Base registries REST/JSON querying Real-time data

Custom Haal Centraal integration development

Appfront builds custom Haal Centraal integrations that let you query the national base registers in real time, from your case management system, forms module or own application. Through the uniform REST/JSON query APIs of VNG, RvIG and the Kadaster, you retrieve up-to-date personal, address or business data directly from the source, at the moment you need it. No more maintaining your own copies of data, fewer typing errors and demonstrably current data in every process.

What is Haal Centraal?

Haal Centraal is the initiative of VNG, RvIG and the Kadaster to query base registries via uniform, modern REST/JSON APIs, rather than through bulk delivery or local copies. The principle: when you need a piece of data, you request a targeted answer from the source registry, so you always work with current data. The Haal Centraal programme has now been completed; the APIs are managed by RvIG (BRP) and the Kadaster (BAG, BRK, WOZ).

The best-known query APIs are BRP Bevragen (current persons, partners, parents and children from the Personal Records Database, including the Non-Resident Records), BAG (addresses and buildings), BRK (cadastral data) and HR Bevragen (Chamber of Commerce/business register data). An important distinction: with Haal Centraal you query existing base registers, you do not register data through it yourself. In practice, a custom integration means calling the right APIs with the right authorisation, processing the JSON response in your own screens or processes, and only requesting the data for which you have a legal basis.

Appfront builds in line with the official API specifications of VNG Haal Centraal and the applicable government API standards (REST API Design Rules, Dutch API Strategy). We align authorisation, error handling and logging with your actual processes, so the integration keeps pace with new API versions and remains reliable under peak volumes. This complements our broader software for municipalities.

Real-time from the source

No more outdated copies of data: you query the BRP, BAG or BRK at the moment you need the information and receive the current answer straight from the source register. Register once, use many times, with fewer errors and less manual re-keying.

Consistent REST/JSON APIs

All Haal Centraal APIs follow the same modern design: REST, JSON and published OpenAPI specifications. One build approach for BRP, BAG, BRK and HR, so additional registers are easy to add to your integration later.

Controlled authorisation

Access runs through OAuth 2.0 / OpenID Connect and, typically, an API Gateway, with every query logged. You only request the data for which you have a legal basis, traceably recorded for your processing register.

Our development process for Haal Centraal integrations

We work to a proven methodology that removes uncertainty early and delivers a stable integration. From an initial analysis of your processes, required registers and authorisation through to go-live and ongoing management, every step is aimed at an integration your own organisation can understand, manage and account for.

1
Analysis & scope

We map out which registers you want to query (BRP, BAG, BRK, HR), which data you need, which legal basis applies, and which screens or processes the answers should feed into.

2
Architecture

We design the integration architecture, arrange authorisation via OAuth 2.0 / OpenID Connect and an API Gateway, and set out a strategy for error handling and logging.

3
Development

Implementation against the Haal Centraal test environment, with automated tests, structured logging and monitoring. You see working versions along the way.

4
Go-live & management

Controlled connection to the production environment with validation and safeguards, followed by ongoing management, monitoring and keeping pace with new API versions.

What a Haal Centraal integration delivers in practice

Every Haal Centraal integration is set up specifically for your processes, the registers you are permitted to query and your existing applications. Below are the capabilities we most often deliver for municipalities and implementing organisations that want to consult the base registers in real time.

BRP queries (persons)

Current personal data (name, address and residence details, partner, parents and children) directly from the Personal Records Database, including the Non-Resident Records (RNI). Your case management system or form populates the data automatically based on a BSN or search query, with no manual re-keying. See also our BRP integration.

BAG address validation

Validate and enrich addresses and buildings against the Key Register of Addresses and Buildings (BAG). An entered address is checked, completed and linked to the correct address-object and building data, resulting in fewer errors in applications and correspondence.

BRK and HR queries

Look up cadastral data via BRK Bevragen and business and trade register details via HR Bevragen. This way you consult ownership and company information within the same integration platform whenever your process requires it, using the same authorisation approach.

