RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division

10 August 2026· 39 min read confirmed
John van der Velden
John van der Velden
Independent Researcher
BelastingdienstBelastingdienst MKBMinistry of FinanceT. van OostenbruggenKPMGAutoriteit PersoonsgegevensAuditdienst RijkTweede KamerRIECLIECLSIiCOVSVBUWVDT BDDF&A
RDM Regio Data Model RAM Risk Analysis Model Tax and Customs Administration MKB Rivierenland National Customer Image compliance colours profiling discrimination GDPR Dutch Personal Data Protection Act nationality postcode Lekkerbek fish stalls RIEC LIEC iCOV fundamental rights

The Regio Data Model (RDM) was the MKB-specific risk classification layer of the Tax and Customs Administration, built on top of the Risk Analysis Model (RAM), originating in 2009 in the Rivierenland region. The system carried four different names with the same abbreviation and classified 1.9 million MKB entities by compliance colours. RDM drew its information from RAM and fed the National Customer Image. The House letter of 26 May 2025 confirms that RAM was used for years structurally in violation of statutory requirements and that 14 spreadsheets selected on nationality.

Summary

The Regio Data Model (RDM) was the Tax and Customs Administration’s risk model for SMEs, built on top of the broader Risk Analysis Model (RAM). It began in 2009 in the former Rivierenland region and grew into a national system that assigned compliance colours (White, Green, Yellow, Orange, Red) and turnover benchmarks in eight quadrants to 1.9 million SME entities. The same system had four different names, all abbreviated RDM. The Written Consultation of 26 May 2025 states that the underlying RAM infrastructure was used for years “structurally in violation of statutory requirements in the areas of data protection, security and archiving.”

RDM pulled its data from RAM and fed the National Customer Image (Landelijk Klantbeeld), with deliveries to at least ten collaborative partnerships, including RIEC, LIEC, LSI, iCOV and the Counter-terrorism information box. The House letter of 6 March 2025 identified 14 spreadsheets with selection on nationality and 35 spreadsheets with selection on postcode, out of 1,170 RAM extracts found. A confidential memo of 2 February 2021 reports that nationality data of SME entrepreneurs remained uncleaned in a replacement analysis environment from May 2018 to January 2021 — a structural GDPR violation of 2 years and 8 months.


The system that carried four names

The sources show the same instrument under four different names, all abbreviated RDM. This is not sloppy editing. It reflects an instrument that grew informally for twenty years without a formal product name and without a central owner.

#NameSourceFrequency
1Regio Data ModelOwn title page 3 March 2015; KPMG report section 6.6.10; Government.nl; Written Consultation 26-5-2025Official
2RisicoDataModelInternal operational inventory table Annex 1B3 of 29 mentions
3Risicomodel RivierenlandProject report second-hand car trade, Annex 1AWorking name
4Risicodatamodel RivierenlandProject report second-hand car trade, Annex 1AWorking name

Names 3 and 4 combine the words “Risico” and “Rivierenland”. This is presumably the original working name from 2009 when the instrument was built locally in the Rivierenland region by an Intelligence working group. In the following years the name generalised to “Regio Data Model”, while “Risico…” remained as a functional working name in certain internal operational tables, probably to align with the broader RAT family (Risk Analysis Tool StiVer, RAT ANBI, RAT Follow the Money, RAT Verhuurdersheffing).

The formal name

The KPMG report of 25 February 2025 consistently refers in section 6.6.10 to “Regio Data Model (RDM)” and quotes a description provided by organisational unit MKB. The Government publication of 6 March 2025 and the House of Representatives documents use the same name. In this investigation we use only the formal name.


The operating mechanism

ElementContent
Origin2009, Rivierenland region, Intelligence working group
GuidelineMLTP 2011-2015 (Long-Term Multi-Year Plan Tax and Customs Administration)
Target groupMKB enterprises (1.9 million entities), including ZZP (self-employed), STARTERS, tax consultants
Source filesIKB, RAM, BI files; with ACL (EDP_Audit) flat files on Entity Number and Tax Number
ArchitecturePresentation and selection layer on top of RAM (RDM drew information from RAM, later Track 2/Track 3)
OutputsCompliance colour per BSN/entity per year, quadrant benchmark per sector, score for National Customer Image

Three categories of disruptions

RDM classified behaviour along three axes, derived from the spearheads of the MLTP 2011-2015.

CategoryDisruptions
Filing behaviourVAT filing defaults; ex officio VPB; ex officio IH; wage tax filing defaults; ATA project contact moments
Payment behaviourVAT payment defaults; wage tax payment defaults; INL balance positions 2010-2015; current outstanding amount; irrecoverable losses
Accuracy/Completenessaudit corrections; IH additional assessments; VPB additional assessments; VAT supplementary assessments; wage tax supplementary assessments; system assessments VAT

The makers of RDM themselves set a methodological limit: “we chose not to simply link all kinds of files from ‘handy Harries et al’.” There was therefore awareness of the risk of uncontrolled data combination. That awareness did not lead to GDPR-compliant design.

Five compliance colours

Each BSN, entity or tax number received a colour per year that determined whether it qualified for the so-called integrated approach: audits, system assessments, visits and recovery.

ColourMeaning
WhiteNot visited in the past 6 years and no disruptions
GreenVisited in the past 6 years, but no disruptions
YellowOne disruption in one of the three categories
OrangeTwo disruptions in two categories
RedAll three categories affected

The colour was cumulative: one filing default plus one payment default in the same year automatically produced at least Orange, regardless of the factual context. The description in the original RDM document itself warns that VPB and IH figures are “at the very least debatable” because those taxes have only one filing moment per year, often with deferral arrangements, making the data structurally at least one year out of date. Nevertheless, that data was used for risk scores with direct enforcement consequences.

Eight quadrants

In addition to the colour, per Region → Theme/attention area → Branch code the total declared VAT turnover could be divided by the number of active entrepreneurs, resulting in a turnover benchmark in eight bands.

QuadrantTurnover vs. group average
Agreater than 150%
B125 to 150%
C100 to 125%
D75 to 100%
E50 to 75%
F25 to 50%
Gless than 25%
(none)no VAT activity

An entrepreneur in quadrant A in combination with compliance colour Red automatically came into view for integrated approach. The system thus made group comparisons with direct enforcement consequences, without there being an individually identifiable irregularity.

