NETHERLANDS Law and Practice Contributed by: Friederike Henke, Ingrid Cools, Philip ter Burg, IJsbrand Uljée, Suzan van de Kam and Epke Spijkerman, BUREN
Trade Secrets The Dutch Trade Secrets Act ( Wet bescherming bedri- jfsgeheimen ) implements the EU Trade Secrets Direc - tive (Directive 2016/943/EU), which sets out rules for the protection of trade secrets. Trade secrets refer to any information that: • is not generally known or readily accessible to per - sons in the circles who normally deal with this type of information and is therefore of economic value; • is subject to appropriate confidentiality measures by the lawful holder; and • the holder has a legitimate interest in the confiden - tiality thereof. An owner of trade secrets must enforce “appropriate measures” and establish the confidentiality of said trade secrets in order to ensure protection. The Dutch Trade Secrets Act stipulates the actions allowed for discovering trade secrets: so-called reverse engineering is permissible, provided it does not violate contractual obligations or other mandatory statutory law. In the case of infringements, trade secrets owners can demand the cessation or prohibition of the use or dis - closure of the trade secret, and even product recalls regarding the infringing goods and/or their destruc - tion, as well as damages. 8. Data Protection 8.1 Applicable Regulations The main regulations applicable to personal data pro - tection in the Netherlands are: • Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free move - ment of such data (GDPR); and • the Dutch GDPR Implementation Act ( Uitvoering- swet AVG ) of 16 May 2018. The GDPR The GDPR is a uniform and unitary data protection law applicable throughout the EU and EEA, and is directly
applicable in the Netherlands. It allows EU member states to enact additional implementing provisions – eg, in relation to special categories of personal data as referred to in Article 9 (1) of the GDPR, and provid - ing for certain exemptions for scientific or historical research or statistical purposes, for authentication and security purposes, etc. The Netherlands has exer - cised this right by introducing the GDPR Implementa - tion Act. The GDPR defines “personal data” as any data that can be traced back to specific individuals (the data subjects), either directly or indirectly. Health data, genetic data, data about race or ethnicity, and other special categories of personal data, as well as personal data relating to criminal convictions and offences, enjoy additional protection. The GDPR defines a controller as the party who deter - mines the purpose and means of processing, and a processor as the party who processes personal data on behalf of a controller. Both controllers and proces - sors are subject to the rules in the GDPR. The GDPR stipulates that, in order to be able to dem - onstrate compliance, controllers must adopt internal policies and implement measures that satisfy the prin - ciples of data protection by design and data protec - tion by default. The processing of personal data (including disclosure to third parties) must be lawful, transparent and fair. It must be limited to specific purposes and to the data necessary for these purposes (data minimisation). Other principles are that the data must: • be accurate; • be kept secure; and • not be stored for any longer than needed (storage limitation). The GDPR also requires businesses to inform data subjects of how their data is used and to document their compliance with the GDPR. Data subjects have the right to access their personal data, to request cor - rections, and to have their data deleted (or restricted) under certain conditions. Controllers and processors must designate data pro - tection officers (DPO’s) in the following circumstances:
745 CHAMBERS.COM
Powered by FlippingBook