
RDM: the Regio Data Model on top of RAM at the Tax and Customs Administration's MKB division
The Regio Data Model (RDM) was the MKB-specific risk classification layer of the Tax and Customs Administration, built on top of the Risk Analysis Model (RAM), originating in 2009 in the Rivierenland region. The system carried four different names with the same abbreviation and classified 1.9 million MKB entities by compliance colours. RDM drew its information from RAM and fed the National Customer Image. The House letter of 26 May 2025 confirms that RAM was used for years structurally in violation of statutory requirements and that 14 spreadsheets selected on nationality.
Summary
The Regio Data Model (RDM) was the Tax and Customs Administration’s risk model for SMEs, built on top of the broader Risk Analysis Model (RAM). It began in 2009 in the former Rivierenland region and grew into a national system that assigned compliance colours (White, Green, Yellow, Orange, Red) and turnover benchmarks in eight quadrants to 1.9 million SME entities. The same system had four different names, all abbreviated RDM. The Written Consultation of 26 May 2025 states that the underlying RAM infrastructure was used for years “structurally in violation of statutory requirements in the areas of data protection, security and archiving.”
RDM pulled its data from RAM and fed the National Customer Image (Landelijk Klantbeeld), with deliveries to at least ten collaborative partnerships, including RIEC, LIEC, LSI, iCOV and the Counter-terrorism information box. The House letter of 6 March 2025 identified 14 spreadsheets with selection on nationality and 35 spreadsheets with selection on postcode, out of 1,170 RAM extracts found. A confidential memo of 2 February 2021 reports that nationality data of SME entrepreneurs remained uncleaned in a replacement analysis environment from May 2018 to January 2021 — a structural GDPR violation of 2 years and 8 months.
The system that carried four names
The sources show the same instrument under four different names, all abbreviated RDM. This is not sloppy editing. It reflects an instrument that grew informally for twenty years without a formal product name and without a central owner.
| # | Name | Source | Frequency |
|---|---|---|---|
| 1 | Regio Data Model | Own title page 3 March 2015; KPMG report section 6.6.10; Government.nl; Written Consultation 26-5-2025 | Official |
| 2 | RisicoDataModel | Internal operational inventory table Annex 1B | 3 of 29 mentions |
| 3 | Risicomodel Rivierenland | Project report second-hand car trade, Annex 1A | Working name |
| 4 | Risicodatamodel Rivierenland | Project report second-hand car trade, Annex 1A | Working name |
Names 3 and 4 combine the words “Risico” and “Rivierenland”. This is presumably the original working name from 2009 when the instrument was built locally in the Rivierenland region by an Intelligence working group. In the following years the name generalised to “Regio Data Model”, while “Risico…” remained as a functional working name in certain internal operational tables, probably to align with the broader RAT family (Risk Analysis Tool StiVer, RAT ANBI, RAT Follow the Money, RAT Verhuurdersheffing).
The formal name
The KPMG report of 25 February 2025 consistently refers in section 6.6.10 to “Regio Data Model (RDM)” and quotes a description provided by organisational unit MKB. The Government publication of 6 March 2025 and the House of Representatives documents use the same name. In this investigation we use only the formal name.
The operating mechanism
| Element | Content |
|---|---|
| Origin | 2009, Rivierenland region, Intelligence working group |
| Guideline | MLTP 2011-2015 (Long-Term Multi-Year Plan Tax and Customs Administration) |
| Target group | MKB enterprises (1.9 million entities), including ZZP (self-employed), STARTERS, tax consultants |
| Source files | IKB, RAM, BI files; with ACL (EDP_Audit) flat files on Entity Number and Tax Number |
| Architecture | Presentation and selection layer on top of RAM (RDM drew information from RAM, later Track 2/Track 3) |
| Outputs | Compliance colour per BSN/entity per year, quadrant benchmark per sector, score for National Customer Image |
Three categories of disruptions
RDM classified behaviour along three axes, derived from the spearheads of the MLTP 2011-2015.
| Category | Disruptions |
|---|---|
| Filing behaviour | VAT filing defaults; ex officio VPB; ex officio IH; wage tax filing defaults; ATA project contact moments |
| Payment behaviour | VAT payment defaults; wage tax payment defaults; INL balance positions 2010-2015; current outstanding amount; irrecoverable losses |
| Accuracy/Completeness | audit corrections; IH additional assessments; VPB additional assessments; VAT supplementary assessments; wage tax supplementary assessments; system assessments VAT |
The makers of RDM themselves set a methodological limit: “we chose not to simply link all kinds of files from ‘handy Harries et al’.” There was therefore awareness of the risk of uncontrolled data combination. That awareness did not lead to GDPR-compliant design.
Five compliance colours
Each BSN, entity or tax number received a colour per year that determined whether it qualified for the so-called integrated approach: audits, system assessments, visits and recovery.
| Colour | Meaning |
|---|---|
| White | Not visited in the past 6 years and no disruptions |
| Green | Visited in the past 6 years, but no disruptions |
| Yellow | One disruption in one of the three categories |
| Orange | Two disruptions in two categories |
| Red | All three categories affected |
The colour was cumulative: one filing default plus one payment default in the same year automatically produced at least Orange, regardless of the factual context. The description in the original RDM document itself warns that VPB and IH figures are “at the very least debatable” because those taxes have only one filing moment per year, often with deferral arrangements, making the data structurally at least one year out of date. Nevertheless, that data was used for risk scores with direct enforcement consequences.
Eight quadrants
In addition to the colour, per Region → Theme/attention area → Branch code the total declared VAT turnover could be divided by the number of active entrepreneurs, resulting in a turnover benchmark in eight bands.
| Quadrant | Turnover vs. group average |
|---|---|
| A | greater than 150% |
| B | 125 to 150% |
| C | 100 to 125% |
| D | 75 to 100% |
| E | 50 to 75% |
| F | 25 to 50% |
| G | less than 25% |
| (none) | no VAT activity |
An entrepreneur in quadrant A in combination with compliance colour Red automatically came into view for integrated approach. The system thus made group comparisons with direct enforcement consequences, without there being an individually identifiable irregularity.
