out a police duty, such as enforcement within the municipality, the Police Data Act (Wpg) applies.

Like the General Police Data Regulation, the Wpg sets out requirements for the processing of police data. For example, the Wpg specifies specific retention periods for the storage of police data. The Wpg also sets out requirements for the sharing of police data between different parties, imposes a logging obligation and grants privacy rights to the data subject.

In carrying out our duties and obligations as a local authority, we process police data. We comply with the applicable legislation. In this privacy statement, you can read more about how Apeldoorn City Council handles police data.

The municipal governing bodies are generally responsible for the processing carried out by or on behalf of the municipality. They are referred to as ‘data controllers’. Where police data is processed by special investigating officers, the Municipal Executive acts as the data controller.

The municipality of Apeldoorn employs a number of special investigating officers:

  • Community support officers in public spaces. They monitor compliance with, amongst other things, the General Local Regulation (APV). Think, for example, of the enforcement officers on the streets.
  • Compulsory Education Officers. They monitor compliance with the Compulsory Education Act. This includes issues such as truancy.
  • Social investigators. Their work includes, for example, investigating benefit fraud with the aim of combating fraud relating to employment and income.

The special investigating officers are divided into a number of so-called ‘domains’. At Apeldoorn Council, these are Domains I and II (Public Spaces and the Environment), Domain III (Compulsory Education Officers) and Domain V (Social Investigators).

The local authority only processes police data where there is a legal basis for doing so. The legal basis on which the special investigating officers (BOAs) of the municipality of Apeldoorn process police data is the performance of a statutory duty. BOAs are required to process police data by virtue of their police duties.

In addition to the Police Data Act, special investigating officers also process police data under other regulations, for example:

  • Code of Criminal Procedure.
  • Decision by a special investigating officer.
  • General Local By-law (APV).
  • Compulsory Education Act.
  • Participation Act.

A complete overview can be found in the ‘Regulations on domain lists for special investigating officers’, which sets out, for each area, the legislation with which special investigating officers are required to deal.

The police data processed by special investigating officers depends on the exact duties they carry out and the area of responsibility to which they belong. For example, an enforcement officer in the city centre requires different personal data to carry out his or her police duties than a school attendance officer. In any case, the following details are recorded in an official report: name, address and place of residence, telephone number, date of birth and national insurance number.

Sometimes the local authority needs to pass on police data to other parties. For example, to the Central Judicial Collection Agency (CJIB), the Public Prosecution Service (OM) or the police.

If we have a company process police data on our behalf, we enter into a data processing agreement. In this data processing agreement, we set out arrangements regarding how the other party is to handle police data appropriately. In this way, we ensure a high standard of security and that police data remains confidential. These data processors include, for example, debt collection agencies, cloud and hosting providers, and IT service providers. We always retain ultimate responsibility for the police data.

The municipality of Apeldoorn only engages external parties within the European Union or the European Economic Area (EEA). Exceptions to this rule are made only in exceptional cases. When we disclose personal data or police data to parties outside the EEA, this is done in accordance with the requirements of the GDPR and the Wpg, such as by making appropriate arrangements regarding the level of data protection in that country. On the the Dutch Data Protection Authority’s website You can find more information about this there.

The Police Data Act sets out specific rules on how long we are permitted to retain police data. The Act specifies time limits for how long police data may be retained. Once this time limit has been reached, the personal data must be permanently deleted. We must, in any case, comply with two different retention periods. Which one we must apply depends on whether a special investigating officer (BOA) carries out day-to-day police duties or is involved in longer-term investigations, such as a social investigator. We explain this below.

The retention period for police data processed for day-to-day policing duties – for example, for issuing fines – is as follows. During the first year after a special investigating officer (BOA) first processes police data, this data is widely accessible to BOAs where necessary for the performance of their duties. In the four years that follow, police data may only be accessed via targeted searches, for example by registration number or name. Finally, police data is retained for a further five years. During this final phase, the data may only be used for purposes such as handling complaints or conducting audits. After this final period, the data is destroyed.

The retention period for police data processed in the context of targeted investigations, for example by social investigators, is as follows. For targeted investigations, police data may be processed for as long as is necessary to achieve the purpose of the investigation. The purpose may, for example, be deemed to have been achieved once a court has finally handed down a judgement. After that, information from an investigation may still be reused for a further six months. An official within the local authority oversees this process. Finally, police data is retained for a further five years. During this final phase, the data may only be used for purposes such as handling complaints or conducting audits. During this phase, the Public Prosecution Service may, for example, still request the information. This only occurs in exceptional cases. Once these five years have elapsed, the data is destroyed.

Whenever we process your police records, we will inform you of the reasons for doing so. For example, through this privacy notice. In addition to this right to information, you have other rights. You may exercise the following rights:

  • Right of access.

You can ask the local authority to show you what police data it holds about you. This means that we will provide you with a list of the police data we process about you.

  • Right to rectification.

You can ask the local authority to amend or supplement police records.

  • Deletion (erasure) or blocking of data.

You can ask the local authority to delete your police records. As there is sometimes a strict retention period in place, we cannot always delete all personal data. In some cases, rather than deleting police records, we have to restrict access to the data.

Terms and conditions or restrictions may apply. On the page Submitting a request under the GDPR and the Wpg You can find more information about your rights here. You can submit a request to Apeldoorn Council using the online form on this page.

Apeldoorn Municipality handles police data with care and treats it as confidential. We never grant access to anyone without good reason and take both technical and organisational measures to safeguard police data. For example, only individuals bound by a duty of confidentiality process police data, and staff only have access to the police data necessary for their work.

The municipality of Apeldoorn processes police data solely for the purpose for which it was collected. In doing so, we also ensure that police data is protected by appropriate technical security measures. This safeguards personal data against destruction or damage. In doing so, we comply with the Information Security Baseline (BIO) and the Cybersecurity Act. These regulations have been established by the national government and set out a wide range of measures to maintain information security standards. We are also audited by independent auditors. This means that an independent body checks whether we are complying with the law.

The municipality of Apeldoorn is no the use of fully automated decision-making. This means that no decisions are taken without the involvement of a municipal employee.

Despite our best efforts, data breaches can unfortunately occur. Examples include an email or letter being sent to the wrong address, a website containing too much information, or a file going missing. In such cases, a data breach may have occurred. It is important that you report this to the local authority. We can then take measures to prevent and/or minimise any damage and, if necessary, inform the individuals concerned about the breach.

If you suspect that a data breach has occurred, please report it immediately to Apeldoorn City Council via datalek@apeldoorn.nl or by telephone on 14055. We will then take immediate action.

The municipality of Apeldoorn has appointed a Data Protection Officer (DPO). The DPO is the independent, internal supervisor responsible for ensuring compliance with data protection legislation. The DPO monitors whether the municipality is complying with this legislation and can provide independent advice.

Do you have a question or complaint regarding the municipality of Apeldoorn’s implementation of the General Data Protection Regulation or the Police Data Act? If so, please contact our Data Protection Officer via email at FG@apeldoorn.nl or via our postal address.

You can also ask questions about the protection of your personal data by contacting us directly via privacy@apeldoorn.nl.

Do you have a complaint about the way your request has been handled by the local authority? You can do so via the complaints-handling procedure submit a complaint to the municipality of Apeldoorn.

You have the right to lodge a complaint with the national data protection supervisory authority: the Dutch Data Protection Authority.

Amend the privacy statement

Due to new legislation or other developments, Apeldoorn City Council regularly updates its processes. This may also include changes to the way police data is processed. We therefore recommend that you check this page regularly. We update this page on an ongoing basis.

This privacy statement was last updated on 4 November 2025.