What GDPR covers, in plain terms.
GDPR is the EU-wide regulation that governs how any organisation collects, stores and uses personal data, and it applies to a business registered in the Netherlands the same way it applies everywhere else in the bloc. Personal data is defined broadly: a name, an email address, a phone number, a photograph, or browsing activity tied back to a specific person all count, not only the obvious categories like a passport number or a home address.
The protections are not something you have to sign up for or activate. The moment an organisation holds data that identifies you, the obligations already apply to it, and the rights below already belong to you, whether or not you have ever read the fine print of a privacy policy.
It also does not matter how the organisation collected the data in the first place. Information typed into a form, gathered through a cookie, inferred from browsing behaviour or simply handed over in a message all fall under the same set of obligations once it sits in a system somewhere, tied to a real person.
The core rights, one at a time.
Most of GDPR in daily life comes down to a short, practical list. Each right can be exercised on its own, in writing, without needing to explain a reason beyond the request itself, and none of them require the involvement of a lawyer to get started.
Two rights that come up less often.
Where a decision about you is made entirely by an automated system, with no human involved and a meaningful effect on you, you generally have a right not to be subject to that decision alone, or at least a right to have a person review it. This rarely comes up outside credit scoring, large scale hiring tools and similar automated pipelines, so most people go years without ever needing it.
Where processing rests on consent rather than another legal basis, that consent can be withdrawn at any point, as easily as it was given. A business cannot make withdrawing consent harder than granting it in the first place, and withdrawing it does not undo processing that already happened lawfully before the withdrawal took effect.
How this plays out with an ordinary business.
A booking with a companionship agency involves comparatively little data by design. Arranging time with Jasmin or looking through profiles filed under petite does not require a full identity document, an employer's name or a home address unless the visit itself is at that address. That restraint is not only good manners, it lines up neatly with what an organisation handling personal data is expected to practise on its own initiative.
The same logic applies to messages sent while confirming plans in Amsterdam Centrum or arranging an overnight: the fewer fields a business asks for, the fewer obligations it has to manage around that data, and the smaller the record left behind either way. It is a rare case where privacy and simplicity point in exactly the same direction.
When a right can be lawfully refused.
These rights are strong but not absolute. A business can hold on to certain records where a separate legal duty requires it, such as a narrow bookkeeping entry that tax rules expect an organisation to keep on file for a defined period. A request that is manifestly unfounded or excessive, repeated many times over with no new purpose behind it, can also be refused or made subject to a reasonable fee.
A business is also allowed to verify identity before acting on a request, precisely so that one person's data cannot be deleted or handed over to someone else pretending to be them. A short identity check is a safeguard for the person making the request as much as it is a process step for the business handling it.
Making a request that actually gets answered.
A request in writing, naming the specific right being exercised, moves faster than a vague message asking a business to do something with your data without saying what. Keep a copy of what was sent and when. The usual expectation is a reply inside roughly a month, occasionally stretching a little longer where the request itself is genuinely complicated to untangle.
The mechanics of a formal request, what a business has to disclose and by when, are explored in more depth in our guide to subject access requests. If a request goes unanswered past a reasonable point, the body set up to take that complaint further is explained in our Dutch Data Protection Authority guide.
Where discretion and rights meet.
For a booking that depends on being kept quiet, these rights are not an abstract legal topic, they are the backstop behind the promise. Whoever you are meeting, whether that is time with Nora filed under brunette or an evening arranged through the rates page, the same rights apply to whatever small record that booking leaves behind, and none of them expire once the evening itself is over.
Knowing the list is often enough on its own. Most people never need to formally exercise a single one of these rights against a discreet, well run business, but knowing they exist changes how confidently a form or a booking gets handled in the first place.