Bankruptcy prediction without validation
The RDM document describes a predictive function based on historical bankruptcies:
“The latter [W=probable] is based on a query built on the behaviour over the years 2010/2012 of entities that have gone bankrupt; this query is run over the mass without the bankrupt entities and returns those entities that are about to (probably) go bankrupt.”
This is an unsupervised discriminant analysis on two years of historical bankruptcies, run over the living MKB mass. The document contains no specification of sensitivity, specificity or false-positive rate. No human review-before-check is described. Companies that received the “probably bankrupt” label ran the risk of early recovery, assessments and credit restrictions — a self-fulfilling prophecy without published validation.
The relationship with RAM
The KPMG report establishes in section 6.6.10 an architectural fact that is not explicitly stated in the own RDM document from 2015:
“DF&A indicated that RDM drew its information from RAM, and later from Track 2/Track 3.”
RDM was therefore not a stand-alone system. It was a presentation and selection layer built specifically for the MKB segment, on top of the underlying RAM infrastructure.
Two views on the same system
| Source | Statement on the deployment of RDM |
|---|---|
| Own RDM document 3 March 2015 | Broad deployment: integrated approach, compliance colours, bankruptcy prediction, score for National Customer Image, ranking of tax consultants |
| KPMG RAM report section 6.6.10, 25-2-2025 | “RDM was only used for the selection of book investigations and the logistical process of assigning these book investigations to the offices.” |
The discrepancy may stem from a difference in time: the 2015 RDM report describes ambition and wishes; KPMG looks back in 2025 at actual deployment between 2013 and 2024. There may have been a loss of function after the migration to AWS 6/7 in 2018-2019, in which RDM degraded from a broad customer image instrument to a logistical selection tool. For file use, this means that statements about RDM impact must always be checked against the KPMG report and must not assume the broad RDM report from 2015.
Who built and managed RDM
A programme scoping document states:
“The capacity deployment of the business consists, in addition to the provision of a programme manager, of the deployment of the required project leaders/product owners and the deployment of intelligence staff (RAM/RDM builders).”
The construction and management of RDM was the responsibility of intelligence staff of the MKB segment. Not an independent regulator. Not an IT organisation with formal quality control. The term “RAM/RDM builders” confirms the close technical interweaving of both systems and the absence of a separation between developer, manager and user.
Victims and scale: 11 million citizens, 1.9 million entrepreneurs
The scale of profiling via RDM and the underlying RAM is difficult to grasp. The State Secretary states in the Written Consultation that “virtually every taxpayer, citizens and businesses, was findable in RAM.” Below the documented numbers.
Victims by category
| Category | Number | Source |
|---|---|---|
| Citizens in Tax Administration data | 11 million | WRR Working Paper 021, 2016 |
| MKB entities in RDM | 1.9 million | RDM document 3 March 2015; MKB Intelligence-base |
| Enterprises in RAM data | 1.5 million | WRR Working Paper 021, 2016 |
| RAM entities (total) | 2.2 million | KPMG report February 2025 |
| Vehicles in RAM | 10.5 million | KPMG report part 1 |
| Allowance families affected | ~26,000 | Parliamentary documents |
| FSV registrations | ~180,000 citizens | PwC; Donner Committee |
| RAM selections in 20 years | ~500,000 | AP letter July 2025; KPMG |
| RAM extracts recovered | 1,170 (0.25%) | KPMG; AP |
| Spreadsheets containing nationality | 369 of 1,170 | KPMG |
| Spreadsheets with selection on nationality | 14 | Written Consultation 26-5-2025 |
| Spreadsheets with selection on postcode | 35 | Written Consultation 26-5-2025 |
| Excel files distributed via USB/email/CD | 2,662 | KPMG |
| Book investigations MKB per year via RAM | 9,683 (44% of 22,000) | Memo 11-4-2018 |
| Nationality files in track 2 IVT | 23 (2012-2016) | Nationality memo 2-2-2021 |
| Files containing bank data | 7 | Nationality memo 2-2-2021 |
| Files containing WOZ values | 9 | Nationality memo 2-2-2021 |
| Data vault total files | 64 million | House letter 2026D24511 |
| Data vault substantive files | 24.3 million | House letter 2026D24511 |
| Excel files in data vault | ~2 million | House letter 2026D24511 |
| Files in unopened ZIPs | ~87,000 relevant | Technical briefing 26-5-2026 |
| Unique file types in data vault | 31,000 | Technical briefing 26-5-2026 |
| Mailboxes of Toeslagen employees | 1,004 | House letter 2026D24511 |
| Period of GDPR violation on nationality | 2 years 8 months | Nationality memo 2-2-2021 |
RAM usage 2017 — who queried what
The memo of 11 April 2018 from the Chain Generic Facilities Supervision and Office to the Management Team Tax Administration contains the first documented RAM usage figures for 2017. MKB completely dominated usage.
| Segment | Customer Image | % | Spec-data | Total | % |
|---|---|---|---|---|---|
| MKB | 4,627 | 95% | 11,071 | 19,091 | 89% |
| Directie Belastingen | 123 | 3% | 1,100 | 1,318 | 6% |
| Belastingdienst/Switch | 0 | 0% | 68 | 68 | < 1% |
| FIOD | 32 | 1% | 102 | 136 | 1% |
| GO | 27 | 1% | 167 | 197 | 1% |
| Douane | 47 | 1% | 83 | 137 | 1% |
| Belastingdienst Toeslagen | 0 | 0% | 1 | 1 | < 1% |
| PDB | 15 | 0% | 185 | 211 | 1% |
| Other | 21 | 0% | 213 | 234 | 1% |
| TOTAL | 4,891 | 100% | 12,988 | 21,394 | 100% |
The MKB segment was responsible for 44% of 22,000 book investigations in 2018 (9,683 investigations) based on RAM selections. RAM was thus the primary instrument for MKB enforcement. The Tax and Customs Administration’s Toeslagen division had only one record in 2017. That does not mean Toeslagen did not receive RDM data — that happened via the chain collaboration partnerships — but direct front-end access was negligible.
