Custom BRP integration development
Appfront builds custom BRP integrations that let your application query personal data directly at the source: the Dutch Personal Records Database (Basisregistratie Personen), managed by RvIG. Using the modern Haal Centraal BRP Bevragen API (REST/JSON) or the legacy StUF-BG, we retrieve up-to-date name, marital status and residence data, with PKIoverheid, OAuth 2.0 and data minimisation within your authorisation decision. This way you work with current, reliable source data without duplicate registration.
What is a BRP integration?
The Basisregistratie Personen (BRP) is the central register of personal data for residents of the Netherlands (ingezetenen) and for non-residents (RNI), managed by the Dutch Identity Information Services Agency (RvIG). The BRP is the primary source for current name and address details, civil status, partner, child and parent details, nationality and place of residence. By querying the source directly, you work with current, reliable data and avoid duplicate record-keeping.
Queries can run via two routes. Modern: the Haal Centraal BRP Bevragen API, a RESTful API with JSON that deliberately uses the POST method so that no personal data ends up in URLs or server logs. Legacy: StUF-BG (based on LO GBA), the older SOAP/XML standard still running in many existing municipal and implementation systems. Access is strictly reserved for organisations with a public task and a BRP authorisation decision, subject to strict GDPR and security requirements.
Appfront builds in line with the official RvIG BRP API documentation and the OWASP ASVS security standard. We align queries, authorisation and error handling with your actual processes and the principle of data minimisation, so the integration only retrieves the data covered by your authorisation decision and remains reliable even at peak volumes.
Querying the source
Consult current personal data directly in the BRP by BSN or through search queries: name, civil status, partners, children and nationality. No outdated copies held in-house, just real-time source data from the RvIG register.
Modern or legacy
Integrate via the modern Haal Centraal BRP Bevragen API (REST/JSON) or via legacy StUF-BG (SOAP/XML, LO GBA). We connect to your existing landscape or build a bridge from StUF to the new API where that makes sense.
Within your authorisation
The integration respects your BRP authorisation decision and the principle of data minimisation: only the fields necessary for your statutory task. PKIoverheid, OAuth 2.0 and Diginetwerk ensure secure, traceable queries.
Our development process for BRP integrations
We work to a proven methodology that removes uncertainty early and delivers a stable integration. From an initial analysis of your processes, authorisation decision and existing systems through to go-live and ongoing management, every step is aimed at an integration your team can understand and trust.
We map which BRP data you need for which processes, which route (Haal Centraal or StUF-BG) fits, and which fields fall within your authorisation decision and data minimisation requirements.
We design the integration architecture, arrange PKIoverheid certificates, OAuth 2.0 and the Diginetwerk connection, and define an error-handling strategy.
Implementation of the queries with automated tests, structured logging free of PII leakage, and monitoring. You see working builds along the way.
Controlled go-live with validation against the BRP and a fallback safeguard, followed by ongoing management, certificate rotation and further development.
What a BRP integration delivers in practice
Every BRP integration is set up specifically for your processes, authorisation decision and adjacent systems. Below are the functionalities we most often deliver for organisations that query personal data from the BRP for their services.
Looking up & searching persons
Look up a person by BSN or search by name, date of birth and address. The integration retrieves up-to-date personal details, marital status, partners, children, parents and nationality, from the BRP as well as the register of non-residents (RNI).
Residence history & occupancy
Query historical data: a person's residence history over a period or at a reference date, and the occupancy of an address over time. Essential for processes that need to look back at previous addresses or residents.
Information products
Alongside raw data, the BRP API delivers derived information products: addressing with correct salutations and address lines, guardianship of minors, age in years, full name with titles and predicates, and initials, ready to use in your letters and applications.
Data minimisation
The integration only requests the fields that fall within your authorisation decision and statutory task. We configure queries so that you receive no more personal data than strictly necessary, demonstrably in line with the GDPR and the RvIG's principles.
StUF-BG bridge & migration
Still using StUF-BG (SOAP/XML, LO GBA)? We connect to it or build a bridge that decouples your existing systems from the underlying route, so you can migrate step by step to the modern Haal Centraal API.