Bankruptcy prediction without validation

The RDM document describes a predictive function based on historical bankruptcies:

“The latter [W=probable] is based on a query built on the behaviour over the years 2010/2012 of entities that have gone bankrupt; this query is run over the mass without the bankrupt entities and returns those entities that are about to (probably) go bankrupt.”

This is an unsupervised discriminant analysis on two years of historical bankruptcies, run over the living MKB mass. The document contains no specification of sensitivity, specificity or false-positive rate. No human review-before-check is described. Companies that received the “probably bankrupt” label ran the risk of early recovery, assessments and credit restrictions — a self-fulfilling prophecy without published validation.


The relationship with RAM

The KPMG report establishes in section 6.6.10 an architectural fact that is not explicitly stated in the own RDM document from 2015:

“DF&A indicated that RDM drew its information from RAM, and later from Track 2/Track 3.”

RDM was therefore not a stand-alone system. It was a presentation and selection layer built specifically for the MKB segment, on top of the underlying RAM infrastructure.

Two views on the same system

SourceStatement on the deployment of RDM
Own RDM document 3 March 2015Broad deployment: integrated approach, compliance colours, bankruptcy prediction, score for National Customer Image, ranking of tax consultants
KPMG RAM report section 6.6.10, 25-2-2025“RDM was only used for the selection of book investigations and the logistical process of assigning these book investigations to the offices.”

The discrepancy may stem from a difference in time: the 2015 RDM report describes ambition and wishes; KPMG looks back in 2025 at actual deployment between 2013 and 2024. There may have been a loss of function after the migration to AWS 6/7 in 2018-2019, in which RDM degraded from a broad customer image instrument to a logistical selection tool. For file use, this means that statements about RDM impact must always be checked against the KPMG report and must not assume the broad RDM report from 2015.

Who built and managed RDM

A programme scoping document states:

“The capacity deployment of the business consists, in addition to the provision of a programme manager, of the deployment of the required project leaders/product owners and the deployment of intelligence staff (RAM/RDM builders).”

The construction and management of RDM was the responsibility of intelligence staff of the MKB segment. Not an independent regulator. Not an IT organisation with formal quality control. The term “RAM/RDM builders” confirms the close technical interweaving of both systems and the absence of a separation between developer, manager and user.


Victims and scale: 11 million citizens, 1.9 million entrepreneurs

The scale of profiling via RDM and the underlying RAM is difficult to grasp. The State Secretary states in the Written Consultation that “virtually every taxpayer, citizens and businesses, was findable in RAM.” Below the documented numbers.

Victims by category

CategoryNumberSource
Citizens in Tax Administration data11 millionWRR Working Paper 021, 2016
MKB entities in RDM1.9 millionRDM document 3 March 2015; MKB Intelligence-base
Enterprises in RAM data1.5 millionWRR Working Paper 021, 2016
RAM entities (total)2.2 millionKPMG report February 2025
Vehicles in RAM10.5 millionKPMG report part 1
Allowance families affected~26,000Parliamentary documents
FSV registrations~180,000 citizensPwC; Donner Committee
RAM selections in 20 years~500,000AP letter July 2025; KPMG
RAM extracts recovered1,170 (0.25%)KPMG; AP
Spreadsheets containing nationality369 of 1,170KPMG
Spreadsheets with selection on nationality14Written Consultation 26-5-2025
Spreadsheets with selection on postcode35Written Consultation 26-5-2025
Excel files distributed via USB/email/CD2,662KPMG
Book investigations MKB per year via RAM9,683 (44% of 22,000)Memo 11-4-2018
Nationality files in track 2 IVT23 (2012-2016)Nationality memo 2-2-2021
Files containing bank data7Nationality memo 2-2-2021
Files containing WOZ values9Nationality memo 2-2-2021
Data vault total files64 millionHouse letter 2026D24511
Data vault substantive files24.3 millionHouse letter 2026D24511
Excel files in data vault~2 millionHouse letter 2026D24511
Files in unopened ZIPs~87,000 relevantTechnical briefing 26-5-2026
Unique file types in data vault31,000Technical briefing 26-5-2026
Mailboxes of Toeslagen employees1,004House letter 2026D24511
Period of GDPR violation on nationality2 years 8 monthsNationality memo 2-2-2021

RAM usage 2017 — who queried what

The memo of 11 April 2018 from the Chain Generic Facilities Supervision and Office to the Management Team Tax Administration contains the first documented RAM usage figures for 2017. MKB completely dominated usage.

SegmentCustomer Image%Spec-dataTotal%
MKB4,62795%11,07119,09189%
Directie Belastingen1233%1,1001,3186%
Belastingdienst/Switch00%6868< 1%
FIOD321%1021361%
GO271%1671971%
Douane471%831371%
Belastingdienst Toeslagen00%11< 1%
PDB150%1852111%
Other210%2132341%
TOTAL4,891100%12,98821,394100%

The MKB segment was responsible for 44% of 22,000 book investigations in 2018 (9,683 investigations) based on RAM selections. RAM was thus the primary instrument for MKB enforcement. The Tax and Customs Administration’s Toeslagen division had only one record in 2017. That does not mean Toeslagen did not receive RDM data — that happened via the chain collaboration partnerships — but direct front-end access was negligible.

The invisible victims

The figures tell only part of the story. Who was specifically disadvantaged by RDM profiling can no longer be reconstructed. The state itself states:

“Given the time that has passed, it is no longer possible to establish which data from RAM was shared with which collaborative partnerships.” — Decision note 7-5-2025

The 500,000 selections in 20 years of RAM are the upper limit of the number of individuals who may have been directly affected. Less than 0.25% of those selections have been recovered from archives. The remaining 99.75% may be in the 2 million Excel files in the data vault, or has been destroyed. The 14 spreadsheets with selection on nationality contain an unknown number of citizens. Citizens who appear in these spreadsheets have not been informed to date.


Project Lekkerbek: fish stalls as a risk group

In the Decision Note of 7 May 2025 the State Secretary refers to “the project on fish stalls.” The Written Consultation of 26 May 2025 confirms in paragraph 6 that this concerned Project Lekkerbek, a local initiative aimed at mobile fish stalls.

