Allied Intelligence — 2026-07-01

Dutch Oversight Body Finds AIVD and MIVD Violated Privacy Law in Large-Scale Data Processing

BLUFMinisterial acknowledgment without enforceable compliance deadlines leaves AIVD and MIVD bulk-data practices functionally unchanged until the Wiv 2017 revision delivers statutory constraints.

The Dutch oversight body CTIVD found the AIVD and MIVD unlawfully processed personal data within large bulk datasets, in some cases granting groups of employees unauthorized access and retaining data beyond the legal limit of eighteen months plus a possible one-year extension, in some cases without even tracking how long files had been held 1234. The datasets, which can contain millions of entries including names, phone numbers, location and social media data, are drawn from other government agencies, commercial sources, and in some cases material obtained by hackers, including data from the Odido breach, and sold online 1234. CTIVD chair Hugo Hillenaar said the processing constitutes a privacy intrusion for individuals in the datasets, most of whom have no connection to espionage or terrorism, and the commission issued thirteen recommendations to improve safeguards 13. Defense Minister Dilan Yeşilgöz and Interior Minister Pieter Heerma told parliament they recognize CTIVD's findings, said improving bulk dataset management is a priority, and stated some recommendations will feed into the planned revision of the 2017 Intelligence and Security Services Act 34. Digital rights group Bits of Freedom said the services have a history of over-collecting citizen data and voiced concern they may be training AI systems on it, including data obtained from leaks 1.

Analysis
CTIVD's findings expose a structural gap between the scale of bulk-dataset use across AIVD and MIVD and the oversight meant to constrain it, with the thirteen recommendations setting benchmarks the planned Wiv 2017 revision will be measured against, though reporting rests on the single CTIVD report with outlets amplifying rather than independently corroborating it. Ministerial acknowledgment without a compliance timeline leaves access-control and logging gaps unresolved, and risks repeating the pre-2017 over-collection cycle Bits of Freedom warns of, particularly given its unaddressed concern that leaked or purchased data may be feeding AI training. Tech-expert Bert Hubert instead attributes the lapses to institutional habit and an outdated telecom-era statute rather than deliberate rule-breaking.
5 sources
  1. Dutch intelligence agencies accused of privacy breaches in large-scale data processing - NL Times
  2. Inlichtingendiensten houden zich niet aan regels voor datasets met persoonsgegevens - NOS
  3. CTIVD: persoonsgegevens in bulkdata onrechtmatig door AIVD en MIVD verwerkt - Security.NL
  4. Toezichthouder: 'AIVD en MIVD verwerkte persoonsgegevens in meerdere gevallen onrechtmatig' - Dutch IT Channel
  5. AIVD en MIVD moeten bij bulkdataverwerking persoonlijke privacy beter beschermen - CTIVD (Commissie van Toezicht op de Inlichtingen- en Veiligheidsdiensten)

View in full brief →

UNCLASSIFIED // OPEN SOURCE