Netherlands - Algorithm Regulation (Kamerstuk 26 643, nr. 1056)

Collective Parliamentary Letter 'Regulating Algorithms' (Compilation Letter)

Collectieve Parlementaire Brief 'Algoritmen reguleren' (Verzamelbrief)

Netherlands

RAI-NL-NA-CPLARXX-2023
Adopted(Adopted)
PolicyGovernance and OversightConformity Assessment and RegistrationRisk Management
Export PDF

The July 7, 2023 collective parliamentary letter "Algoritmen reguleren" sets out the Dutch government’s policy approach to the responsible use of algorithms by public authorities. It introduces an ImplementatieKader for responsible algorithm deployment, commits to an Algoritmeregister with a 2025 target for registering high-risk algorithms, and establishes oversight roles and coordination with supervisory authorities.

Summary

The Collective Parliamentary Letter "Algoritmen reguleren" (Kamerstuk 26 643, nr. 1056), published on 7 July 2023, is a policy package addressing the governance, transparency and risk management of algorithmic systems used across the Dutch public sector. The letter responds to concerns about the societal and individual impacts of algorithmic decision-making—particularly when used by government entities—and sets out three core actions: (1) the roll-out of an Implementatiekader for the responsible deployment of algorithms (IKA) to guide ministries and public bodies on norms and practices; (2) the further development and potential mandatory use of an Algoritmeregister to provide public transparency about government algorithms, with a commitment that at least all identified high‑risk algorithms are to be registered by end‑2025; and (3) adoption and dissemination of a non‑discrimination handreiking and related impact assessment tools (such as an IAMA) to better integrate human rights and non‑discrimination assessments into lifecycle processes. The IKA synthesizes existing audit and testing frameworks (e.g., Auditdienst Rijk, Algemene Rekenkamer) and aligns with the EU AI ethical guidelines and the prospective EU AI Regulation; it emphasizes human oversight, technical robustness, data governance, transparency, fairness, environmental and societal considerations and organizational embedding. The letter identifies institutional roles — notably BZK (Ministry of the Interior and Kingdom Relations) as policy lead, CIO Rijk coordinating departmental plans, and the Autoriteit Persoonsgegevens’ Directie Coördinatie Algoritmes (DCA) acting as an external algorithm supervisor — and sets expectations for departments to inventory algorithms, perform risk classification, apply the IKA, and report progress annually. The policy is procedural and normative rather than punitive in itself, though it foresees links to existing legal regimes (AVG/GDPR, Algemene wet bestuursrecht) and supervisory enforcement by sectoral regulators. Supplementary attachments included a draft Implementatiekader (version 1.0, 30 June 2023), a decisional note, and research handbooks. Subsequent departmental letters (from various ministries) and progress updates (late 2023–2024) translate the commitments into departmental plans and timelines toward the 2025 registration target. The letter therefore functions as a cross‑government roadmap—aligning national practice with developing European standards, prioritizing high‑risk systems, increasing transparency, and improving oversight and accountability of algorithmic systems in public administration.

Full article

Read full text ↗

Overview

The Collective Parliamentary Letter "Algoritmen reguleren" (Kamerstuk 26 643, nr. 1056), dated 7 July 2023, is the Dutch government’s consolidated policy communication to parliament setting out actions and instruments for the responsible use of algorithms across the public sector. It explains the rationale for government action, noting both the operational opportunities presented by algorithmic decision support and the risks to public values and fundamental rights. The letter sets three central tracks: (1) publish and operationalize an Implementatiekader (IKA) to guide lifecycle governance for algorithms; (2) develop and potentially mandate registration of government algorithms in the national Algoritmeregister, with a target that all high-risk algorithms be registered by 2025; and (3) disseminate and embed non-discrimination materials and human-rights impact tools (such as the IAMA). The policy package is supported by annexes including the draft IKA and background research. The full government letter and attachments are publicly available (see the primary document published by the Eerste Kamer and the attached IKA). For the canonical text, see the government transmission to the Tweede Kamer: Collective Parliamentary Letter 'Algoritmen reguleren' (7 July 2023).