What data was collected

The project explicitly used RAM to map the regional population of mobile fish stalls and then added:

  • name, business address, legal form (EMZ, VOF, BV)
  • tax number (BSN, RSIN, VAT number)
  • profit return IH/VPB (turnover, purchase value, costs, investments)
  • wage data (wage sum, number of employees)
  • ratio figures such as wage/turnover and gross profit percentage
  • filing and payment behaviour

On this basis, information meetings were organised, question letters sent, company visits and book investigations carried out. The State Secretary concluded: “As far as can be ascertained, this project was carried out with safeguards, and given the data used, I see no reason to suspect (in)direct discrimination.”

Other projects without further information

DENK MPs also asked about projects mentioned in the KPMG report on page 130: Security companies, Cleaning sector and Amsterdam Taxi companies. The answer reads:

“No further information has become available about the other mentioned projects. It should be borne in mind that these projects took place an estimated 10 to 15 years ago.”

The Tax and Customs Administration thus cannot reconstruct which safeguards applied to a number of projects in the 2010-2015 period. That is precisely the period in which the toeslagenaffaire took place.


Evidence of discrimination: 14 spreadsheets, 4 specific nationalities

The most explosive part of the Written Consultation of 26 May 2025 is paragraph 5. The State Secretary confirms what was already announced in the House letter of 6 March 2025.

“In my letter of 6 March 2025 I already confirmed that in 14 of the 1,170 spreadsheets found, first and/or second nationality was used as a selection criterion.” — State Secretary T. van Oostenbruggen, Written Consultation RAM, 26 May 2025

The four nationalities in the 14 spreadsheets

The AP report of 9 July 2025 (reference 2025-002145), signed by AP board member Katja Mur, specifies in footnote 3 which nationalities are involved:

“This concerns the Bulgarian, Romanian, Afghan or Albanian nationality as first and/or second nationality.” — Autoriteit Persoonsgegevens, letter to State Secretary Van Oostenbruggen, 9 July 2025

This is not an abstract selection on “foreign nationality” in general. It concerns four specific nationalities: three of them are Eastern European EU member states (Bulgaria, Romania, Albania is not EU but a candidate member state), and one is an asylum country (Afghanistan). The selection thus combines an Eastern European and an asylum seeker profile — precisely the groups that were disproportionately hard hit in the toeslagenaffaire.

CategoryNumberSelection criterionSource
Nationality spreadsheets (House letter)141st and/or 2nd nationalityWritten Consultation 26-5-2025
Nationalities in these 14 spreadsheets4Bulgarian, Romanian, Afghan, AlbanianAP report 9-7-2025, footnote 3
Postcode extracts (according to AP)61PostcodeAP report 9-7-2025
Postcode spreadsheets (according to House)35Postcode (optionally + house number)Written Consultation 26-5-2025
Total RAM spreadsheets found1,170diverseKPMG report
RAM selections in 20 years~500,000unknownAP report; less than 0.25% recovered
Excel files with nationality369 of 1,170diverseKPMG report

Discrepancy 35 versus 61 postcode extracts

There is a difference between the number of postcode extracts that the House (35) and the Autoriteit Persoonsgegevens (61) mention. The AP report explicitly states: “You have now indicated that selections on postcode will also be examined, concerning 61 RAM extracts.” Possibly the state subsequently identified more extracts, or the 35 is a subset reported to the House while the AP knows the broader 61. For the file, the highest known number (61) is guiding.

Citizens not yet informed

“Since it is not clear for what purpose these spreadsheets were prepared and whether the use of these spreadsheets led to a violation of a citizen’s fundamental right, citizens who appear in this spreadsheet have (not yet) been informed.” — State Secretary T. van Oostenbruggen, Written Consultation RAM, 26 May 2025

Citizens whose nationality was selected in a spreadsheet for tax supervision do not know that this happened. The State Secretary states that investigation must first establish whether there was a violation. That investigation is conducted using the methodology of the Compensation Act for Selection at the Gate (Wet compensatie wegens selectie aan de poort) and is tested by the Auditdienst Rijk. The Autoriteit Persoonsgegevens follows the analyses.

Premature refusal of a compensation fund

In response to the question from the DENK party whether the cabinet is considering a compensation fund comparable to the toeslagenaffaire, State Secretary T. van Oostenbruggen (Finance — Taxation, Tax and Customs Administration and Customs) replied in the Written Consultation of 26 May 2025:

“If there is a demonstrated need for recovery, a proposal for coverage is also appropriate. The cabinet sees no need to consider a compensation fund for this.” — State Secretary T. van Oostenbruggen, Written Consultation RAM, 26 May 2025, Our reference 2025-0000101261

This refusal comes before the investigation into the 14 nationality spreadsheets has been completed, before the legal analysis of the postcode extracts has been completed, and before the Auditdienst Rijk or the Autoriteit Persoonsgegevens have pronounced. The refusal is premature and difficult to reconcile with the own recognition that a responsibility rests on the state in cases of fundamental rights violations.


The nationality memo of 2 February 2021

In Annex 1A of the KPMG submission there is a confidential memo of 2 February 2021 that only became public in 2025. The document describes a discovery that significantly completes the RDM/Track 2 story.

Timeline of the discovery

DateEvent
8 January 2021During ANBI work, discovered that an uncleaned RAM extract is on the track 2 IVT environment
14 January 2021Factual finding: 1st and 2nd nationality recorded in multiple files
19 January 2021Investigation started via query logging in Splunk; order to remove nationality
21 January 2021Investigation completed
1 February 2021Confirmation by all known MKB users that they did not use the uncleaned extract
2 February 2021Memo recorded, confidential

What was found

The scan by an MKB and a DF&A analyst produced:

  • 23 unique files with nationality, distributed across 2012 (2), 2013 (7), 2014 (6), 2015 (4), 2016 (1) and 3 files with unknown year
  • 7 files contained bank data
  • 9 files contained WOZ values
  • No logging in the track 2 IVT environment, so use cannot factually be ruled out
  • No server-side export with nationality in 2019 and 2020
  • Client-side export cannot be ruled out

The explanation

“When placing the relevant RAM extract on the track 2 IVT environment, a cleaning operation was carried out to ensure GDPR compliance. However, due to human error, an uncleaned extract of RAM was placed on the IVT track 2 environment.”

The cleaning was explicitly ordered on 24 May 2018, as Annex 1C documents: “Nationality 1 and 2 are marked for deletion.” The cleaning was carried out on 12 to 15 June 2018 with written confirmation. Nevertheless, on 14 January 2021, it was discovered that nationality was still present.

