The Dutch Digital Government Act Regulates How Citizens Log In
The Netherlands’ Digital Government Act treats access to public services as a trust decision. The sensitivity of the service should determine the strength of the login—not the convenience of the existing portal.
The Wet digitale overheid, or Wdo, began phased commencement on 1 July 2023. It provides a legal basis for secure and reliable electronic identification when citizens and businesses use public and semi-public services. It also supports recognised login methods, information-security rules and mandatory open standards.
The Act’s importance lies in the connection between a public service, its risk and the assurance level required of the person signing in.
Classify the service before choosing the login
A public service provider must determine the appropriate reliability level for each digital service. A portal showing general information is not the same as an application that changes benefit payments, discloses medical details or lets a representative act for a company.
Classification should consider the harm caused by impersonation, unauthorised access, erroneous action and denial of service. It should also consider the population using the service. A technically strong login that excludes many intended users can undermine access to government.
The evidence record should identify the service, data and transactions, the selected level, the risks considered, the accepted authentication methods and the date for reassessment. Reusing one classification for an entire website may hide materially different functions behind the same login.
Recognition creates choice and integration work
The Act supports a system in which people can use recognised identification methods, not only a single government-issued route. For public service providers, that creates obligations around acceptance, interface security and reliable transfer of identity attributes.
The receiving service needs to know what was actually verified, at what level and for which person or representative. Authentication logs should support investigation without becoming an excessive identity history. Error handling also matters: if an external method is unavailable, the fallback must not quietly reduce assurance for a sensitive transaction.
Representation is a separate design problem. A person acting for a business, client or relative needs authority as well as identity. Systems should record both without confusing successful login with permission to perform every action.
Open standards move from policy to requirement
The Wdo provides a basis for requiring public organisations to use designated open standards. One visible example from the first phase is the obligation for publicly accessible government websites and web applications to use HTTPS and HSTS in line with relevant security guidance.
That makes configuration evidence part of legal compliance. A certificate alone is insufficient if insecure protocols remain enabled, redirects permit downgrade or HSTS is misconfigured. Automated testing should be backed by ownership, remediation and exception handling.
Open standards also reduce unnecessary dependency on a single supplier and help public services work across administrative chains. Procurement should specify the standard, version, conformance evidence and change process rather than using “open” as a marketing adjective.
Phasing does not remove the need to prepare
Not every Wdo obligation became fully operational on 1 July 2023. Implementation has been phased, and the transition allowing some services to continue at a lower reliability level has been extended to 1 July 2028 while higher-level methods become more widely available.
That extension should be recorded as transitional risk, not interpreted as a conclusion that the lower level is appropriate. Providers should maintain the target classification, dependencies, user-migration plan and controls that reduce risk during the transition.
The operational checklist
Public and semi-public service providers should be able to show:
- a service-by-service reliability classification;
- accepted identification methods and their assurance levels;
- separate controls for representation and authorisation;
- secure integration, logging and fallback behaviour;
- conformance with mandated standards such as HTTPS and HSTS; and
- a migration plan where a transitional lower level is still used.
The Dutch Act makes digital identity part of service governance. A login is not a generic front door added after the service is built. It is a control selected from the harm, authority and accessibility requirements of the particular public transaction.
Official sources
- Digital Government: legislation overview and Wdo commencement
- Digital Government: Wet digitale overheid explained
- Digital Government: mandatory HTTPS and HSTS under the Wdo
Continue the series
- Next in the Netherlands: The Netherlands Is Making Electronic Health-Data Exchange Mandatory
- European National Cyber & Digital Law Series index
This article provides general information and is not legal advice.