The invisible victims
The figures tell only part of the story. Who was specifically disadvantaged by RDM profiling can no longer be reconstructed. The state itself states:
“Given the time that has passed, it is no longer possible to establish which data from RAM was shared with which collaborative partnerships.” — Decision note 7-5-2025
The 500,000 selections in 20 years of RAM are the upper limit of the number of individuals who may have been directly affected. Less than 0.25% of those selections have been recovered from archives. The remaining 99.75% may be in the 2 million Excel files in the data vault, or has been destroyed. The 14 spreadsheets with selection on nationality contain an unknown number of citizens. Citizens who appear in these spreadsheets have not been informed to date.
Project Lekkerbek: fish stalls as a risk group
In the Decision Note of 7 May 2025 the State Secretary refers to “the project on fish stalls.” The Written Consultation of 26 May 2025 confirms in paragraph 6 that this concerned Project Lekkerbek, a local initiative aimed at mobile fish stalls.
What data was collected
The project explicitly used RAM to map the regional population of mobile fish stalls and then added:
- name, business address, legal form (EMZ, VOF, BV)
- tax number (BSN, RSIN, VAT number)
- profit return IH/VPB (turnover, purchase value, costs, investments)
- wage data (wage sum, number of employees)
- ratio figures such as wage/turnover and gross profit percentage
- filing and payment behaviour
On this basis, information meetings were organised, question letters sent, company visits and book investigations carried out. The State Secretary concluded: “As far as can be ascertained, this project was carried out with safeguards, and given the data used, I see no reason to suspect (in)direct discrimination.”
Other projects without further information
DENK MPs also asked about projects mentioned in the KPMG report on page 130: Security companies, Cleaning sector and Amsterdam Taxi companies. The answer reads:
“No further information has become available about the other mentioned projects. It should be borne in mind that these projects took place an estimated 10 to 15 years ago.”
The Tax and Customs Administration thus cannot reconstruct which safeguards applied to a number of projects in the 2010-2015 period. That is precisely the period in which the toeslagenaffaire took place.
Evidence of discrimination: 14 spreadsheets, 4 specific nationalities
The most explosive part of the Written Consultation of 26 May 2025 is paragraph 5. The State Secretary confirms what was already announced in the House letter of 6 March 2025.
“In my letter of 6 March 2025 I already confirmed that in 14 of the 1,170 spreadsheets found, first and/or second nationality was used as a selection criterion.” — State Secretary T. van Oostenbruggen, Written Consultation RAM, 26 May 2025
The four nationalities in the 14 spreadsheets
The AP report of 9 July 2025 (reference 2025-002145), signed by AP board member Katja Mur, specifies in footnote 3 which nationalities are involved:
“This concerns the Bulgarian, Romanian, Afghan or Albanian nationality as first and/or second nationality.” — Autoriteit Persoonsgegevens, letter to State Secretary Van Oostenbruggen, 9 July 2025
This is not an abstract selection on “foreign nationality” in general. It concerns four specific nationalities: three of them are Eastern European EU member states (Bulgaria, Romania, Albania is not EU but a candidate member state), and one is an asylum country (Afghanistan). The selection thus combines an Eastern European and an asylum seeker profile — precisely the groups that were disproportionately hard hit in the toeslagenaffaire.
| Category | Number | Selection criterion | Source |
|---|---|---|---|
| Nationality spreadsheets (House letter) | 14 | 1st and/or 2nd nationality | Written Consultation 26-5-2025 |
| Nationalities in these 14 spreadsheets | 4 | Bulgarian, Romanian, Afghan, Albanian | AP report 9-7-2025, footnote 3 |
| Postcode extracts (according to AP) | 61 | Postcode | AP report 9-7-2025 |
| Postcode spreadsheets (according to House) | 35 | Postcode (optionally + house number) | Written Consultation 26-5-2025 |
| Total RAM spreadsheets found | 1,170 | diverse | KPMG report |
| RAM selections in 20 years | ~500,000 | unknown | AP report; less than 0.25% recovered |
| Excel files with nationality | 369 of 1,170 | diverse | KPMG report |
Discrepancy 35 versus 61 postcode extracts
There is a difference between the number of postcode extracts that the House (35) and the Autoriteit Persoonsgegevens (61) mention. The AP report explicitly states: “You have now indicated that selections on postcode will also be examined, concerning 61 RAM extracts.” Possibly the state subsequently identified more extracts, or the 35 is a subset reported to the House while the AP knows the broader 61. For the file, the highest known number (61) is guiding.
Citizens not yet informed
“Since it is not clear for what purpose these spreadsheets were prepared and whether the use of these spreadsheets led to a violation of a citizen’s fundamental right, citizens who appear in this spreadsheet have (not yet) been informed.” — State Secretary T. van Oostenbruggen, Written Consultation RAM, 26 May 2025
Citizens whose nationality was selected in a spreadsheet for tax supervision do not know that this happened. The State Secretary states that investigation must first establish whether there was a violation. That investigation is conducted using the methodology of the Compensation Act for Selection at the Gate (Wet compensatie wegens selectie aan de poort) and is tested by the Auditdienst Rijk. The Autoriteit Persoonsgegevens follows the analyses.
Premature refusal of a compensation fund
In response to the question from the DENK party whether the cabinet is considering a compensation fund comparable to the toeslagenaffaire, State Secretary T. van Oostenbruggen (Finance — Taxation, Tax and Customs Administration and Customs) replied in the Written Consultation of 26 May 2025:
“If there is a demonstrated need for recovery, a proposal for coverage is also appropriate. The cabinet sees no need to consider a compensation fund for this.” — State Secretary T. van Oostenbruggen, Written Consultation RAM, 26 May 2025, Our reference 2025-0000101261
This refusal comes before the investigation into the 14 nationality spreadsheets has been completed, before the legal analysis of the postcode extracts has been completed, and before the Auditdienst Rijk or the Autoriteit Persoonsgegevens have pronounced. The refusal is premature and difficult to reconcile with the own recognition that a responsibility rests on the state in cases of fundamental rights violations.