The period of unlawful processing

From 25 May 2018 (entry into force of GDPR) to 19 January 2021 (removal of nationality from track 2 IVT), the period of structural GDPR violation amounts to 2 years and 8 months. Every MKB entrepreneur with a first or second nationality who was included in a RAM-based or derived product during that period has a presumption of unlawful processing of special personal data within the meaning of Article 9 GDPR in conjunction with Article 1 of the Equal Treatment Act.


Ten collaborative partnerships received data

Paragraph 4 of the Written Consultation lists the collaborative partnerships that received data from RAM. This list is of particular importance for the file because several of these partnerships have participants from the social security domain.

#PartnershipRelevant participantsPossible spillover
1National Approach to Address Quality (LAA)MunicipalitiesAddress control, assistance
2Financial Expertise Centre (FEC)FIOD, police, Public Prosecution Service, AFM, DNB, FIUCriminal law
3Regional Information and Expertise Centres (RIECs)Police, Public Prosecution Service, municipalities, UWV (Employee Insurance Agency), SVB (Social Insurance Bank)Subversion, social security
4National Information and Expertise Centre (LIEC)Idem + SZW (Ministry of Social Affairs)Idem
5National Steering Group Intervention Teams (LSI)Idem + SZW, UWV, SVBIdem
6Infobox Criminal & Unexplained Assets (iCOV)JusticeAsset seizure
7BIBOB CollaborationJusticePermit refusal
8Citydeal Visibility on SubversionMunicipalitiesLocal supervision
9Counter-terrorism CT infoboxJustice and SecurityCounter-terrorism
10Healthcare Fraud NodeVWS (Health), health insurersHealth insurance

The State Secretary relativises the importance of these data flows:

“Without RAM, largely the same data could have been provided as with RAM (with the exception of data generated with RAM).”

That relativisation is only partly valid. The data generated by RAM concerned calculated fields with totals and risk scores per tax service provider. These scores, which were found in spreadsheets by KPMG, form the vulnerable point. The State Secretary then states:

“The 20-year period in which RAM was used makes it no longer possible to establish over that period which data was shared, with what frequency, and with which collaborative partnerships. Nor can any statements be made about the extent to which the data was used outside a collaborative partnership.”

For individual victims, this means that the burden of proof is factually impossible. The state acknowledges that data has been shared with at least ten chain partners for twenty years, but cannot reconstruct what, when, with whom, and for what purpose.


Guilt acknowledged by the state

The Written Consultation of 26 May 2025 contains acknowledgments by State Secretary T. van Oostenbruggen that are new in their explicitness in the toeslagenaffaire. Where previous officials hid behind “the system”, “unforeseen” and “complex”, the State Secretary now acknowledges structural breach of the law, regret, and personal responsibility for fundamental rights violations. These quotes work in administrative or civil proceedings as facts that can no longer be denied. The burden of proof shifts to the State.

Seven acknowledgments in a row

#Quote (line in Written Consultation)What is acknowledged
1“RAM was used for years in a way that structurally violated statutory requirements in the areas of data protection, security and archiving.” (192-194, NSC — State Secretary shares this view)Structural violation of the law
2“I share the view of the NSC party that KPMG’s findings about RAM are serious. […] It is unacceptable that the Tax and Customs Administration used RAM and […] I regret that.” (197-201)Unacceptability + regret
3“If mistakes were made with RAM that led to serious consequences for citizens, such as a violation of fundamental rights, then I believe I have a responsibility for that.” (203-206)Personal responsibility for fundamental rights violations
4“RAM was not limited to MKB companies, however. Ultimately, virtually every taxpayer, citizens and businesses, was findable in RAM.” (175-176)Population size: 11 million citizens + 1.5 million enterprises
5“That there was a risk that RAM possibly had long been non-compliant with the prevailing Wbp, we found only in the aforementioned ‘CDO Risk’ document for the concern directors in January 2017.” (744-749)Wbp violation known to concern directors 16 months before GDPR
6“From 1998 to 2010, decision-making authority over RAM was decentrally assigned within the Tax and Customs Administration […] In addition, the supervisory interest prevailed within the Tax and Customs Administration.” (763-768)Administrative failure acknowledged
7“The Tax and Customs Administration acknowledges that the lack of logging and monitoring in RAM resulted in deficient insight.” (391-397)Evidence destruction / impossibility of reconstruction acknowledged

What the State thereby acknowledges

The seven acknowledgments together form a complete removal of the main arguments that the State made in earlier proceedings:

  • Where the State previously argued that there was no question of intent or structural failure, it now acknowledges structural violation of the law (quote 1)
  • Where the State previously argued that the system operated within bounds, it now acknowledges unacceptability and regrets it (quote 2)
  • Where the State previously shifted responsibility to individual officials or the system, the State Secretary now takes personal responsibility for fundamental rights violations (quote 3)
  • Where the State previously argued that the FSV was an isolated problem, it now acknowledges that virtually every taxpayer was in RAM (quote 4)
  • Where the State previously argued that it was unaware of the problems, it now acknowledges that the concern directors were informed in January 2017 about Wbp violations (quote 5)
  • Where the State previously argued that there was adequate administrative control, it now acknowledges that between 1998 and 2010 decision-making authority was decentralised and the supervisory interest prevailed over the legal requirements (quote 6)
  • Where the State previously argued that the files had been delivered completely, it now acknowledges that logging was missing and reconstruction is impossible (quote 7)

What the State then refuses

Despite these acknowledgments, the state refuses three things:

  1. Actively inform citizens about their presence in the 14 nationality spreadsheets (quote Written Consultation lines 1155-1157)
  2. Establish a compensation fund comparable to the toeslagenaffaire (quote Written Consultation lines 1114-1115: “The cabinet sees no need to consider a compensation fund for this”)
  3. Hold the responsible officials and officeholders personally accountable for their share in the structure that remained in place for sixteen months after the first warning

The Wbp violation: sixteen months before the GDPR

The CDO Risk document presented to the concern directors in January 2017 signalled that RAM had possibly long been non-compliant with the Personal Data Protection Act (Wbp). That is sixteen months before the GDPR entered into force. In those sixteen months, no decision was made to switch off RAM. Only the hard deadline of 25 May 2018 forced the Tax and Customs Administration into action.

This means that the Wbp violation — and thus the unlawful processing of personal data of millions of citizens and entrepreneurs — lasted at least from January 2017 to May 2018, and the GDPR violation until January 2021 (the nationality memo). That is a total of four years of known unlawful processing by the Tax and Customs Administration, with the knowledge of the concern directors.


