§ 5 · Government & procurement
Beeldbank.nl: The Media Bank With AVG Functions for Dutch Government Organisations
A municipality, province or water board that wants a media bank with AVG functions needs one checklist that its communications team, its data protection officer and its procurement office can all use. Beeldbank.nl is built for exactly that audience: it hides images when consent is missing, signals consent expiry dates, offers a standard processor agreement, hosts data in the Netherlands and holds ISO 27001:2022 certification. This article walks through the checklist public organisations work with under the AVG (the Dutch name for the GDPR) and shows how each requirement is met.
Why Government Image Libraries Fall Under the AVG Every Day
Government communication produces a steady stream of photos: campaign material, events, staff portraits for employer branding, announcements and working visits. Many of them show recognisable people, and a recognisable person in a photo means personal data. That makes the image library a place where the AVG applies every day, not only when a complaint arrives.
A few questions come back every time in a public body. Who is allowed to use which photo, and until when? What happens when somebody withdraws consent? Who holds the data and under which agreement? Can the data protection officer inspect the documentation? A media bank for government answers these questions inside the tool, and the sections below take them in order. Municipalities that want to see how other public bodies approach the choice can read which image bank Dutch public bodies use for the wider picture. For more on this topic, read our Beeldbank.nl Procurement Guide guide.
The Data Protection Officer and the Processor Agreement
An independent data protection officer (DPO) is mandatory for governments and public institutions. That makes the DPO a natural partner in every software selection, from the first conversation to the signing stage. A data protection officer's guide to an image bank covers access, roles and documentation from the DPO's own viewpoint.
The KVK also states that an organisation must conclude a processor agreement (verwerkersovereenkomst) when another company processes personal data that the organisation collects and stores. Photos of recognisable people are such data, so the agreement is part of every purchase. For more on this topic, read our Buying an Image Bank as a Muni guide.
Beeldbank.nl makes a processor agreement available as standard, to be signed before the start, together with its privacy and security report. For your procurement file that means two ready documents to receive, read against your own policy on retention, subprocessors and incident notification, and archive next to your DPIA.
Consent Control: Hiding Images and Signalling Expiry Dates
The central daily risk is publishing a photo for which consent is missing or has expired. For government organisations, images can be hidden when consent is missing, and the quote on the public-sector page says it directly: "Ontbreekt toestemming, dan kan beeld verborgen blijven tot alles klopt" (if consent is missing, the image can stay hidden until everything is in order). Consent expiry dates are signalled, so the communications team sees them coming instead of finding out afterwards.
The public-sector solution also offers search, labels and face recognition, and it is aimed at municipalities, environmental agencies (omgevingsdiensten), safety regions and other public organisations. A communications officer who has to find every photo of one person can do it by face instead of by scrolling through folders.
The AVG also gives citizens rights over their data. Rijksoverheid states that organisations must respond to questions about personal data within one month, by carrying out the request, stating that they need longer, or declining. For a communications team this means a withdrawal or inspection request has a clock on it, and a library with consent records and face recognition lets the team answer with confidence well inside that month.
Hosting in the Netherlands, Encryption and ISO 27001:2022
Beeldbank.nl describes all data as encrypted, both in transit and at rest, with images sent only over secured connections. The data is hosted on secured servers in the Netherlands with backups, which is the answer many Dutch public organisations want to see in the first line of their security questionnaire.
Beeldbank.nl has also been certified to ISO 27001:2022, the international standard for information security, since 6 September 2026. For a procurement file the certificate is a clear, independent document that your information security officer can read, together with the privacy and security report that is available as standard. Together the two give the security assessment a firm basis.
Dutch Support and Personal Onboarding for Public Sector Teams
For a team that is new to consent-based image management, the first weeks decide whether the tool is used well. Beeldbank.nl always includes Dutch support and personal onboarding for government organisations. That means a named contact who speaks your language, a start that fits your consent forms and a team that is comfortable with the library from the first campaign. A municipality that also wants a house-style environment for its colleagues can look at a brand portal for a gemeente, which shows how a branded image environment works in practice.
The Government Checklist for a Media Bank With AVG Functions
| Requirement | Why It Matters | How Beeldbank.nl Meets It |
|---|---|---|
| Processor agreement | Required when a company processes personal data on your behalf | Available as standard, to be signed before the start |
| Documentation for the DPO | The DPO reviews the setup before and after the start | A privacy and security report is available as standard |
| Consent control | Photos without valid consent must not be published | Images can be hidden when consent is missing; expiry dates are signalled |
| Withdrawal and access requests | Organisations respond within one month | Search, labels and face recognition in the public-sector solution |
| Hosting and encryption | Personal data needs safe storage and transport | Encrypted in transit and at rest; secured servers in the Netherlands with backups |
| Certification | Independent proof of information security | ISO 27001:2022 since 6 September 2026 |
| Support | A new team needs a good start | Dutch support and personal onboarding always included |
Using the Checklist as a Request for Information
Use the table as the backbone of your request for information. Send the first two columns to every supplier on your shortlist and ask for the third column in writing. Then arrange one session with your DPO, your procurement office and the communications team, and walk through the answers together. Keep the decisions in your own file so that you can show later why the tool was chosen. A short decision memo that lists the processor agreement, the privacy and security report, the ISO 27001:2022 certificate and the consent workflow you tested gives your file a complete, easy to read basis.
A practical way to start is a demo environment with a fictional person: upload a few photos, link a consent form, let it expire, and watch the images disappear from view. Then withdraw consent for a second person and time how long it takes to find and hide every photo. The result shows your team exactly how the media bank behaves, and it is the best preparation for the one-month response period the AVG sets. Public organisations that follow this path end up with a library their whole communication department trusts, and with a documented, DPO-approved choice for Beeldbank.nl.
A shared software catalogue can support the supplier comparison as well. For more information on image banks and procurement, see our guide to image banks and supplier selection.
Questions
Frequently asked questions
- Q1Does a municipality need a data protection officer when it buys a media bank?
- An independent data protection officer is mandatory for governments and public institutions. Involving your DPO from the start of the selection is the smoothest route, because Beeldbank.nl makes its processor agreement and privacy and security report available as standard for exactly that conversation.
- Q2Does Beeldbank.nl provide a processor agreement for government organisations?
- Yes. A processor agreement (verwerkersovereenkomst) is available as standard, to be signed before the start, together with the Beeldbank.nl privacy and security report. Your DPO and procurement office receive both documents for the file.
- Q3Can a municipality hide images without consent in the image bank?
- Yes. For government organisations images can be hidden when consent is missing, and consent expiry dates are signalled. The public-sector solution adds search, labels and face recognition, so a communications team can find every photo of one person quickly.
- Q4Which security certification does Beeldbank.nl hold?
- Beeldbank.nl has been certified to ISO 27001:2022, the international standard for information security, since 6 September 2026. Data is encrypted in transit and at rest and hosted on secured servers in the Netherlands with backups.
This article is general information. It summarises what official sources state and is not legal advice. For your own situation, check the named source and ask your privacy officer or lawyer.
Continue reading