De Compliance Afdeling (hereinafter: De Compliance Afdeling / we / us) provides a compliance programme that works. In that capacity, we process personal data. We process most personal data on behalf of our customers, for example when a customer uses our risk analysis. This privacy statement explains how we process the personal data of our contacts.
Who is responsible for processing personal data?
In most cases, we process personal data on behalf of our customers because this is necessary to perform the agreement. As defined in the General Data Protection Regulation (GDPR), De Compliance Afdeling is the processor and the customer is the controller in these cases.
In other cases, when personal data is processed through our website www.decomplianceafdeling.nl, De Compliance Afdeling is the controller as defined in the GDPR.
When does De Compliance Afdeling collect and process your personal data?
De Compliance Afdeling collects and processes personal data in situations including the following:
- When you purchase products and/or services directly from us.
- When your employer uses our compliance programme and has provided us with your personal data in order to purchase products or services.
- When you complete a contact or demo form on our marketing website. We process the information you enter (such as your name, company name, email address and telephone number) and store it in our CRM system (Pipedrive) in order to handle your request.
- When you contact us directly, for example through our website, by email or by telephone, because you are interested in our services or have a question.
- When a third party forwards your personal data to us.
- When, as part of our compliance programme, we receive personal data concerning login data, error messages, data traffic, or your or a third party's contact details.
Which personal data does De Compliance Afdeling process?
De Compliance Afdeling may process the following personal data about you:
- Contact details: first name and/or surname, address, telephone number and email address.
- Other personal data: information you provide yourself, such as your date of birth, gender, employer or professional circumstances.
- Use of the website and communications: information about how you use the website and whether you open or forward our messages, including data collected through cookies and similar technologies. More information can be found in our cookie policy.
- Form data: information you enter in contact and demo forms on our marketing website, including your name, company name, email address, telephone number and your message or package selection.
- Interaction data: login data, error messages, data traffic, information about purchases of products and services, interaction with our sales department and third parties, and participation in market research.
- IT security: information about abnormal use of your compliance programme may be monitored. Where applicable, De Compliance Afdeling may receive and use personal data in accordance with the detailed descriptions of the relevant services and subject to the associated security measures.
For which purposes do we process your personal data?
De Compliance Afdeling processes your personal data only where we have a lawful basis for doing so. Some examples of lawful bases and purposes are:
| Lawful basis | Purposes of processing (including) |
|---|---|
| Entering into or performing an agreement | To provide services correctly in accordance with the agreement. |
| Consent | Marketing – to promote De Compliance Afdeling's services and share news or offers with you. |
| Legitimate interest | In connection with preventing fraud and criminal activity – to protect our organisation, customers and society against crime and its consequences. |
| Legal obligation | To respond to binding requests from authorities or regulators. |
How do we protect your personal data?
We use various security measures to protect your personal data, including encryption and authentication tools. We do this to protect and maintain the security, integrity and availability of your personal data.
How long do we retain your personal data?
In accordance with Article 17 of the GDPR, we do not retain your personal data for longer than is necessary for the purposes for which it was collected or otherwise processed. We delete personal data automatically or at our customers' request. To ensure that all your personal data is deleted in accordance with the principle of data minimisation and Article 17 of the GDPR, De Compliance Afdeling has developed internal deletion procedures.
We apply the following principles when deleting personal data:
- Use for the performance of an agreement: in order to meet contractual obligations, we may retain collected personal data for as long as the contract remains in force. Depending on the nature and scope of the contract, personal data is deleted seven years after the contract ends.
- Use for marketing purposes: personal data collected for marketing purposes is retained unless you ask us to delete it.
Who do we grant international access to your personal data?
De Compliance Afdeling preferably processes personal data within the European Economic Area (EEA).
If personal data is processed in countries outside the EEA or in countries that are not covered by an adequacy decision, De Compliance Afdeling uses European Union standard contractual clauses, together with appropriate technical and organisational measures, to ensure that your personal data receives a level of protection equivalent to European data protection standards.
Which third parties do we work with?
In some cases, De Compliance Afdeling uses third parties to provide services. De Compliance Afdeling takes privacy very seriously and selects these suppliers carefully. We assess, among other things, whether a supplier has sufficient technical and organisational measures in place to protect personal data.
We also determine whether a supplier is a processor or a controller under the GDPR. Where De Compliance Afdeling shares personal data with a processor, a data processing agreement is in place.