Logging and traceability
Every query is logged traceably, recording who, when and on what legal basis, without personal data leaking into URLs or plain-text logs. This keeps you in control of usage and ensures your processing register remains complete and auditable.
Typical use cases in practice
A BRP integration looks very different from one organisation to the next. We see a number of recurring patterns, and for each we have a working set-up with attention to authorisation, data minimisation and the right route (Haal Centraal or StUF-BG).
Municipalities
Municipalities that need up-to-date personal data for civil registration, the social domain and enforcement. The BRP integration feeds case management systems and forms with verified personal details and marital status data. See also our software for municipalities and Haal Centraal integration.
Health insurers
Health insurers that base their insured persons' administration and policy processes on up-to-date personal data. The integration verifies personal details, date of birth and place of residence at the source, with data minimisation within the authorisation decision and strict GDPR safeguards for sensitive data.
Pension funds
Pension funds and administrators that keep participant records current. Changes in marital status, partner relationships and address are verified at source, so benefits and correspondence are accurate. Residence history supports checks on lawfulness.
Implementing bodies
National and regional implementation organisations with a public task that need personal data for allowances, permits or enforcement. The integration delivers verified source data, with traceable logging and a legal basis for each BRP query.
Technology we use
We build BRP integrations using the official Haal Centraal BRP Bevragen API (REST/JSON) or the legacy StUF-BG standard, combined with the backend stack that suits you. The exact choice depends on your route, authorisation decision and existing systems, so that your own team can manage or further develop the integration.
Why choose Appfront for your BRP integration?
Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands, including the public sector. We always start with a thorough analysis of your existing systems, processes and authorisation decision. A BRP integration must not only work technically, but also fit within the legal framework and your way of working.
For every integration, we write clear documentation and make sure your own team, or a future supplier, can understand and manage it. No black box: just transparent code and clear agreements on monitoring, certificate management and alerting.
You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.
Also see our broader services around custom software, software for municipalities and related government integrations such as the BAG API integration, StUF integration and DigiD integration.
- Experience with the Haal Centraal BRP Bevragen API and StUF-BG
- Familiar with PKIoverheid, OAuth 2.0 and Diginet
- Works to data minimisation within your authorisation decision
- Secure by default: certificate rotation, scoped permissions, no PII in logs
- Structured error handling and retry mechanisms
- Comprehensive, traceable logging and monitoring from day one
- Clear documentation your team can read and manage
- A fixed point of contact, no account managers passed around
- Ongoing management and migration from StUF-BG to Haal Centraal
- A way of working aligned with your existing IT landscape
Security and privacy in BRP integrations
Personal data from the BRP is among the most sensitive data you can process, so access is strictly regulated. Queries may only be made within your BRP authorisation decision and public task, following the principle of data minimisation: only the fields you genuinely need. The Haal Centraal BRP Bevragen API requires a PKIoverheid certificate (mTLS), OAuth 2.0 authentication and traffic over Diginet, and uses the POST method so that no personal data ends up in URLs or server logs. Appfront builds on top of this in line with the OWASP ASVS.
The difference between the modern and the legacy route is also a security choice. The Haal Centraal BRP Bevragen API is designed around data minimisation and modern authentication. The legacy StUF-BG (LO GBA) works with SOAP/XML and has a different security model. For every query, we document the legal basis, the fields requested and the data flows, and we record traceable audit logs, so that your register of processing activities is complete and you can demonstrably comply with the GDPR. The application for the authorisation decision itself goes through the RvIG (Dutch Ministry of the Interior's authorisation body); we build and manage the integration within those frameworks.
More about related government integrations: DigiKoppeling and AI for municipalities and government. Questions about your specific situation? Get in touch.
- Querying within your BRP authorisation decision and public task
- Data minimisation: only the necessary fields
- PKIoverheid certificate (mTLS) and OAuth 2.0
- Traffic over Diginet, no PII in URLs or logs
- Traceable audit logs with a legal basis for each query
- Encryption in transit (TLS 1.2+) and at rest
- Secrets and certificate management according to best practice
- Documentation for your record of processing activities
Frequently asked questions about BRP integrations
Answers to the questions we are asked most often about BRP integrations.