Definitions

The letter and its Implementatiekader define key terms pragmatically for public administration use. "Algorithm" and "AI/system" are used to denote automated or semi-automated decision-support or decision-making systems (including rule-based, statistical and machine learning systems). "High-risk algorithm" is defined operationally in the context of impact on individuals’ rights, duties, entitlements, or significant interests (a definition that is to be aligned with the EU AI Regulation risk approach). "Implementatiekader (IKA)" refers to the set of principles, mandatory measures and recommended practices intended to structure responsible development, deployment, testing and monitoring of algorithms throughout their lifecycle. "Algoritmeregister" denotes the public register maintained for government algorithmic systems to increase transparency and accountability. "IAMA" refers to the Impact Assessment on Human Rights for algorithms, recommended within the IKA.

Governance and Institutional Framework

The policy sets out an inter‑departmental governance approach. The Ministry of the Interior and Kingdom Relations (BZK) acts as the principal policy lead in coordinating the IKA and registration initiative. The CIO Rijk is responsible for inter-ministerial planning and for asking departments to inventory and plan registration of algorithms. The Autoriteit Persoonsgegevens (AP), through its Directie Coördinatie Algoritmes (DCA), is designated as an external algorithm supervisor to facilitate cross-domain norm interpretation and to provide supervisory expertise. The letter also situates control tasks with existing institutions—Auditdienst Rijk (ADR), Algemene Rekenkamer and sectoral regulators—indicating these bodies will be involved in monitoring and audits. The Implementatiekader itself contains suggested internal governance structures ("lines of defense") to ensure multiple control points (policy owners, compliance functions, technical teams). See the IKA attachment for a description of institutional roles and responsibilities: Implementatiekader 'Verantwoorde inzet van algoritmen' (30 June 2023).

Key Focus Areas

The Implementatiekader organizes obligations and guidance across seven themes: (1) Human control and oversight; (2) Technical robustness and safety; (3) Privacy and data governance; (4) Transparency and explainability; (5) Diversity, non-discrimination and fairness; (6) Environmental and societal impact; and (7) Accountability and documentation. For each theme the IKA distinguishes between measures that are legally binding (derived from existing laws like the AVG/GDPR or administrative law) and recommended best practices (tools, templates, methodological guidance). The letter emphasizes early-stage risk identification and design-time embedding of safeguards, advocating for human-in-the-loop controls and pre-deployment rights‑impact checks. It highlights the need for non-discrimination by design, and recommends publication of taxonomy and documentation in the Algoritmeregister to enable external oversight and redress. The IKA recommends routine testing, scenario analysis, and bias mitigation techniques, and highlights the compatibility and complementarity of the national approach with the emerging EU AI regulatory framework and ethical guidelines.

Implementation Framework

The government proposes an operational pathway to implement the IKA across departments. Steps include: organizational inventory of algorithmic systems; risk classification using an IKA-linked handreiking; mandatory application of specific IKA measures for high-risk systems (e.g., documented human oversight, safety testing, secure data governance and an IAMA); and publication of metadata in the Algoritmeregister. Departments must produce department-level roadmaps for registering high-risk algorithms and embed the IKA into procurement, development and vendor-management processes. The IKA is designed as a living document: periodic updates are foreseen to incorporate lessons, sector-specific addenda, and the eventual obligations flowing from the EU AI Regulation. The government also foresees building public-facing case studies and practical tools in collaboration with civil society and practitioners to speed adoption and knowledge sharing (see attachments to the brief for the initial instrument list).