The nationality memo of 2 February 2021
In Annex 1A of the KPMG submission there is a confidential memo of 2 February 2021 that only became public in 2025. The document describes a discovery that significantly completes the RDM/Track 2 story.
Timeline of the discovery
| Date | Event |
|---|---|
| 8 January 2021 | During ANBI work, discovered that an uncleaned RAM extract is on the track 2 IVT environment |
| 14 January 2021 | Factual finding: 1st and 2nd nationality recorded in multiple files |
| 19 January 2021 | Investigation started via query logging in Splunk; order to remove nationality |
| 21 January 2021 | Investigation completed |
| 1 February 2021 | Confirmation by all known MKB users that they did not use the uncleaned extract |
| 2 February 2021 | Memo recorded, confidential |
What was found
The scan by an MKB and a DF&A analyst produced:
- 23 unique files with nationality, distributed across 2012 (2), 2013 (7), 2014 (6), 2015 (4), 2016 (1) and 3 files with unknown year
- 7 files contained bank data
- 9 files contained WOZ values
- No logging in the track 2 IVT environment, so use cannot factually be ruled out
- No server-side export with nationality in 2019 and 2020
- Client-side export cannot be ruled out
The explanation
“When placing the relevant RAM extract on the track 2 IVT environment, a cleaning operation was carried out to ensure GDPR compliance. However, due to human error, an uncleaned extract of RAM was placed on the IVT track 2 environment.”
The cleaning was explicitly ordered on 24 May 2018, as Annex 1C documents: “Nationality 1 and 2 are marked for deletion.” The cleaning was carried out on 12 to 15 June 2018 with written confirmation. Nevertheless, on 14 January 2021, it was discovered that nationality was still present.
The period of unlawful processing
From 25 May 2018 (entry into force of GDPR) to 19 January 2021 (removal of nationality from track 2 IVT), the period of structural GDPR violation amounts to 2 years and 8 months. Every MKB entrepreneur with a first or second nationality who was included in a RAM-based or derived product during that period has a presumption of unlawful processing of special personal data within the meaning of Article 9 GDPR in conjunction with Article 1 of the Equal Treatment Act.
Ten collaborative partnerships received data
Paragraph 4 of the Written Consultation lists the collaborative partnerships that received data from RAM. This list is of particular importance for the file because several of these partnerships have participants from the social security domain.
| # | Partnership | Relevant participants | Possible spillover |
|---|---|---|---|
| 1 | National Approach to Address Quality (LAA) | Municipalities | Address control, assistance |
| 2 | Financial Expertise Centre (FEC) | FIOD, police, Public Prosecution Service, AFM, DNB, FIU | Criminal law |
| 3 | Regional Information and Expertise Centres (RIECs) | Police, Public Prosecution Service, municipalities, UWV (Employee Insurance Agency), SVB (Social Insurance Bank) | Subversion, social security |
| 4 | National Information and Expertise Centre (LIEC) | Idem + SZW (Ministry of Social Affairs) | Idem |
| 5 | National Steering Group Intervention Teams (LSI) | Idem + SZW, UWV, SVB | Idem |
| 6 | Infobox Criminal & Unexplained Assets (iCOV) | Justice | Asset seizure |
| 7 | BIBOB Collaboration | Justice | Permit refusal |
| 8 | Citydeal Visibility on Subversion | Municipalities | Local supervision |
| 9 | Counter-terrorism CT infobox | Justice and Security | Counter-terrorism |
| 10 | Healthcare Fraud Node | VWS (Health), health insurers | Health insurance |
The State Secretary relativises the importance of these data flows:
“Without RAM, largely the same data could have been provided as with RAM (with the exception of data generated with RAM).”
That relativisation is only partly valid. The data generated by RAM concerned calculated fields with totals and risk scores per tax service provider. These scores, which were found in spreadsheets by KPMG, form the vulnerable point. The State Secretary then states:
“The 20-year period in which RAM was used makes it no longer possible to establish over that period which data was shared, with what frequency, and with which collaborative partnerships. Nor can any statements be made about the extent to which the data was used outside a collaborative partnership.”
For individual victims, this means that the burden of proof is factually impossible. The state acknowledges that data has been shared with at least ten chain partners for twenty years, but cannot reconstruct what, when, with whom, and for what purpose.
Guilt acknowledged by the state
The Written Consultation of 26 May 2025 contains acknowledgments by State Secretary T. van Oostenbruggen that are new in their explicitness in the toeslagenaffaire. Where previous officials hid behind “the system”, “unforeseen” and “complex”, the State Secretary now acknowledges structural breach of the law, regret, and personal responsibility for fundamental rights violations. These quotes work in administrative or civil proceedings as facts that can no longer be denied. The burden of proof shifts to the State.