The migration timeline: 17 months of chaos

Annex 1C contains a confidential timeline of the RAM migration, drawn up on 29 January 2021 in response to the nationality discovery.

DateEvent
October 2017GEB RAM delivered, insight into remaining measures to be introduced
22-29 November and 6 December 2017Power meetings: search for a solution path from RAM migration to a new intelligence facility
December 2017Solution path including cost picture
December 2017 - April 2018Administrative alignment on solution path
6 April 2018Chain table GKT states that “RAM must be out by 25/5, and that there can be no question of a date of 1/7/18 (from IT)”
12 April 2018Memo in MTBD: 25/5 is hard date
17 April 2018Kick-off emergency provision with three tracks
24 May 2018Cleaning order: “Nationality 1 and 2 are marked for deletion”
25 May 2018RAM switched off, one day before GDPR
12 to 15 June 2018Cleaning carried out and confirmed
11 July 2018Switching off the apandu22 customer group RAM
7 December 2018WMIK within DF&A negative about track 2 IVT
7 February 2019Status of phase-out at chain table GKT
4 April 2019End of project RAM
20 April 2019Last steering group emergency provision RAM
8 January 2021Discovery of nationality still present in track 2 IVT

The chain table GKT stated on 6 April 2018 that RAM had to be out by 25 May. There was no room for the extension to 1 July 2018 proposed by IT. This implies that there was a tension within the Tax and Customs Administration between IT (which wanted time) and the business (which set 25 May as a hard limit). The GDPR deadline forced a decision that should have been made internally sixteen months earlier.


Three replacement tracks: all prematurely terminated

After switching off RAM on 25 May 2018, three replacement tracks were set up. The Written Consultation of 26 May 2025 states that these tracks were supposed to respect the GDPR, but that “these tracks insufficiently met preconditions for recording and documentation, also in relation to the GDPR.”

TrackContentResult
1GDPR-compliant cleaned copy of the RAM database; non-GDPR fields removedSame objections remained; switched off May 2019
2Current data from a number of transaction systems; idea: this aligns with GDPRInsufficient recording and documentation; prematurely terminated
3Fiscal core data for tactical and strategic analysesLimited to branches; prematurely terminated

The evidence problem

  • For tracks 1 and 3, descriptions of the datasets are still available, but not the queries executed on those datasets
  • For track 2, neither the dataset descriptions nor the queries are available anymore
  • The logging of RAM for the period after 2012 was not made available, simply because “no log files are available”

The state therefore cannot reconstruct which data was actually processed, by whom, and for what purpose. That is precisely the evidence problem that stands in the way of victims of the toeslagenaffaire.


All connected source systems: the data archipelago

RDM and RAM were not stand-alone systems. They functioned as a node in an extensive archipel of source systems, analysis environments, successor systems and chain partners. Below is the complete overview of what was connected to what, based on the text exports of Annex 1A, 1B and 1C and the KPMG report.

The 72 source systems of RAM

An internal memo of 20 November 2017 states that “RAM unlocks data from 72 sources and enables users to query and analyse it. This functionality is unique within the Tax and Customs Administration.” The KPMG report documents 69 source systems and 250 data tables in RAM. The most important source systems are:

CodeFull nameContent
BVRRelations Management (core system)Main customer relations file
ABSAssessment Tax SystemIH/VPB assessments
TSLToeslagen (Allowances)Allowance and child-related budget data
HSBWithholding Tax (vehicle data)Vehicle data
OBValue Added Tax (VAT / Omzetbelasting)VAT returns, defaults, supplementary assessments
IHIncome Tax / Income LevyIH returns, additional assessments
VpbCorporate Tax (Vennootschapsbelasting)VPB returns, corrections
LHWage Tax (Loonheffing)LH returns, wage sums, employees
KvKChamber of CommerceRegistrations, branch codes, shareholders
FSVFraud Signalling Facility~180,000 citizens as a fraud signal
GOSGeneric Support ServicesSupport services
FLGFinancial Wage DataWage and financial data
HLPWage Tax and Employee/National Insurance LeviesWage tax + insurance premiums
GEFISIntegrated Fraud Information SystemCriminal records + fiscal fines (FIOD)
VIESVAT Information Exchange SystemEU-wide VAT exchange
INLLocal Recovery (new GOA)Outstanding amounts, local recovery
IKBIntegral Customer ImageIntegrated customer view
RAMRisk Analysis ModelThe main system itself
RDMRegio Data ModelThe MKB selection layer on top of RAM
LOA’sLocally Developed ApplicationsDozens of informal tools

RAM also linked to: bank data, vehicle data (RDW), real estate files, notarial deeds, Fiscal Allowance and bank data, IP addresses, Becon files (tax consultants), emigration data, GBA/CBR data, AKI notifications (Labour Chain Inspection), PIT notifications, ERA data.

The analysis environments and their successors

SystemStatusLinkSpecial feature
RAM (Risk Analysis Model)Switched off 25-5-201872 sources250 data tables; 20 years in use
RDM (Regio Data Model)Phased outDrew from RAMMKB-specific presentation layer
Track 1 (GDPR-compliant copy)Switched off May 2019RAM copySame objections remained
Track 2 (IVT on TD/SASgrid)Prematurely terminatedTransaction systemsDatasets AND queries destroyed
Track 3 (structural)Prematurely terminatedFiscal core dataLimited to branches
Emergency provisionIn use until July 2018RAM extract60 employees under MKB leadership
IVT track 2Closed 1-1-2021RAM extract uncleanedNationality 2012-2016 present

The seven RAM-like successor systems (2025)

The KPMG report of February 2025 identified seven systems that were still in production in 2025 and showed “comparable risks” to RAM. The Autoriteit Persoonsgegevens demanded immediate phase-out of the first two in July 2025.

SystemFull nameRisk levelAP judgment
KTACustomer Supervision ApplicationCRITICALPhase out immediately (18,000 users, all personal data without authorisation roles)
InformatiesjabloonExcel export toolCRITICALPhase out immediately (personal data outside security)
IHPInformation Hub PlatformHIGHMitigate (~2,000 users, no logging)
IFLInformation for CareerHIGHMitigate (Excel macros, no transition plan)
SMOBSelection Module VATMODERATEMitigate (2,314 users, passive monitoring)
GruffGraph databaseMODERATEMitigate (no solution architecture)
PRISMACustoms risk modelMODERATEMitigate (predefined rules)

The Tax and Customs Administration ignored the AP call. As of May 2026, the systems are still running.