Authorisation via Gateway

Central authorisation and access management through an API Gateway and Identity Provider, using OAuth 2.0 / OpenID Connect tokens. Which queries and fields are permitted is enforced per user and per register.

Logging and traceability

Every query is logged in a traceable way: who requested what, when and on which legal basis. This keeps your processing register complete, supports audits and demonstrates that only authorised data has been requested.

Processing within your own screens

JSON responses are processed cleanly within your existing case management system, forms or web application, with error handling, retries and clear notifications if the source is temporarily unavailable. See also our custom software development.

Typical use cases in practice

A Haal Centraal integration differs from one organisation to another. We often see a number of recurring patterns among municipalities and implementing bodies, and for each of these we have a working setup that pays close attention to the correct registration, authorisation and processing.

Case management & public services

Municipalities that retrieve up-to-date personal details (NAW data) directly from the BRP when a request or notification comes in, so that a civil servant does not have to retype them and the applicant does not have to enter their details twice. See also our municipality website and ZGW API integration.

Online forms & e-services

Application forms for permits, benefits or grants that validate an address against the BAG and pre-fill personal details from the BRP. This reduces drop-off, prevents errors and speeds up processing. See also our BAG API integration.

Implementing bodies

Implementing bodies that need current personal or business details within their processes, for example for checks, decisions or correspondence. Rather than maintaining their own copy of the data, they query the source at the right moment, with logging and a legal basis recorded for each request.

Address & business verification

Processes that require cadastral or trade register data, such as checking property ownership via the BRK or verifying a company through HR Bevragen. The integration consults the correct register and processes the response with the same authorisation and logging as your other queries.

Technology we use

We build Haal Centraal integrations against the official REST/JSON query APIs and their OpenAPI specifications, combined with the backend stack that suits you. The precise choice depends on which registers you query and which authorisation and gateway setup you use, so that your own team can manage and further develop the integration.

For income data from the Basisregistratie Inkomen, see our page on a BRI integration.

Haal Centraal BRP Bevragen API BAG Bevragen API BRK Bevragen API HR Bevragen API REST / JSON OpenAPI (OAS) specifications OAuth 2.0 / OpenID Connect API Gateway & Identity Provider REST API Design Rules Dutch API Strategy Node.js / Python / PHP / .NET / Java TLS / secure connections Test & production environment Logging & monitoring Error handling & retries GitHub Actions

Why choose Appfront for your Haal Centraal integration?

Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands, including in the public sector. We always begin with a thorough analysis of your existing systems, processes and legal bases. An integration must not only work technically, but also fit within your legal framework and way of working.

For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.

You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.

See also our wider services for the public sector: software for municipalities, AI for municipalities and water board software. Questions about your situation? Get in touch.

  • Experience with the Haal Centraal query APIs (BRP, BAG, BRK, HR)
  • Familiar with government API standards (REST API Design Rules, Dutch API Strategy)
  • Authorisation via OAuth 2.0 / OpenID Connect and API Gateway
  • Attention to legal basis, data minimisation and traceable logging
  • Structured error handling and retry mechanisms
  • Comprehensive logging and monitoring from day one
  • Clear documentation your team can read and manage
  • A fixed point of contact, no account managers passed around
  • Ongoing maintenance and keeping pace with new API versions
  • A way of working aligned with your existing IT landscape

Security and privacy in Haal Centraal integrations

Querying basic registers almost always involves personal data, certainly with the BRP. Appfront therefore builds in line with data minimisation and the OWASP ASVS: querying only the fields for which you have a legal basis, authorisation via OAuth 2.0 / OpenID Connect and an API Gateway, secure connections, and traceable logging of every query. This way the integration aligns with the government frameworks for information security.

We document the data flows, the authorisation setup and the lawful basis for each query, so your record of processing activities is complete and you can demonstrate compliance with the GDPR. Logging every request - who, what, when and on which legal basis - serves as accountability for regulators and during audits.

