A permit register operates within a tighter regulatory framework than almost any other government application. A permit is a decision with legal effect, and the process leading to it is set out in detail in regulation. That determines how the system looks on the inside.
The Environment Act is the basis for the vast majority of physical living environment permits. It brings its own procedural and technical obligations: connection to the Digital Environment Act System, use of applicable rules in STTR, submission via STAM, coherence with the environmental plan, and the out-of-plan environmental plan activity (BOPA) as a specific route. On top of that sits the Building Quality Assurance Act (Wkb). For construction activities in consequence class 1, the technical review runs through an independent quality assurer, while the spatial part remains with the competent authority. Our register lets these two paths run in parallel.
The General Administrative Law Act (Algemene wet bestuursrecht, Awb) governs the entire process: admissibility, the duty to give reasons, the right to be heard, standard and extended procedures, decision deadlines, grounds for suspension and extension, and the permit granted by operation of law where that is not excluded. Deadline monitoring is built into the system itself. The GDPR and the Dutch GDPR Implementation Act (UAVG) set requirements for purpose limitation, data minimisation and data subject rights — we actively document which data is held where, on what legal basis, and how access or correction requests are handled technically.
The Baseline Information Security for Government (Baseline Informatiebeveiliging Overheid, BIO) sets requirements for logging, access management and incident handling. In a permit register, the audit log is literally part of the legal process — who gave which advice, who signed which decision, which extension was granted. The Digital Government Act (Wet digitale overheid) and the Digital Accessibility of Government Bodies Decree (Besluit digitale toegankelijkheid overheid) require WCAG 2.1 AA compliance — a design requirement that touches every component, independently audited before going live.
The AI Act applies to your system as soon as you deploy AI components, such as a classifier for incoming applications or an AI tool for reviewing building drawings. AI that supports decisions about people's rights is almost always classed as high-risk. We treat every AI function as a separate decision chain, with its own DPIA, its own entry in the Algoritmeregister (the Dutch public algorithm register) and its own evaluation cycle. See also our wider AI development practice. Finally, we work with the standards of VNG, Geonovum and Logius: GEMMA, Common Ground and NLX for inter-organisational integrations, and Haalcentraal for querying basic registers.