Seven acknowledgments in a row
| # | Quote (line in Written Consultation) | What is acknowledged |
|---|---|---|
| 1 | “RAM was used for years in a way that structurally violated statutory requirements in the areas of data protection, security and archiving.” (192-194, NSC — State Secretary shares this view) | Structural violation of the law |
| 2 | “I share the view of the NSC party that KPMG’s findings about RAM are serious. […] It is unacceptable that the Tax and Customs Administration used RAM and […] I regret that.” (197-201) | Unacceptability + regret |
| 3 | “If mistakes were made with RAM that led to serious consequences for citizens, such as a violation of fundamental rights, then I believe I have a responsibility for that.” (203-206) | Personal responsibility for fundamental rights violations |
| 4 | “RAM was not limited to MKB companies, however. Ultimately, virtually every taxpayer, citizens and businesses, was findable in RAM.” (175-176) | Population size: 11 million citizens + 1.5 million enterprises |
| 5 | “That there was a risk that RAM possibly had long been non-compliant with the prevailing Wbp, we found only in the aforementioned ‘CDO Risk’ document for the concern directors in January 2017.” (744-749) | Wbp violation known to concern directors 16 months before GDPR |
| 6 | “From 1998 to 2010, decision-making authority over RAM was decentrally assigned within the Tax and Customs Administration […] In addition, the supervisory interest prevailed within the Tax and Customs Administration.” (763-768) | Administrative failure acknowledged |
| 7 | “The Tax and Customs Administration acknowledges that the lack of logging and monitoring in RAM resulted in deficient insight.” (391-397) | Evidence destruction / impossibility of reconstruction acknowledged |
What the State thereby acknowledges
The seven acknowledgments together form a complete removal of the main arguments that the State made in earlier proceedings:
- Where the State previously argued that there was no question of intent or structural failure, it now acknowledges structural violation of the law (quote 1)
- Where the State previously argued that the system operated within bounds, it now acknowledges unacceptability and regrets it (quote 2)
- Where the State previously shifted responsibility to individual officials or the system, the State Secretary now takes personal responsibility for fundamental rights violations (quote 3)
- Where the State previously argued that the FSV was an isolated problem, it now acknowledges that virtually every taxpayer was in RAM (quote 4)
- Where the State previously argued that it was unaware of the problems, it now acknowledges that the concern directors were informed in January 2017 about Wbp violations (quote 5)
- Where the State previously argued that there was adequate administrative control, it now acknowledges that between 1998 and 2010 decision-making authority was decentralised and the supervisory interest prevailed over the legal requirements (quote 6)
- Where the State previously argued that the files had been delivered completely, it now acknowledges that logging was missing and reconstruction is impossible (quote 7)
What the State then refuses
Despite these acknowledgments, the state refuses three things:
- Actively inform citizens about their presence in the 14 nationality spreadsheets (quote Written Consultation lines 1155-1157)
- Establish a compensation fund comparable to the toeslagenaffaire (quote Written Consultation lines 1114-1115: “The cabinet sees no need to consider a compensation fund for this”)
- Hold the responsible officials and officeholders personally accountable for their share in the structure that remained in place for sixteen months after the first warning
The Wbp violation: sixteen months before the GDPR
The CDO Risk document presented to the concern directors in January 2017 signalled that RAM had possibly long been non-compliant with the Personal Data Protection Act (Wbp). That is sixteen months before the GDPR entered into force. In those sixteen months, no decision was made to switch off RAM. Only the hard deadline of 25 May 2018 forced the Tax and Customs Administration into action.
This means that the Wbp violation — and thus the unlawful processing of personal data of millions of citizens and entrepreneurs — lasted at least from January 2017 to May 2018, and the GDPR violation until January 2021 (the nationality memo). That is a total of four years of known unlawful processing by the Tax and Customs Administration, with the knowledge of the concern directors.
The migration timeline: 17 months of chaos
Annex 1C contains a confidential timeline of the RAM migration, drawn up on 29 January 2021 in response to the nationality discovery.
| Date | Event |
|---|---|
| October 2017 | GEB RAM delivered, insight into remaining measures to be introduced |
| 22-29 November and 6 December 2017 | Power meetings: search for a solution path from RAM migration to a new intelligence facility |
| December 2017 | Solution path including cost picture |
| December 2017 - April 2018 | Administrative alignment on solution path |
| 6 April 2018 | Chain table GKT states that “RAM must be out by 25/5, and that there can be no question of a date of 1/7/18 (from IT)” |
| 12 April 2018 | Memo in MTBD: 25/5 is hard date |
| 17 April 2018 | Kick-off emergency provision with three tracks |
| 24 May 2018 | Cleaning order: “Nationality 1 and 2 are marked for deletion” |
| 25 May 2018 | RAM switched off, one day before GDPR |
| 12 to 15 June 2018 | Cleaning carried out and confirmed |
| 11 July 2018 | Switching off the apandu22 customer group RAM |
| 7 December 2018 | WMIK within DF&A negative about track 2 IVT |
| 7 February 2019 | Status of phase-out at chain table GKT |
| 4 April 2019 | End of project RAM |
| 20 April 2019 | Last steering group emergency provision RAM |
| 8 January 2021 | Discovery of nationality still present in track 2 IVT |
The chain table GKT stated on 6 April 2018 that RAM had to be out by 25 May. There was no room for the extension to 1 July 2018 proposed by IT. This implies that there was a tension within the Tax and Customs Administration between IT (which wanted time) and the business (which set 25 May as a hard limit). The GDPR deadline forced a decision that should have been made internally sixteen months earlier.
Three replacement tracks: all prematurely terminated
After switching off RAM on 25 May 2018, three replacement tracks were set up. The Written Consultation of 26 May 2025 states that these tracks were supposed to respect the GDPR, but that “these tracks insufficiently met preconditions for recording and documentation, also in relation to the GDPR.”
| Track | Content | Result |
|---|---|---|
| 1 | GDPR-compliant cleaned copy of the RAM database; non-GDPR fields removed | Same objections remained; switched off May 2019 |
| 2 | Current data from a number of transaction systems; idea: this aligns with GDPR | Insufficient recording and documentation; prematurely terminated |
| 3 | Fiscal core data for tactical and strategic analyses | Limited to branches; prematurely terminated |
The evidence problem
- For tracks 1 and 3, descriptions of the datasets are still available, but not the queries executed on those datasets
- For track 2, neither the dataset descriptions nor the queries are available anymore
- The logging of RAM for the period after 2012 was not made available, simply because “no log files are available”
The state therefore cannot reconstruct which data was actually processed, by whom, and for what purpose. That is precisely the evidence problem that stands in the way of victims of the toeslagenaffaire.
All connected source systems: the data archipelago
RDM and RAM were not stand-alone systems. They functioned as a node in an extensive archipel of source systems, analysis environments, successor systems and chain partners. Below is the complete overview of what was connected to what, based on the text exports of Annex 1A, 1B and 1C and the KPMG report.
