Dutch Internet Providers Introduce Strict New Rules to Tackle Online Abuse
Amsterdam, Friday 28 August 2026
Updated Dutch internet codes of conduct now align with EU laws, forcing service providers to assess and remove reported illegal online content within a strict one-working-day deadline.
Aligning with the Digital Services Act
In a significant regulatory shift for the Benelux digital ecosystem, the Dutch internet sector has officially updated its self-regulatory codes of conduct to combat online abuse and streamline content removal [1][2][3]. On 27 August 2026, a coalition of key industry bodies—including digital infrastructure association DINL, the Dutch Cloud Community (DCC), the Dutch National Internet Providers Association (NBIP), and the Association of Registrars (VvR)—released the updated ‘Gedragscode Abusebestrijding’ (Code of Conduct for Combatting Abuse) and ‘Gedragscode Notice and Take Down’ (NTD) [2][3]. This coordinated update is specifically designed to help hosting providers and internet service intermediaries comply with the stringent requirements of the European Union’s Digital Services Act (DSA) alongside national Dutch laws [1][2].
The Clean Networks Initiative
These updated codes are managed under the umbrella of ‘Clean Networks’, an independent initiative operated by the NBIP [1][2]. The initiative, which also maintains a dedicated threat intelligence platform, is supported by the Dutch Data Center Association (DDA) and the Anti-Abuse Network (AAN) [1][2]. Funding and resources for Clean Networks are provided via subsidies from the European Union, the Digital Trust Center, and the SIDN Fonds, with active involvement from the Dutch Ministry of Justice and Security [1][2]. By formalising these standards, the sector aims to transition from voluntary intentions to clear, enforceable industry benchmarks [1][2][3].
The One-Working-Day Mandate and Proactive Enforcement
The most notable operational change introduced in the revised Notice and Take Down (NTD) guidelines is the introduction of a strict timeline for handling illegal online content [3]. Under the new protocol, digital service providers must establish a functional system to receive, assess, and act upon abuse reports, with the entire cycle of receipt confirmation, assessment, and ultimate removal of illegal content mandated to take place within just one working day [3]. This rapid turnaround represents a major shift for hosting providers, who must now ensure their compliance infrastructure can support near-instantaneous content moderation and legal assessments [3].
Broadening the Scope of Abuse Prevention
Beyond reactive takedowns, the updated ‘Gedragscode Abusebestrijding’ obligates service providers to adopt a highly proactive stance against technical abuse, such as malware distribution and Distributed Denial of Service (DDoS) attacks [2][3]. Providers are required to maintain dedicated abuse reporting hotlines and contact clients immediately upon receiving verified abuse reports [2][3]. In cases of severe or critical abuse, hosting and cloud providers must implement direct, immediate mitigation measures [3]. To ensure compliance, the code establishes strict enforcement protocols: providers must suspend services or completely terminate contracts for clients who engage in prolonged or repeated violations of Acceptable Use Policies (AUP) [3].
Mandatory KYC and Cryptocurrency Verification
To prevent anonymous bad actors from exploiting local infrastructure, the updated codes of conduct establish concrete standards across five operational areas: Policy & Procedures, Know Your Customer (KYC), Notice-and-Take-Down, Incident Follow-up, and Enforcement [3]. Most notably, the code introduces a mandatory KYC verification procedure for all clients [3]. For platforms and service providers processing digital assets, this includes a strict requirement to verify cryptocurrency transactions prior to the very first transaction [3]. This measure targets the financial anonymity often leveraged by cybercriminals to host malicious campaigns or distribute illegal material [GPT].
A Practical Framework for the Future
Octavia de Weerdt, the Managing Director of the NBIP, emphasised that these updates bridge the gap between complex European legislation and day-to-day operations [1][2][3]. De Weerdt noted that the codes translate the broad requirements of the DSA and Dutch legislation into highly practical, actionable agreements that providers can implement immediately [1][2][3]. To ensure the guidelines remain resilient against emerging cyber threats and shifting legal landscapes, the sector has committed to reviewing and revising both codes of conduct on an annual basis [1][2][3].