Some of the third parties De Compliance Afdeling works with are:
Website (decomplianceafdeling.nl)
- Scaleway (website hosting)
- Pipedrive (CRM; processing contact and demo requests)
- Google (reCAPTCHA to protect forms and, where applicable, Google Tag Manager for tag management)
- Plausible Analytics (aggregated, cookie-free website statistics)
- Microsoft Clarity (interaction analytics and session recordings, only after consent)
How can you access your personal data and change your privacy preferences?
You can contact us to find out which personal data we process about you. We will be happy to help and explain more about how and why we process personal data.
You cannot request information from us about the use of your personal data by third parties. To access that information or ask questions about how a third party uses your personal data, please contact the relevant third party directly.
What are your privacy rights?
Under the GDPR, you have a number of individual rights. The following section explains your rights as defined in the GDPR. Depending on the type and scope of your request, we may ask you to submit it in writing.
Right of access (Article 15 GDPR)
You may ask us at any time which personal data we process about you. This information includes, among other things, the categories of data we process, the purposes of the processing, the source of the personal data (if we did not receive it directly from you) and, where applicable, the recipients to whom we have disclosed your personal data.
If you would like to access the personal data processed by De Compliance Afdeling, please contact us.
Right to rectification (Article 16 GDPR)
You may ask us to correct your personal data. We want the personal data we process to be accurate.
If you would like to change your personal data, please contact us.
Access to choices made (consent)
We allow you to choose whether we may use or process your personal data for commercial approaches and offers. You may request an overview of the choices you previously made and that we have recorded. We will then give you the opportunity to change those choices.
Please contact us if you would like to receive this overview.
Right to erasure (Article 17 GDPR)
You may request that we delete your personal data. We can comply only if the relevant legal requirements are met. In accordance with Article 17 of the GDPR, this may be the case where:
- your personal data is no longer necessary for the purpose for which it was collected or processed;
- you withdraw the consent on which the processing was based and there is no other lawful basis for the processing;
- you object to the processing of your personal data and there is no overriding legitimate reason for processing it, or you object to the processing of your personal data for direct marketing;
- the personal data has been processed unlawfully;
- processing is not necessary for us to comply with a legal obligation to process your personal data;
- processing is not necessary for the establishment, exercise or defence of legal claims;
- processing is not necessary in connection with statutory retention periods.
Right to restrict or block processing (Article 18 GDPR)
You may ask us to restrict or block the processing of your personal data where:
- you dispute the accuracy of your personal data – this applies only for the period we need to verify its accuracy;
- the processing is unlawful, but you do not want the personal data to be deleted and instead request that its use be restricted;
- we no longer need your personal data, but you need it for the establishment, exercise or defence of legal claims;
- you have objected to the processing, but it has not yet been determined whether our legitimate grounds override your reasons.
Right to data portability (Article 20 GDPR)
At your request and where technically feasible, we will transmit certain personal data to another controller or provide it to you on a portable data carrier. This right applies only where the processing is based on your consent or is necessary to perform a contract.
Right to object (Article 21 GDPR)
You may object to the processing of your personal data at any time for reasons arising from your particular situation, provided that the processing is based on your consent, our legitimate interests or those of a third party. In that case, we will no longer process your personal data. This does not apply where we can demonstrate compelling legitimate grounds for the processing that override your interests, or where we need your personal data for the establishment, exercise or defence of legal claims.
Time limits for responding to your individual rights
In general, we will endeavour to comply with your request within 30 days. This period may be extended for reasons connected with the specific right concerned, the basis of the request or the complexity of your request.
Restrictions on providing information about your rights
If you submit a request to exercise your rights, we will inform you as soon as possible whether, and to what extent, we can comply. In some cases, we may refuse a request, for example if you ask us to erase personal data that we still need for tax or other statutory requirements. If this occurs, we will always explain why we cannot comply with all or part of your request.
Complaint to the Dutch Data Protection Authority
If you wish to complain about our use of your personal data, you may contact us. We take your comments, objections and rights concerning the processing of personal data seriously. If, however, you believe that your comment or objection has not been handled properly, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Contact us
If you have questions about our use of your personal data, how we handle it or this privacy statement, you can contact the responsible Data Protection Officer (DPO) at:
Email address: privacy@decomplianceafdeling.com
Telephone number: +31 (0)6 30488534 (weekdays from 09:00 to 17:00 CET)
Postal address:
De Compliance Afdeling
Attn. DPO
Burgemeester Oudlaan 50
3062 PA
Rotterdam
The Netherlands
Changes to this privacy statement
De Compliance Afdeling reserves the right to amend this privacy statement (last updated 23 August 2026). If substantial changes are made that affect the processing of your personal data, we will notify you by means of a notice on our website.
