The Dutch intelligence oversight committee CTIVD has concluded that the country's two intelligence services, the general service AIVD and the military service MIVD, failed to meet legal requirements when processing bulk datasets. The report, published July 1, 2026, found that groups of employees had unlawful access to personal data and that large volumes of personal data were, in multiple cases, retained longer than the law allows.
Bulk datasets are large collections of personal data, sometimes running to millions of records. According to the CTIVD, they can contain names, phone numbers, location data, social media data, and the content of communications. The sources include other government bodies, commercial data vendors, and datasets that hackers have offered online. Dutch broadcaster NOS reported that the CTIVD's findings confirm the services use sets that surfaced through breaches.
The regulator attributes the failures to technical shortcomings in the services' systems and to procedures that do not adequately enforce policy and law. It issued 13 recommendations, including clarifying the legal definition of a bulk dataset. CTIVD chair Hugo Hillenaar said the vast majority of people in these datasets have nothing to do with espionage or terrorism, and that the safeguards, in his words, "simply have to be in order" (translated from Dutch).
The responsible ministers, Interior Minister Heerma and Defence Minister Yeşilgöz-Zegerius, wrote to parliament that the services recognize the picture the CTIVD paints, that fixing the problems is high on the agenda, and that some recommendations will feed into the upcoming revision of the intelligence law. They point to a fragmented data infrastructure that creates administrative pressure and raises the risk of human error, and note the services had already flagged several risks to the regulator themselves.
Digital rights organization Bits of Freedom, responding on July 2, argues the report shows a pattern rather than an incident. The group notes that in 2020 the same services were found to have retained data on millions of citizens far too long, and destroyed it only after Bits of Freedom filed a complaint.
The group also raises a more pointed claim. Based on the report, it says the services appear to be training their own AI on citizens' data, and appear even to purchase data originating from breaches. Bits of Freedom argues the law does not permit this, and that unlike with commercial services, citizens cannot opt out. The CTIVD material provided does not independently confirm the purchasing claim, and the services have not publicly addressed it.
Evelyn Austin, director of Bits of Freedom, said the services keep asking for more power while repeatedly showing they cannot handle the powers they already have, calling that especially worrying for agencies that operate in secret by design (translated from Dutch).
Get the ICD Newsletter
Subscribe for source-forward cyber news, OSINT notes, breach updates, and analysis. Have evidence or a lead? Send it to ICD.