Monitoring and Evaluation

Monitoring is organized through a combination of departmental reporting, the Algoritmeregister, and oversight by supervisory authorities. The cabinet committed to periodic reporting to parliament: departments will report progress via the Jaarverslag Bedrijfsvoering Rijk and by discrete letters on departmental planning. External oversight is enabled by the AP’s DCA, the ADR and the Algemene Rekenkamer, each with specific audit and control competences. The Algoritmeregister is designed as both a transparency tool and a monitoring artefact: it supports tracing of which algorithms are in use, their risk classification, and the applied safeguards. The government established milestones (see timeline) and expects to evaluate the effectiveness of the IKA and registration by reviewing both internal compliance metrics and outcomes from audits and public feedback.

Penalties, Liability, and Appeals

The Verzamelbrief is a policy instrument and does not itself create a bespoke penalty regime; rather it links to existing statutory enforcement channels. Legal obligations remain enforceable through the General Data Protection Regulation (AVG) for data‑processing requirements, administrative law principles under the Algemene wet bestuursrecht for decision-making processes, and sectoral laws (e.g., taxation, social security specific rules). Where violations involve personal data processing, the Autoriteit Persoonsgegevens retains powers to investigate and sanction under the AVG. Administrative remedies and judicial review remain available to affected parties; the letter further anticipates that audit findings by ADR or reports by the Algemene Rekenkamer could result in parliamentary scrutiny or corrective mandates. Departments are advised to maintain liability and redress procedures proportionate to algorithmic risk

Relationship to Other Instruments

The policy explicitly positions the IKA and the Algoritmeregister in a wider regulatory ecosystem: it cross-references the AVG/GDPR, existing oversight by ADR and ARK, the Council and European Commission’s AI ethical guidelines, and the expected obligations under the forthcoming EU AI Regulation. Annexes and the IKA draw on existing materials such as the non-discrimination by-design handreiking and the IAMA tools developed by civil-society and academic partners. The IKA is designed to complement and not duplicate sectoral regimes; where sector-specific obligations (healthcare, policing, justice) apply, those remain authoritative. The government also references and coordinates with other national initiatives such as the Algoritmeregister guidance and public repositories of best practices.

International Alignment

International alignment is a stated objective. The letter notes active Dutch participation in EU-level negotiations on the AI Regulation, and alignment of the IKA’s principles with the European Commission’s Ethics Guidelines for Trustworthy AI and with the risk-based approach enacted in the EU AI legislative process. The government intends the Dutch approach to be interoperable with EU obligations and to support common standards for high-risk systems, conformity assessment and technical documentation. It also signals cooperation with other member states and international bodies to share lessons, testing methodologies and audit approaches. See the brief for explicit references to European texts and coordination commitments.

Implementation Timeline

MilestoneDate / Target
Publication of Verzamelbrief and attachments2023-07-07
IKA initial version (concept)2023-06-30
Departments prepare departmental roadmaps and inventories2023 Q3 – 2024 Q1 (departmental schedules vary)
Progress updates to Parliament (periodic)Late 2023 – annually thereafter
Deadline to have at least all high-risk algorithms registered in Algoritmeregister2025-12-31 (government target)

Sources and References

SourceType
Collective Parliamentary Letter 'Algoritmen reguleren' - Kamerstuk 26 643, nr. 1056 (7 July 2023)Primary Source
Implementatiekader 'Verantwoorde inzet van algoritmen' (Implementatiekader IKA) - Version 1.0 (30 June 2023)Primary Source
Algoritmeregister (Dutch government)Primary Source

Requirements for a company

What an organisation has to do under Netherlands - Algorithm Regulation (Kamerstuk 26 643, nr. 1056), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Adopted). These requirements apply once the instrument takes effect and may change before then.