The 72 source systems of RAM
An internal memo of 20 November 2017 states that “RAM unlocks data from 72 sources and enables users to query and analyse it. This functionality is unique within the Tax and Customs Administration.” The KPMG report documents 69 source systems and 250 data tables in RAM. The most important source systems are:
| Code | Full name | Content |
|---|---|---|
| BVR | Relations Management (core system) | Main customer relations file |
| ABS | Assessment Tax System | IH/VPB assessments |
| TSL | Toeslagen (Allowances) | Allowance and child-related budget data |
| HSB | Withholding Tax (vehicle data) | Vehicle data |
| OB | Value Added Tax (VAT / Omzetbelasting) | VAT returns, defaults, supplementary assessments |
| IH | Income Tax / Income Levy | IH returns, additional assessments |
| Vpb | Corporate Tax (Vennootschapsbelasting) | VPB returns, corrections |
| LH | Wage Tax (Loonheffing) | LH returns, wage sums, employees |
| KvK | Chamber of Commerce | Registrations, branch codes, shareholders |
| FSV | Fraud Signalling Facility | ~180,000 citizens as a fraud signal |
| GOS | Generic Support Services | Support services |
| FLG | Financial Wage Data | Wage and financial data |
| HLP | Wage Tax and Employee/National Insurance Levies | Wage tax + insurance premiums |
| GEFIS | Integrated Fraud Information System | Criminal records + fiscal fines (FIOD) |
| VIES | VAT Information Exchange System | EU-wide VAT exchange |
| INL | Local Recovery (new GOA) | Outstanding amounts, local recovery |
| IKB | Integral Customer Image | Integrated customer view |
| RAM | Risk Analysis Model | The main system itself |
| RDM | Regio Data Model | The MKB selection layer on top of RAM |
| LOA’s | Locally Developed Applications | Dozens of informal tools |
RAM also linked to: bank data, vehicle data (RDW), real estate files, notarial deeds, Fiscal Allowance and bank data, IP addresses, Becon files (tax consultants), emigration data, GBA/CBR data, AKI notifications (Labour Chain Inspection), PIT notifications, ERA data.
The analysis environments and their successors
| System | Status | Link | Special feature |
|---|---|---|---|
| RAM (Risk Analysis Model) | Switched off 25-5-2018 | 72 sources | 250 data tables; 20 years in use |
| RDM (Regio Data Model) | Phased out | Drew from RAM | MKB-specific presentation layer |
| Track 1 (GDPR-compliant copy) | Switched off May 2019 | RAM copy | Same objections remained |
| Track 2 (IVT on TD/SASgrid) | Prematurely terminated | Transaction systems | Datasets AND queries destroyed |
| Track 3 (structural) | Prematurely terminated | Fiscal core data | Limited to branches |
| Emergency provision | In use until July 2018 | RAM extract | 60 employees under MKB leadership |
| IVT track 2 | Closed 1-1-2021 | RAM extract uncleaned | Nationality 2012-2016 present |
The seven RAM-like successor systems (2025)
The KPMG report of February 2025 identified seven systems that were still in production in 2025 and showed “comparable risks” to RAM. The Autoriteit Persoonsgegevens demanded immediate phase-out of the first two in July 2025.
| System | Full name | Risk level | AP judgment |
|---|---|---|---|
| KTA | Customer Supervision Application | CRITICAL | Phase out immediately (18,000 users, all personal data without authorisation roles) |
| Informatiesjabloon | Excel export tool | CRITICAL | Phase out immediately (personal data outside security) |
| IHP | Information Hub Platform | HIGH | Mitigate (~2,000 users, no logging) |
| IFL | Information for Career | HIGH | Mitigate (Excel macros, no transition plan) |
| SMOB | Selection Module VAT | MODERATE | Mitigate (2,314 users, passive monitoring) |
| Gruff | Graph database | MODERATE | Mitigate (no solution architecture) |
| PRISMA | Customs risk model | MODERATE | Mitigate (predefined rules) |
The Tax and Customs Administration ignored the AP call. As of May 2026, the systems are still running.
The hidden storage environments
In addition to the active production systems, the Tax and Customs Administration hosted multiple shielded storage environments that only came to light in 2025-2026.
| Environment | Content | Status upon discovery |
|---|---|---|
| Data vault | 64 million files, of which 24.3 million substantive | Created May 2019; rediscovered July 2025; House informed April 2026 |
| Toeslagen mailboxes | 1,004 copies of mailboxes of former DTO | Safeguarded May 2020; never searched |
| Employee Q-drives | Personal work environments | Not yet found (2026) |
| Connect People environments | Collaboration platform | Not yet found (2026) |
| FSV data vault | Shielded FSV environment | Terminology also used for FSV archive |
| Excel files on network drives | 2 million Excel files | Without archive management; not searched |
Ten chain partners that received RAM data
The RDM/RAM data was not only used within the Tax and Customs Administration. Via covenants, data was shared with ten external collaborative partnerships.