The hidden storage environments

In addition to the active production systems, the Tax and Customs Administration hosted multiple shielded storage environments that only came to light in 2025-2026.

EnvironmentContentStatus upon discovery
Data vault64 million files, of which 24.3 million substantiveCreated May 2019; rediscovered July 2025; House informed April 2026
Toeslagen mailboxes1,004 copies of mailboxes of former DTOSafeguarded May 2020; never searched
Employee Q-drivesPersonal work environmentsNot yet found (2026)
Connect People environmentsCollaboration platformNot yet found (2026)
FSV data vaultShielded FSV environmentTerminology also used for FSV archive
Excel files on network drives2 million Excel filesWithout archive management; not searched

Ten chain partners that received RAM data

The RDM/RAM data was not only used within the Tax and Customs Administration. Via covenants, data was shared with ten external collaborative partnerships.

#PartnershipSectorParticipants
1National Approach to Address Quality (LAA)Address controlMunicipalities
2Financial Expertise Centre (FEC)Financial/fiscalFIOD, police, Public Prosecution Service, AFM, DNB, FIU
3Regional Information and Expertise Centres (RIECs)SubversionPolice, Public Prosecution Service, municipalities, UWV, SVB
4National Information and Expertise Centre (LIEC)National subversionIdem + SZW
5National Steering Group Intervention Teams (LSI)InterventionSZW, UWV, SVB, police, Public Prosecution Service
6Infobox Criminal & Unexplained Assets (iCOV)AssetsJustice
7BIBOB CollaborationPermitsJustice
8Citydeal Visibility on SubversionLocalMunicipalities
9Counter-terrorism CT infoboxTerrorismJustice and Security
10Healthcare Fraud NodeHealthcareVWS (Health), health insurers

The total number of connected systems

Added up, the RDM/RAM data archipelago comprised:

CategoryNumber
RAM source systems72
RAM data tables250
Locally Developed Applications (LOAs)20-25 systems across 15 organisational units
Temporary analysis environments3 tracks + emergency provision + IVT track 2
RAM-like successor systems7
Hidden storage environments6+ (data vault, mailboxes, Q-drives, Connect People, FSV vault, Excel)
External chain partners10
RAM selections in 20 years~500,000
Citizens/enterprises in data11 million + 1.9 million

The state profiled virtually every Dutch citizen for twenty years through a system that “structurally violated statutory requirements”, shared the results with ten chain partners, and stores the evidence in six hidden storage environments that only came to light in 2025-2026. The state still refuses to systematically search these environments and actively inform citizens.


The AP report of 9 July 2025: systematic violation confirmed

On 9 July 2025, the Autoriteit Persoonsgegevens published its report on RAM and the six comparable systems. The report is signed by AP board member Katja Mur and addressed to State Secretary Van Oostenbruggen. The AP bases itself on the KPMG report and does not conduct additional independent investigation into RAM itself — “because much information about RAM is no longer available.

Four main conclusions about RAM

#ConclusionWhat the AP acknowledges
1RAM unlawfully processed personal data, including special categories and personal data concerning criminal convictions and offencesViolation GDPR art. 9 (special categories)
2A distinction was made between persons, including on nationality, and to date no objective justifications are known. RAM was therefore used to carry out discriminatory processingViolation art. 1 Constitution, art. 14 ECHR, art. 9 GDPR
3No appropriate technical and organisational measures were taken for the security of personal data in RAM. Data could be freely exported from RAM and these extracts were also not securedViolation GDPR art. 32
4The Tax and Customs Administration withdrew from supervision for years by not reporting the relevant processing of personal data to the DPO and the Personal Data Protection Authority (Cbp). Those reports were legally requiredViolation GDPR art. 36-37

The key passage

“The Tax and Customs Administration has with the application RAM for a long time systematically violated the regulations regarding the protection of personal data. The AP concludes that there are serious violations. The Tax and Customs Administration did not take the WRP and the Wbp seriously, and everything indicates that the goal — exercising supervision on taxpayers — sanctified all means. Fundamental rights of citizens were seriously violated. What particularly disturbs the AP is that RAM made it possible, at the whim of the tax inspector and without controls on this, to make all kinds of risk selections in which the risk of discriminatory processing becoming real.” — Autoriteit Persoonsgegevens, letter 9 July 2025, Our reference 2025-002145, signed by Katja Mur

The sanction that did not happen

“These are violations so serious that a firm sanction would not be out of place. However, because the violations were committed more than seven years ago, the AP does not proceed to do so.”

The seven-year limitation period saves the State from a formal fine. The FSV fine from July 2020 amounted to €2.75 million — a fraction of a working day’s budget for a government organisation. The AP here chooses to let the public condemnation suffice, in the hope that the Tax and Customs Administration will improve internally. For individual victims, this means that there is no direct administrative enforcement action.

The six “systems comparable to RAM”

KPMG identified six systems that were still in use in 2025 and showed comparable risks. The AP subjected these systems to an expedited data protection inspection.

SystemOwnerAP judgmentProblem
InformatiesjabloonTax and Customs AdministrationPhase out immediatelyExcel export of personal data outside security; sexual orientation derivable
KTA (Customer Supervision Application)Tax and Customs AdministrationPhase out immediately18,000 employees have access to all personal data without authorisation roles; sexual orientation derivable
GruffTax and Customs AdministrationMitigateNo solution architecture
IHP (Information Hub Platform)Tax and Customs AdministrationMitigateQueries not logged
SMOB (Selection Module VAT)Tax and Customs AdministrationMitigatePassive monitoring
PRISMACustomsMitigateRisk selection system with predefined rules

The AP requests the Tax and Customs Administration to submit a solid plan for the phase-out of Informatiesjabloon and KTA no later than 15 October 2025. The other four systems must be improved. The AP considered immediately shutting down the two systems, but ruled that “this would have too drastic consequences for the performance of the public task of the Tax and Customs Administration.”

AP perspective on the compensation process

“In the 20 years that RAM was used, an estimated 500,000 selections were made. For only 1,170 of these selections was a RAM extract found in the Tax and Customs Administration archives (this is less than 0.25%), which forms the basis for the compensation action. Although the total number of individuals disadvantaged by RAM cannot be established, the AP considers it plausible that, given the small percentage of RAM extracts that can be investigated, only a small percentage of the potentially disadvantaged citizens can actually qualify for a form of compensation.”