More on our public sector expertise: software for municipalities and custom software.

  • GDPR-compliant querying with data minimisation and a lawful basis
  • Encryption in transit (TLS 1.2+) and at rest
  • Role-based access and least-privilege principles
  • Audit logs with traceable data flows
  • Automatic retries and dead-letter queues
  • Monitoring and alerting for anomalies
  • Secrets management in line with best practice
  • Documentation and logging for your record of processing activities

Frequently asked questions about Haal Centraal integrations

Answers to the questions we are asked most often about Haal Centraal integrations.

A Haal Centraal integration is a technical link between your application (such as a case management system, forms module or custom web application) and the government's Haal Centraal query APIs. Through these uniform REST/JSON APIs you query the basic registers in real time: BRP (Personal Records Database) for persons, BAG (Key Register of Addresses and Buildings) for addresses and buildings, and BRK (Land Registry) for cadastral data. This means you retrieve up-to-date data at the moment you need it, rather than maintaining your own copy file. The integration handles authorisation, the API calls and the processing of the JSON response in your own screens or processes.

Haal Centraal is specifically designed to query existing basic registers, not to maintain one yourself. You do not build a copy of the BRP or BAG; instead, you ask the source register a targeted question at the right moment and receive the current answer. This reduces the risk of outdated or incorrect data and fits the principle of 'register once, use many times'. Bulk delivery or locally synchronising complete registers is a different approach; Haal Centraal deliberately opts for real-time querying via APIs.

The Haal Centraal initiative provides query APIs for several basic registers. The best known are BRP Bevragen (current personal data from the Personal Records Database, including RNI), BAG (addresses and buildings) and BRK (land registry data); WOZ queries also fall under this. In addition, HR Bevragen exists for Chamber of Commerce / business register data. Which APIs are relevant to you depends on your processes - we will determine together which registers you need and which data you are permitted to retrieve from them.

Access to the Haal Centraal APIs is governed by controlled authorisation. In practice this means OAuth 2.0 and OpenID Connect via an Identity Provider, often combined with an API gateway that manages central authorisation and access control for the municipality. On top of that, the government's requirements for secure message exchange apply, such as secure connections and logging. Each register also has a legal basis: you may only request the data for which you have a statutory task and authorisation. We configure the integration so that only the permitted fields and queries are possible.

The cost is determined by the number of APIs to integrate (BRP, BAG, BRK, HR), the complexity of your authorisation and gateway setup, the degree of custom work in your own screens or processes, and the required logging and monitoring. Whether you connect to a test or production environment and which Identity Provider you use also play a role. We always provide a clear quote following a no-obligation analysis of your situation.

Yes, provided it is set up with care. Personal data from the BRP is particularly sensitive, so we build according to data minimisation: we only request the fields you genuinely need, on the basis of a valid legal ground. We document the data flows so your record of processing activities is complete, set up logging so that queries are traceable, and align authorisation with your statutory task. This way you can demonstrably comply with the GDPR and the government information security frameworks.

Yes. Appfront regularly takes over existing government integrations, even when they were originally set up by another party. We review the API calls, the authorisation and gateway configuration, the error handling and the logging, document the current setup and propose improvements. From that point on, we can handle changes, extensions to additional registers and monitoring, including keeping pace with new API versions.

Haal Centraal is intended for municipalities and implementing organisations that need up-to-date personal, address or business data in their processes. Think of a case management system that retrieves current name and address details from the BRP as soon as a request comes in, a form that validates an address against the BAG, or a process that consults cadastral or Chamber of Commerce data. Wherever you currently maintain your own copy file or retype data by hand, a Haal Centraal integration can make it current and reliable.

Ready to build your Haal Centraal integration?

Tell us which basic registers you want to query (BRP, BAG, BRK or HR) and into which case management system or application the data should land. We are happy to think along with you on authorisation, legal basis, logging and connection to the test and production environments. In a no-obligation first conversation you will get a clear picture of the possibilities. Schedule a conversation today.

Edit content