Must do

10
  • Create and maintain an internal catalogue of all algorithmic systems and classify their risk level.Dutch government departments
  • Publish metadata of all high-risk algorithmic systems in the national Algoritmeregister.Dutch government departments deploying high-risk algorithms
  • Apply mandatory technical, governance, and documentation measures from the Implementatiekader for high-risk systems.Dutch government departments deploying high-risk algorithms
  • Perform an Impact Assessment on Human Rights (IAMA) for high-risk algorithmic systems.Dutch government departments deploying high-risk algorithms
  • Ensure documented human control and oversight for high-risk algorithmic systems.Dutch government departments deploying high-risk algorithms
  • Embed Implementatiekader measures into procurement, development, and vendor-management processes.Dutch government departments
  • +4 more in the table below

Must not do

0

Nothing in this category.

Should do

3
  • Conduct routine testing and scenario analysis for algorithmic systems.Dutch government departments deploying algorithms
  • Apply bias mitigation techniques to ensure fairness in algorithmic systems.Dutch government departments deploying algorithms
  • Maintain liability and redress procedures proportionate to algorithmic risk.Dutch government departments deploying algorithms

Should not do

0

Nothing in this category.

Who must do what

The obligations under Netherlands - Algorithm Regulation (Kamerstuk 26 643, nr. 1056), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Dutch government departmentsCreate and maintain an internal catalogue of all algorithmic systems and classify their risk level.
Steps include: organizational inventory of algorithmic systems; risk classification using an an IKA-linked handreiking
Mar 31, 2024Implementation FrameworkCritical
2Dutch government departments deploying high-risk algorithmsPublish metadata of all high-risk algorithmic systems in the national Algoritmeregister.
target that all high-risk algorithms be registered by 2025
Dec 31, 2025OverviewCritical
3Dutch government departments deploying high-risk algorithmsApply mandatory technical, governance, and documentation measures from the Implementatiekader for high-risk systems.
mandatory application of specific IKA measures for high-risk systems
Before deploymentImplementation FrameworkCritical
4Dutch government departments deploying high-risk algorithmsPerform an Impact Assessment on Human Rights (IAMA) for high-risk algorithmic systems.
mandatory application of specific IKA measures for high-risk systems (e.g., ... an IAMA)
Before deploymentImplementation FrameworkCritical
5Dutch government departments deploying high-risk algorithmsEnsure documented human control and oversight for high-risk algorithmic systems.
mandatory application of specific IKA measures for high-risk systems (e.g., documented human oversight)
Before deploymentImplementation FrameworkCritical
6Dutch government departmentsEmbed Implementatiekader measures into procurement, development, and vendor-management processes.
Departments must ... embed the IKA into procurement, development and vendor-management processes.
Implementation FrameworkImportant
7Dutch government departmentsProduce and maintain technical and governance documentation sufficient for audits.
Accountability and documentation. ... supports tracing of which algorithms are in use
Key Focus AreasImportant
8Dutch government departmentsProduce department-level roadmaps for registering high-risk algorithms.
Departments must produce department-level roadmaps for registering high-risk algorithms
Mar 31, 2024Implementation FrameworkImportant
9Dutch government departmentsReport progress on algorithm implementation via annual reports and discrete letters to parliament.
departments will report progress via the Jaarverslag Bedrijfsvoering Rijk and by discrete letters
Annually thereafterMonitoring and EvaluationImportant
10Dutch government departments developing or deploying algorithmsEnsure non-discrimination by design in algorithmic systems.
highlights the need for non-discrimination by design
Before deploymentKey Focus AreasImportant
11Dutch government departments deploying algorithmsConduct routine testing and scenario analysis for algorithmic systems.
The IKA recommends routine testing, scenario analysis
Key Focus AreasRecommended
12Dutch government departments deploying algorithmsApply bias mitigation techniques to ensure fairness in algorithmic systems.
recommends ... bias mitigation techniques
Key Focus AreasRecommended
13Dutch government departments deploying algorithmsMaintain liability and redress procedures proportionate to algorithmic risk.
Departments are advised to maintain liability and redress procedures proportionate to algorithmic risk
Penalties, Liability, and AppealsRecommended

© Regulations.AI · updated on 13-Jun-2026