The AP has been monitoring the Tax and Customs Administration’s compensation process since April 2025. For the file, this is an important recognition: the 1,170 extracts investigated are less than 0.25% of the total. For the remaining 99.75% of the 500,000 selections, no compensation option remains.


The HVB programme: 979 applications scanned

The report “Reporting Sweep Action applications nationality, medical and criminal data (Prio 1a)” of 17 February 2022 — released via the KPMG submission — reveals a follow-up investigation under the HVB programme (Restore, Improve and Safeguard / Herstellen, Verbeteren en Borgen) that has received little broad publicity.

Background

“The Tax and Customs Administration recorded (risk) signals in an application for supervision: the Fraud Signalling System Facility (FSV). It turned out that the FSV did not fully comply with the GDPR, BIO and the Archives Act 1995. The application was therefore taken offline on 27 February 2020.”

Following the FSV affair and a commitment by the then State Secretary on 15 November 2019 to the CAF 11 parents, the Tax and Customs Administration started a scan of all IT-managed applications in December 2020. The question: which applications contained nationality, medical or criminal data without a legal basis?

Results of 979 applications

CategoryNumberStatus
Total identified applications97910 double-counted, 969 unique
Applications without N, M or S data822Clean
Applications with N, M or S (or uncertain)147Further investigated
With sufficient explicit legal basis57Approved
Without sufficient legal basis4FSV, INL, DRI, DRA
Legal basis still unclear86Follow-up actions started
SystemFull name2022 Status
FSVFraud Signalling System FacilityAlready addressed; taken offline 27-2-2020
INLLocal RecoveryFollow-up action required
DRICustoms Query InformationFollow-up action required
DRACustoms Registration and HandlingMitigating measures taken

In addition to the FSV, there are therefore three other systems at the Tax and Customs Administration or Customs that contain nationality, medical or criminal data without explicit legal basis. This finding is separate from the 14 nationality spreadsheets that emerged in the KPMG report.

RDM in the list of 979

RDM is listed as number 952 in validation population C of the HVB report (228 applications), coded with “1” for the occurrence of nationality, medical or criminal data. This confirms that RDM was explicitly recognised as an application that contained special personal data. The HVB report was published in 2022, three years before the KPMG report of February 2025. The Tax and Customs Administration therefore already knew in 2022 that RDM contained special personal data, but did not proactively communicate this to the House.

The broader HVB programmes

The prio 1a report is only one of three parallel projects:

ProjectScopeReport status
Prio 1a — Applications979 applicationsFinal report 17 February 2022
Prio 1b — Lists193 listsReport date unknown
Prio 1c — Databases/disseminationsDissemination databasesReport date unknown

The total population of HVB is therefore considerably broader than just the 979 applications. Whether the prio 1b and 1c reports have ever been made public has not been established.

The Assessment Committee

The HVB steering group set up an independent Assessment Committee in April 2021, composed of employees from:

  • Corporate Service Professional Technique (CD VT) — 2 people
  • Concern Directorate Execution and Enforcement Policy (Cd UHB) — 2 people
  • Concern Directorate Information Provisioning & Data Management (Cd IV&D) — 1 person
  • Concern Directorate Fiscal and Legal Affairs (Cd FJZ) — 1 person

The committee divided the applications into four categories and tested the legal basis with the responsible directorates on three of them. The Assessment Committee’s report is included as an annex to the final report.


Consequences for the rule of law

The combination of RDM, RAM and the migration misery touches on a number of fundamental rights and legal norms.

NormViolation
Art. 1 Constitution (equal treatment)14 spreadsheets selected on 1st/2nd nationality; AP: “no objective justifications known”
Art. 8 ECHR (private life)20+ years of uncontrolled data collection on 1.9 million MKB entities
Art. 14 ECHR (prohibition of discrimination)Systematic selection on nationality; 35 spreadsheets on postcode
Art. 6 ECHR (fair trial)No access, no objection, no defence against profiling
Art. 1 P1 ECHR (property protection)MKB entrepreneurs disadvantaged by profiling-based assessments
GDPR / WbpRDM/RAM never registered; AP: “systematically violated”; nationality left behind after cleaning from 2018 to 2021
Open Government Act (Woo)House only informed in 2022; data vault concealed for seven years
Archives Act~9,000 files destroyed under GDPR pretext; RDM archive incomplete

Causes of the failure

The Written Consultation identifies a number of structural causes:

  • Decentralised assignment of authority (1998-2010): decision-making authority over RAM was decentralised while the instrument was meanwhile used nationally
  • Supervisory interest prevailed: within the Tax and Customs Administration, the supervisory interest outweighed compliance with legal requirements
  • No independent review: RDM construction lay with MKB intelligence staff themselves, not with IT or an independent regulator
  • Culture of silence: the CDO Risk document from January 2017 led to no action; the AP was only informed in 2025
  • Insufficient migration: three tracks failed, the national identity of the data was not safeguarded

Why this matters

The Regio Data Model was not the only profiling system of the Tax and Customs Administration. Nor the largest. But it is the system that most clearly shows how a local initiative in one region (Rivierenland, 2009) could grow into a national classification instrument for 1.9 million SME entities in six years — without anyone in that period recording what the formal product name was, without any independent review of the risk models, and without citizens or entrepreneurs ever seeing their risk colour.

The Written Consultation of 26 May 2025 contains, for the first time, a number of acknowledgments that remained unanswered in earlier parliamentary questions:

  1. The state acknowledges that RDM and RAM were used structurally in violation of statutory requirements
  2. The state acknowledges that there were fourteen spreadsheets that selected on nationality
  3. The state acknowledges that there may have been fundamental rights violations and takes responsibility for them
  4. The state acknowledges that decision-making on RDM/RAM between 1998 and 2010 was decentralised and uncontrolled
  5. The state acknowledges that logging was missing and that this resulted in deficient insight

At the same time, the state refuses to actively inform citizens about the 14 nationality spreadsheets, refuses to establish a compensation fund before the investigation is completed, and relativises the importance of the ten collaborative partnerships that received data for twenty years.

