Custom Suwinet integration
Appfront builds custom Suwinet integrations for municipal social services and other SUWI chain partners. Via Suwinet-Services (web services) and Suwinet-Inkijk, your own case management application requests authorised income, benefit and employment data, in line with Digikoppeling, the Suwinet standards framework and the ENSIA accountability requirements. This lets your team handle data within a single work process, without compromising on the strict security requirements of the SUWI chain.
What is a Suwinet integration?
Suwinet is the secure, shared infrastructure (the Gemeenschappelijke elektronische Voorziening Suwi, GeVS, or Shared Electronic Facility for SUWI) through which organisations in the SUWI chain exchange data with one another for their statutory tasks. The chain consists of UWV (the Dutch employee insurance agency), the SVB (the Social Insurance Bank) and the municipal social services that carry out the Participation Act. Suwinet is managed by BKWI, the Bureau Keteninformatisering Werk en Inkomen (Bureau for Information Chain Work and Income), a recognisable organisational unit of UWV acting on behalf of the Ministry of Social Affairs and Employment.
There are two ways to connect. Suwinet-Inkijk is a web application through which authorised staff manually consult a citizen's data. Suwinet Services are web services through which your own case management application requests authorised data system-to-system, such as income, benefit and employment data. Data is not stored in Suwinet; it is transported solely within government, with strict purpose limitation and only where a legal basis exists.
Appfront builds the integration based on the official BKWI Suwinet documentation and the OWASP ASVS security standard. We align web service calls, authorisation and logging with your working process and with the requirements of the Suwinet standards framework, so the integration fits both your existing software and the strict chain agreements. You should always verify the current specifications and connection requirements with BKWI. We also build integrations with related standards, such as Digikoppeling and the BRP (Personal Records Database).
Suwinet Services web services
System-to-system data exchange from your own case management application, in line with Digikoppeling. Your staff keep working in one environment instead of switching to a separate screen.
Authorisation per service
Access is granted per service and per role via Suwinet Authorisation. We configure the integration so that only authorised data within the purpose limitation of your statutory task is retrieved, and no more than necessary.
Framework & ENSIA
The integration is built within the Suwinet-specific normative framework, which is included in ENSIA. Logging, access restrictions and data minimisation are set up from the start so you can demonstrably account for them every year.
Our development process for Suwinet integrations
We follow a proven method that removes uncertainty early and delivers a stable, compliant integration. From an initial analysis of your working process, the services you need and BKWI's connection requirements through to go-live and ongoing management, every step is aimed at an integration that your team can understand, manage and account for.
We map out which Suwinet services you need, which statutory task and purpose limitation apply, how your authorisation is set up and where your case management application needs to connect.
We design the integration around the Suwinet Services web services, PKIoverheid certificates and mutual TLS, with logging and error handling that meet the normative framework.
Implementation with automated tests, complete audit logging and monitoring. We test against the chain acceptance environment, and you see working builds along the way.
Controlled go-live following BKWI's connection procedure, followed by ongoing management, certificate rotation and support with ENSIA accountability.
What a Suwinet integration delivers in practice
Every Suwinet integration is set up specifically for your workflow, the services you are permitted to use and the adjacent systems in your IT landscape. Below are the capabilities we most often deliver for municipal social services and other SUWI chain partners.
Data within your case management application
Authorised income, benefit and employment data is shown directly within your own case management application via Suwinet-Services. Your case manager or advisor stays in one screen, without switching to a separate inquiry environment.
Tailored web service calls
We integrate exactly the Suwinet services you need, with proper error handling, timeouts and retry logic. If a source is unavailable, this is handled cleanly, so your process does not stall and the employee sees a clear message.
Authorisation and role management
Setup of roles and rights in line with Suwinet-Autorisatie, so that each employee sees only the services and data relevant to their task and legal basis. Layered authorisations keep management clear and demonstrable.
Complete audit logging
Every inquiry is recorded in a traceable way: who, when, which data and on what legal basis. This logging is aligned with the framework and provides the evidence you need for ENSIA reporting and internal audits.