| # | Partnership | Sector | Participants |
|---|---|---|---|
| 1 | National Approach to Address Quality (LAA) | Address control | Municipalities |
| 2 | Financial Expertise Centre (FEC) | Financial/fiscal | FIOD, police, Public Prosecution Service, AFM, DNB, FIU |
| 3 | Regional Information and Expertise Centres (RIECs) | Subversion | Police, Public Prosecution Service, municipalities, UWV, SVB |
| 4 | National Information and Expertise Centre (LIEC) | National subversion | Idem + SZW |
| 5 | National Steering Group Intervention Teams (LSI) | Intervention | SZW, UWV, SVB, police, Public Prosecution Service |
| 6 | Infobox Criminal & Unexplained Assets (iCOV) | Assets | Justice |
| 7 | BIBOB Collaboration | Permits | Justice |
| 8 | Citydeal Visibility on Subversion | Local | Municipalities |
| 9 | Counter-terrorism CT infobox | Terrorism | Justice and Security |
| 10 | Healthcare Fraud Node | Healthcare | VWS (Health), health insurers |
The total number of connected systems
Added up, the RDM/RAM data archipelago comprised:
| Category | Number |
|---|---|
| RAM source systems | 72 |
| RAM data tables | 250 |
| Locally Developed Applications (LOAs) | 20-25 systems across 15 organisational units |
| Temporary analysis environments | 3 tracks + emergency provision + IVT track 2 |
| RAM-like successor systems | 7 |
| Hidden storage environments | 6+ (data vault, mailboxes, Q-drives, Connect People, FSV vault, Excel) |
| External chain partners | 10 |
| RAM selections in 20 years | ~500,000 |
| Citizens/enterprises in data | 11 million + 1.9 million |
The state profiled virtually every Dutch citizen for twenty years through a system that “structurally violated statutory requirements”, shared the results with ten chain partners, and stores the evidence in six hidden storage environments that only came to light in 2025-2026. The state still refuses to systematically search these environments and actively inform citizens.
The AP report of 9 July 2025: systematic violation confirmed
On 9 July 2025, the Autoriteit Persoonsgegevens published its report on RAM and the six comparable systems. The report is signed by AP board member Katja Mur and addressed to State Secretary Van Oostenbruggen. The AP bases itself on the KPMG report and does not conduct additional independent investigation into RAM itself — “because much information about RAM is no longer available.”
Four main conclusions about RAM
| # | Conclusion | What the AP acknowledges |
|---|---|---|
| 1 | RAM unlawfully processed personal data, including special categories and personal data concerning criminal convictions and offences | Violation GDPR art. 9 (special categories) |
| 2 | A distinction was made between persons, including on nationality, and to date no objective justifications are known. RAM was therefore used to carry out discriminatory processing | Violation art. 1 Constitution, art. 14 ECHR, art. 9 GDPR |
| 3 | No appropriate technical and organisational measures were taken for the security of personal data in RAM. Data could be freely exported from RAM and these extracts were also not secured | Violation GDPR art. 32 |
| 4 | The Tax and Customs Administration withdrew from supervision for years by not reporting the relevant processing of personal data to the DPO and the Personal Data Protection Authority (Cbp). Those reports were legally required | Violation GDPR art. 36-37 |
The key passage
“The Tax and Customs Administration has with the application RAM for a long time systematically violated the regulations regarding the protection of personal data. The AP concludes that there are serious violations. The Tax and Customs Administration did not take the WRP and the Wbp seriously, and everything indicates that the goal — exercising supervision on taxpayers — sanctified all means. Fundamental rights of citizens were seriously violated. What particularly disturbs the AP is that RAM made it possible, at the whim of the tax inspector and without controls on this, to make all kinds of risk selections in which the risk of discriminatory processing becoming real.” — Autoriteit Persoonsgegevens, letter 9 July 2025, Our reference 2025-002145, signed by Katja Mur
The sanction that did not happen
“These are violations so serious that a firm sanction would not be out of place. However, because the violations were committed more than seven years ago, the AP does not proceed to do so.”
The seven-year limitation period saves the State from a formal fine. The FSV fine from July 2020 amounted to €2.75 million — a fraction of a working day’s budget for a government organisation. The AP here chooses to let the public condemnation suffice, in the hope that the Tax and Customs Administration will improve internally. For individual victims, this means that there is no direct administrative enforcement action.
The six “systems comparable to RAM”
KPMG identified six systems that were still in use in 2025 and showed comparable risks. The AP subjected these systems to an expedited data protection inspection.
| System | Owner | AP judgment | Problem |
|---|---|---|---|
| Informatiesjabloon | Tax and Customs Administration | Phase out immediately | Excel export of personal data outside security; sexual orientation derivable |
| KTA (Customer Supervision Application) | Tax and Customs Administration | Phase out immediately | 18,000 employees have access to all personal data without authorisation roles; sexual orientation derivable |
| Gruff | Tax and Customs Administration | Mitigate | No solution architecture |
| IHP (Information Hub Platform) | Tax and Customs Administration | Mitigate | Queries not logged |
| SMOB (Selection Module VAT) | Tax and Customs Administration | Mitigate | Passive monitoring |
| PRISMA | Customs | Mitigate | Risk selection system with predefined rules |
The AP requests the Tax and Customs Administration to submit a solid plan for the phase-out of Informatiesjabloon and KTA no later than 15 October 2025. The other four systems must be improved. The AP considered immediately shutting down the two systems, but ruled that “this would have too drastic consequences for the performance of the public task of the Tax and Customs Administration.”
AP perspective on the compensation process
“In the 20 years that RAM was used, an estimated 500,000 selections were made. For only 1,170 of these selections was a RAM extract found in the Tax and Customs Administration archives (this is less than 0.25%), which forms the basis for the compensation action. Although the total number of individuals disadvantaged by RAM cannot be established, the AP considers it plausible that, given the small percentage of RAM extracts that can be investigated, only a small percentage of the potentially disadvantaged citizens can actually qualify for a form of compensation.”
The AP has been monitoring the Tax and Customs Administration’s compensation process since April 2025. For the file, this is an important recognition: the 1,170 extracts investigated are less than 0.25% of the total. For the remaining 99.75% of the 500,000 selections, no compensation option remains.
The HVB programme: 979 applications scanned
The report “Reporting Sweep Action applications nationality, medical and criminal data (Prio 1a)” of 17 February 2022 — released via the KPMG submission — reveals a follow-up investigation under the HVB programme (Restore, Improve and Safeguard / Herstellen, Verbeteren en Borgen) that has received little broad publicity.
Background
“The Tax and Customs Administration recorded (risk) signals in an application for supervision: the Fraud Signalling System Facility (FSV). It turned out that the FSV did not fully comply with the GDPR, BIO and the Archives Act 1995. The application was therefore taken offline on 27 February 2020.”