The investigation into the 14 spreadsheets with selection on nationality and the 35 spreadsheets with selection on postcode is being conducted using the methodology of the Compensation Act for Selection at the Gate, tested by the Auditdienst Rijk. The result is expected in September 2025. Until then, citizens remain ignorant of their status in these spreadsheets.

The parallels with the toeslagenaffaire are striking. In both cases, there was risk-driven profiling of a broad population, based on hard system signals, without individual citizens being able to defend themselves. In both cases, the system continued to run for years despite internal signals. In both cases, the state refuses active recovery.

The difference is that RDM has at least been described in detail in an own product document of 3 March 2015, whereas the operation of the FSV and the second nationality selection at Toeslagen only came to light via PwC and KPMG. This offers a unique opportunity to reconstruct the system and to hold the responsible officials accountable for their responsibility. The wait is for the AP report and the Auditdienst Rijk’s judgment in September 2025.


References

Official documents

Annexes KPMG submission

  • Annex 1A KPMG submission (1,637 pages), contains: memo 11 April 2018 with 2017 RAM usage figures, second-hand car trade project report 1 June 2015 with working name Risicomodel Rivierenland, confidential nationality memo 2 February 2021
  • Annex 1B KPMG submission (910 pages), contains: original RDM documentation 3 March 2015, operational inventory tables with RisicoDataModel as functional working name
  • Annex 1C KPMG submission (628 pages), contains: ODW-RAM-FleXviewer explanation with “06b Region by nationality” template, confidential RAM migration timeline 29 January 2021

OpenBrief investigation reports

  • Equal Treatment Act (Wgb)
  • General Data Protection Regulation (GDPR), Article 9 (special categories of personal data) and Article 22 (profiling)
  • Compensation Act for Selection at the Gate (Wet compensatie wegens selectie aan de poort)
  • Personal Data Protection Act (Wbp, predecessor of GDPR)
  • Constitution Article 1 (equal treatment)
  • ECHR Article 8 (private life), 14 (prohibition of discrimination), 6 (fair trial), 1 P1 (property protection)

Methodological notes

  • The text exports of Annex 1A (108,830 lines), Annex 1B (58,677 lines), Annex 1C (52,904 lines) and KPMG RAM report (13,166 lines) have been fully searched for the terms RDM, Regio Data Model, RisicoDataModel, Risicomodel Rivierenland and Risicodatamodel Rivierenland
  • All quotes in this investigation can be traced line-by-line to the text exports
  • The interpretation of the four names is based on distributional analysis: 26 of 29 mentions in Annex 1B use Regio, 3 use Risico; in Annex 1A, Risicomodel Rivierenland and Risicodatamodel Rivierenland each appear once
  • The conclusion that RDM was a data layer on top of RAM is derived from section 6.6.10 of the KPMG report and is supported by the own RDM description from 2015 in which RAM is mentioned as the source
  • The investigation methodology for the 14 nationality spreadsheets is the methodology of the Compensation Act for Selection at the Gate; the result is expected in September 2025

Sources

  1. KPMG Report investigation Risk Analysis Model (RAM), 25 February 2025 (165 pages), section 6.6.10 Regio Data Model (RDM)
  2. Ministry of Finance, 'The Regio Data Model — A description of the history to date', 3 March 2015 (own product document)
  3. Annex 1A KPMG submission (1,637 pages), memo 11 April 2018 with 2017 RAM usage figures; second-hand car trade project report 1 June 2015; confidential nationality memo 2 February 2021
  4. Annex 1B KPMG submission (910 pages), including original RDM documentation 3 March 2015
  5. Annex 1C KPMG submission (628 pages), confidential RAM migration timeline 29 January 2021; ODW-RAM-FleXviewer explanation
  6. Decision note written consultation RAM, 7 May 2025, Ministry of Finance (note number 2025-0000123285)
  7. Written consultation on the Risk Analysis Model, 26 May 2025, State Secretary T. van Oostenbruggen (Our reference 2025-0000101261)
  8. Open.overheid.nl, document 4d9352c5-75dd-424a-8dbb-5674b719b196
  9. Government.nl, House letter policy response external investigation RAM, 6 March 2025
  10. OpenBrief, 'RAM never disappeared: the state profiles on', 27 May 2026
  11. OpenBrief, 'RAM and MKB Profiling: The Tip of the Iceberg', 14 May 2026
John van der Velden

John van der Velden

Independent Researcher · Open Brief Network

Independent researcher focused on institutional systems, accountability, and administrative processes. Background in network architecture, infrastructure integrity, and process optimisation.

Based in Croatia · Investigative Archive · Systems & Accountability
Full profile →

Case Timeline

High importance Medium Low
2009-01-01
system_operation RDM originated in the Rivierenland region; Intelligence working group established RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2011-01-01
policy MLTP 2011-2015 as guideline: return/payment behaviour, accuracy, unknown entrepreneur RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2013-03-03
intern Internal MKB document: 'The Regio Data Model — A description of the history to date' RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2015-03-03
intern Official title 'Regio Data Model' established in Ministry of Finance product document RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2015-06-01
system_operation Second-hand car trade project uses 'Risicomodel Rivierenland' (RDM) for 300 selections from 26,000 entities RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2017-01-01
internal_report CDO Risk document for concern directors: RAM possibly long non-compliant with Wbp RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2018-04-11
intern DT BD memo: MKB 89% of RAM usage; 44% of MKB book investigations via RAM RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2018-05-24
policy_change Cleaning order: 'Nationality 1 and 2 are marked for deletion' RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2018-05-25
system_change RAM switched off, one day before GDPR entry into force RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2018-06-15
intern Cleaned RAM database in use for 10 employees; cleaning incompletely executed RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2021-01-08
internal_report Discovery: uncleaned RAM extract with nationality present in track 2 IVT RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2021-01-14
internal_report Factual observation: 1st and 2nd nationality in 23 files across 2012-2016 RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2021-02-02
internal_report Confidential memo: 2 years 8 months of structural GDPR violation documented RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2025-02-25
external_report KPMG RAM report (165 pages); section 6.6.10 explicitly names RDM RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2025-05-07
policy Decision note written consultation RAM; 14 nationality spreadsheets + 35 postcode spreadsheets RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2025-05-26
political Written consultation House: State Secretary regrets RAM; acknowledges responsibility for fundamental rights violations RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
2025-09-01
external_report Expected: analysis of 14 nationality spreadsheets + 35 postcode spreadsheets by Auditdienst Rijk RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division