Data minimisation & purpose limitation
The integration only requests what the workflow needs, at the right moment. No unnecessary queries, no superfluous storage: data is transmitted and displayed, not duplicated. This keeps the privacy impact as small as possible.
Certificate and connection management
Management of PKIoverheid certificates and mutual TLS connections, including timely rotation and monitoring of expiring certificates. Disruptions in the chain are flagged early, so data exchange remains reliably available.
Typical use cases in practice
A Suwinet integration looks different for each organisation. We often see a number of recurring contexts within the SUWI chain, and for each of these we have a working setup with attention to authorisation, purpose limitation and the normative framework.
Municipal social services
Case managers who implement the Participation Act and need authorised income, benefit and employment data at intake, re-assessment and eligibility review. The integration brings this data into the case management application, within a single workflow. See also our software for municipalities.
Debt assistance
Debt assistance cases where an up-to-date and reliable picture of income, benefits and employment is essential to draw up a plan. With the right authorisation, the case worker retrieves the necessary data, with complete logging and strict purpose limitation.
Income support
Special assistance, schemes for people on low incomes and other forms of income support where the municipality must be able to substantiate eligibility. Authorised data from the chain supports a careful, fast and traceable assessment of applications.
Enforcement & compliance
Supervision and enforcement teams that investigate signals of unlawful conduct within their statutory remit. The integration delivers only the relevant data to authorised users, with full traceability of every query for accountability and audit.
Technology we use
We build Suwinet integrations around the Suwinet-Services web services, in line with Digikoppeling and the applicable chain agreements. The precise implementation depends on the services you use and your existing back end, so that your own team can manage and account for the integration. We verify the current technical specifications per service with BKWI.
Why choose Appfront for your Suwinet integration?
Appfront has extensive experience building integrations with government standards and API integrations for organisations in the Netherlands. We always begin with a thorough analysis of your working processes, the services required and the chain agreements. A Suwinet integration must not only work technically, but also demonstrably remain within the legal framework.
For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand, manage and account for it. No black box, but transparent code and clear agreements on authorisation, logging, monitoring and certificate management.
You work with a dedicated point of contact who understands both the technology of Suwinet-Services and the requirements of the normative framework. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during the build.
See also our wider services around software for municipalities, custom software, the Digikoppeling integration and the BRP integration. Questions about your situation? Get in touch.
- Experience with government standards, Digikoppeling and web services
- Familiar with Suwinet-Services, Suwinet-Inkijk and authorisation per service
- Works within the Suwinet normative framework and ENSIA accountability
- Secure by default: PKIoverheid certificates, mutual TLS, scoped permissions
- Structured error handling and retry mechanisms
- Complete audit logging and monitoring from day one
- Clear documentation that your team can read, manage and account for
- A fixed point of contact, no account managers passed around
- Ongoing management, certificate rotation and proactive further development
- A way of working tailored to your existing IT landscape and the chain agreements
Security and privacy in Suwinet integrations
Suwinet gives access to highly sensitive personal data, such as income, benefits and employment details, and is therefore strictly regulated. Connected organisations must comply with the Suwinet-specific standards framework, which has been fully incorporated into ENSIA since 1 April 2017 and consists of standards divided into policy, implementation and control domains. You account for compliance with these annually through the ENSIA system. The legal basis is the Wet SUWI (SUWI Act) and the Regeling SUWI (SUWI Regulation), with strict requirements for purpose limitation, authorisation per service and traceability. Appfront also builds in line with the OWASP ASVS.
In practice, we set up the integration with PKIoverheid certificates and mutual TLS, authorisation per service via Suwinet-Autorisatie, strict data minimisation and watertight audit logging that records, for every lookup, who requested data, when and on what legal basis. Data is only transported and displayed, never duplicated in your application. We document all data flows so that your processing register is complete, you demonstrably comply with the GDPR and you pass the Suwinet audit within ENSIA. You should always verify the final standards and connection requirements with BKWI.
More about our approach to security: our information security policy and vulnerability disclosure policy. Or schedule an advisory call about your connection.