A BRP integration is a technical connection between your application and the Basisregistratie Personen (Dutch Personal Records Database), managed by the RvIG. Using the modern Haal Centraal BRP Bevragen API (REST/JSON) or the legacy StUF-BG / LO GBA, your system queries up-to-date personal data at the source, such as name and address details, marital status, partners, children, parents and nationality. The BRP API deliberately uses the POST method rather than GET, so no personal data ends up in the request URL or server logs. An integration can be limited (querying one person by BSN) or broader (searching, residence history and occupancy).
The Haal Centraal BRP Bevragen API is the modern route: a RESTful API with JSON, an OpenAPI specification and data minimisation, so you only request the fields you need. StUF-BG (based on LO GBA) is the legacy standard, using SOAP/XML messages, and is still in use in many existing municipal and implementation systems. If you are building new, we almost always recommend the Haal Centraal route. If you have existing StUF components, we connect to them or build a bridge to the modern API. In an intake, we decide together which route fits your landscape and authorisation decision.
Through the BRP API you can retrieve, among other things, name and address details, date of birth, BSN, marital status, partner, child and parent details, nationality and place of residence, plus historical data via residence history and occupancy. The API also provides derived information products such as addressing (salutation and address lines), guardianship, age, full name and initials. Which fields you may actually request is determined by your BRP authorisation decision and the principle of data minimisation: you only gain access to the data required for your statutory task.
For the modern route, we work with the Haal Centraal BRP Bevragen API: REST, JSON and an OpenAPI 3.0 specification, with OAuth 2.0 (client credentials), a PKIoverheid certificate (mTLS) and a connection via Diginetwerk. For legacy, we integrate with StUF-BG (SOAP/XML, LO GBA). We build the backend in the stack that suits you, whether Node.js, Python, PHP, .NET, Java or Go. We set up structured logging, retry mechanisms and monitoring, so that queries remain reliable even at peak volumes.
The cost is determined by the chosen route (Haal Centraal or StUF-BG), the number of systems to integrate, the queries and information products required, and the amount of custom work in the business logic and error handling. The setup of PKIoverheid certificates, the connection to Diginetwerk and ongoing management also play a part. We always provide a clear quote following a no-obligation analysis of your situation and authorisation decision.
Personal data from the BRP is highly sensitive, so security and privacy are central. The BRP API requires a PKIoverheid certificate (mTLS), OAuth 2.0 authentication and traffic over Diginetwerk; because of the POST method, no personal data ends up in URLs or logs. Appfront builds according to the principle of data minimisation, only including the fields that fall within your authorisation decision and public task, and in line with the OWASP ASVS. We record audit logs and data flows so that your record of processing activities is complete and you can demonstrably comply with the GDPR.
Yes. Appfront regularly takes over existing BRP and StUF-BG integrations, even where they were originally set up by another party. We review the queries, certificate configuration, error handling and authorisation settings, document the current setup and propose improvements. From that point on, we handle adjustments, extensions and monitoring, including timely rotation of PKIoverheid certificates and migration from StUF-BG to the modern Haal Centraal route where that makes sense.
A BRP integration is only permitted for organisations with a public task and a BRP authorisation decision from the RvIG (Dutch Interior Ministry's Office for Identity Data). Think of municipalities, health insurers, pension funds and implementing bodies that need up-to-date name, address and civil status data for their processes and services. If you do not yet have an authorisation decision, we can help with the technical preparation, but the application and approval go through the RvIG. We handle the building and management of the integration within the framework your decision sets out.
Ready to build your BRP integration?
Tell us which personal data you need to query, which route suits you (Haal Centraal or StUF-BG) and which authorisation decision you hold. We are happy to advise on architecture, PKIoverheid, data minimisation and management. A no-obligation first conversation will give you a clear picture of your options within half an hour.