A municipal website operates under a tighter regulatory framework than a corporate site. That is not a side issue: it determines what the platform looks like under the hood.
The Baseline Informatiebeveiliging Overheid (BIO) is the shared standards framework of central government, municipalities, provinces and water boards. It sets requirements for logging, access management, vulnerability policy, data classification and incident handling. We design the platform with BIO in mind from the very first sketch: separated environments, audit logs at the right level, no unnecessary storage of personal data, and hardening of the hosting layer.
The GDPR overlaps with BIO but places its own emphasis on purpose limitation, data minimisation, data subject rights and DPIAs for high-risk processing. For every new feature, we check together with your DPO whether the existing DPIA is sufficient. We actively document which data is held where, on what legal basis, and how a request for access or erasure is handled technically.
The Digital Government Act (Wet digitale overheid) and the Decree on the Digital Accessibility of Government (Besluit digitale toegankelijkheid overheid) require compliance with WCAG 2.1 AA and a corresponding accessibility statement. This is not a tick-box afterwards but a design requirement that affects every component: colour contrast, focus management, semantic HTML, assistive-technology-friendly forms, screen reader support and alternative text. Before going live, we commission an independent audit.
The AI Act affects the platform as soon as you add AI components, such as a chatbot, a classifier for incoming reports or a preliminary-review AI for permits. We treat this as a separate decision chain: first the risk classification for each AI feature, then registration in the Algoritmeregister where applicable, and only then implementation. For organisations that want to explore what AI can do here, see our AI workshop for municipalities.
Finally, we work with the standards of VNG and Geonovum: GEMMA for architecture, NLX for inter-organisational integrations, Haalcentraal for querying base registers (BRP, BAG, BRK, BGT), and the common case and document types for case-based working.