- Complies with the Suwinet standards framework (within ENSIA)
- In line with the Wet SUWI and Regeling SUWI, with strict purpose limitation
- Authorisation per service via Suwinet-Autorisatie
- PKIoverheid certificates and mutual TLS 1.2
- Traceable audit logging for every query
- Data minimisation: transmission only, no storage in your application
- Monitoring, alerting and timely certificate rotation
- Documentation for your record of processing activities and ENSIA accountability
Frequently asked questions about Suwinet integrations
Answers to the questions we are asked most often about Suwinet integrations.
A Suwinet integration connects your application to Suwinet, the secure infrastructure that SUWI chain partners (UWV, SVB and municipal social services) use to exchange data. Alongside querying data through the Suwinet-Inkijk web application, Suwinet-Services (web services) let you retrieve authorised income, benefit and employment data system to system from your own case management application. Suwinet is managed by BKWI, an organisational unit of UWV. Always verify the current conditions with BKWI.
Connecting to Suwinet is reserved for organisations with a statutory task and legal basis within the SUWI chain, such as UWV, SVB and municipal social services departments that implement the Participation Act. Data is only exchanged if there is a legal basis and purpose limitation for it. Whether and how your organisation may connect, and which services you may use, is determined by BKWI in the authorisation process. Appfront builds the technical integration; you confirm the connection requirements with BKWI.
Suwinet-Inkijk is a secure web application that allows authorised staff to look up a citizen's data manually. Suwinet-Services are web services that let your own line-of-business application retrieve data automatically, system to system, without an employee having to switch to a separate screen. For a seamless integration within your own software, Suwinet-Services is usually the most suitable route. Together with you, we assess which variant fits your process and authorisation.
Suwinet-Services are SOAP web services offered in line with Digikoppeling, with pull and push profiles depending on which party initiates the exchange. Messages containing privacy-sensitive data are encrypted using mutual TLS 1.2 with PKIoverheid certificates. We connect these web services to your existing back end, whether Node.js, Java, .NET, Python or PHP, with robust error handling and logging. We verify the final specifications for each service against the current BKWI documentation.
The cost depends on the complexity of the integration, the number of services you use, how authorisation and logging are set up, and the degree of customisation in your line-of-business application. Meeting the Suwinet standards framework and the ENSIA accountability requirements also demands care. We always provide a clear quote after a no-obligation analysis of your situation and BKWI's connection requirements.
Suwinet is strictly regulated. Connected organisations must comply with the Suwinet-specific standards framework, which has been included in ENSIA since 2017, and report on this every year through the ENSIA process. The legal basis lies in the Wet SUWI (SUWI Act) and the Regeling SUWI (SUWI Regulation), with strict purpose limitation and authorisation per service. Appfront builds the integration with PKIoverheid certificates, mutual TLS, tight access control, comprehensive logging and data minimisation, so you can demonstrably comply with both the standards framework and the GDPR.
Yes. Appfront takes over existing Suwinet integrations, including those originally set up by another party. We review the web service calls, certificate chains, authorisation setup, logging and error handling, document the current set-up and assess it against the standards framework. From that point on, we handle changes, the addition of extra services and monitoring, including timely rotation of PKIoverheid certificates.
Via Suwinet, data is made available from, among others, UWV, SVB, municipalities, the BRP (Personal Records Database), the Chamber of Commerce register, the Tax Authority and the RDW (Netherlands Vehicle Authority), to the extent necessary for the statutory task. In practice, this mainly concerns income, benefit and employment data that municipal social services, debt assistance and enforcement teams need. Which services you may use exactly depends on your authorisation. Data is not stored in Suwinet but only transported; you verify the current set of services with BKWI.
Ready to build your Suwinet integration?
Tell us which Suwinet services you want to use and which case management application the data should flow into. We're happy to help with Suwinet Services, authorisation, the normative framework and the ENSIA accountability requirements. A no-obligation first conversation will quickly give you a clear picture of what's possible. You verify the connection requirements with BKWI.