Following the FSV affair and a commitment by the then State Secretary on 15 November 2019 to the CAF 11 parents, the Tax and Customs Administration started a scan of all IT-managed applications in December 2020. The question: which applications contained nationality, medical or criminal data without a legal basis?
Results of 979 applications
| Category | Number | Status |
|---|---|---|
| Total identified applications | 979 | 10 double-counted, 969 unique |
| Applications without N, M or S data | 822 | Clean |
| Applications with N, M or S (or uncertain) | 147 | Further investigated |
| With sufficient explicit legal basis | 57 | Approved |
| Without sufficient legal basis | 4 | FSV, INL, DRI, DRA |
| Legal basis still unclear | 86 | Follow-up actions started |
The four systems without sufficient legal basis
| System | Full name | 2022 Status |
|---|---|---|
| FSV | Fraud Signalling System Facility | Already addressed; taken offline 27-2-2020 |
| INL | Local Recovery | Follow-up action required |
| DRI | Customs Query Information | Follow-up action required |
| DRA | Customs Registration and Handling | Mitigating measures taken |
In addition to the FSV, there are therefore three other systems at the Tax and Customs Administration or Customs that contain nationality, medical or criminal data without explicit legal basis. This finding is separate from the 14 nationality spreadsheets that emerged in the KPMG report.
RDM in the list of 979
RDM is listed as number 952 in validation population C of the HVB report (228 applications), coded with “1” for the occurrence of nationality, medical or criminal data. This confirms that RDM was explicitly recognised as an application that contained special personal data. The HVB report was published in 2022, three years before the KPMG report of February 2025. The Tax and Customs Administration therefore already knew in 2022 that RDM contained special personal data, but did not proactively communicate this to the House.
The broader HVB programmes
The prio 1a report is only one of three parallel projects:
| Project | Scope | Report status |
|---|---|---|
| Prio 1a — Applications | 979 applications | Final report 17 February 2022 |
| Prio 1b — Lists | 193 lists | Report date unknown |
| Prio 1c — Databases/disseminations | Dissemination databases | Report date unknown |
The total population of HVB is therefore considerably broader than just the 979 applications. Whether the prio 1b and 1c reports have ever been made public has not been established.
The Assessment Committee
The HVB steering group set up an independent Assessment Committee in April 2021, composed of employees from:
- Corporate Service Professional Technique (CD VT) — 2 people
- Concern Directorate Execution and Enforcement Policy (Cd UHB) — 2 people
- Concern Directorate Information Provisioning & Data Management (Cd IV&D) — 1 person
- Concern Directorate Fiscal and Legal Affairs (Cd FJZ) — 1 person
The committee divided the applications into four categories and tested the legal basis with the responsible directorates on three of them. The Assessment Committee’s report is included as an annex to the final report.
Consequences for the rule of law
The combination of RDM, RAM and the migration misery touches on a number of fundamental rights and legal norms.
| Norm | Violation |
|---|---|
| Art. 1 Constitution (equal treatment) | 14 spreadsheets selected on 1st/2nd nationality; AP: “no objective justifications known” |
| Art. 8 ECHR (private life) | 20+ years of uncontrolled data collection on 1.9 million MKB entities |
| Art. 14 ECHR (prohibition of discrimination) | Systematic selection on nationality; 35 spreadsheets on postcode |
| Art. 6 ECHR (fair trial) | No access, no objection, no defence against profiling |
| Art. 1 P1 ECHR (property protection) | MKB entrepreneurs disadvantaged by profiling-based assessments |
| GDPR / Wbp | RDM/RAM never registered; AP: “systematically violated”; nationality left behind after cleaning from 2018 to 2021 |
| Open Government Act (Woo) | House only informed in 2022; data vault concealed for seven years |
| Archives Act | ~9,000 files destroyed under GDPR pretext; RDM archive incomplete |
Causes of the failure
The Written Consultation identifies a number of structural causes:
- Decentralised assignment of authority (1998-2010): decision-making authority over RAM was decentralised while the instrument was meanwhile used nationally
- Supervisory interest prevailed: within the Tax and Customs Administration, the supervisory interest outweighed compliance with legal requirements
- No independent review: RDM construction lay with MKB intelligence staff themselves, not with IT or an independent regulator
- Culture of silence: the CDO Risk document from January 2017 led to no action; the AP was only informed in 2025
- Insufficient migration: three tracks failed, the national identity of the data was not safeguarded
Why this matters
The Regio Data Model was not the only profiling system of the Tax and Customs Administration. Nor the largest. But it is the system that most clearly shows how a local initiative in one region (Rivierenland, 2009) could grow into a national classification instrument for 1.9 million SME entities in six years — without anyone in that period recording what the formal product name was, without any independent review of the risk models, and without citizens or entrepreneurs ever seeing their risk colour.
The Written Consultation of 26 May 2025 contains, for the first time, a number of acknowledgments that remained unanswered in earlier parliamentary questions:
- The state acknowledges that RDM and RAM were used structurally in violation of statutory requirements
- The state acknowledges that there were fourteen spreadsheets that selected on nationality
- The state acknowledges that there may have been fundamental rights violations and takes responsibility for them
- The state acknowledges that decision-making on RDM/RAM between 1998 and 2010 was decentralised and uncontrolled
- The state acknowledges that logging was missing and that this resulted in deficient insight
At the same time, the state refuses to actively inform citizens about the 14 nationality spreadsheets, refuses to establish a compensation fund before the investigation is completed, and relativises the importance of the ten collaborative partnerships that received data for twenty years.
The investigation into the 14 spreadsheets with selection on nationality and the 35 spreadsheets with selection on postcode is being conducted using the methodology of the Compensation Act for Selection at the Gate, tested by the Auditdienst Rijk. The result is expected in September 2025. Until then, citizens remain ignorant of their status in these spreadsheets.
The parallels with the toeslagenaffaire are striking. In both cases, there was risk-driven profiling of a broad population, based on hard system signals, without individual citizens being able to defend themselves. In both cases, the system continued to run for years despite internal signals. In both cases, the state refuses active recovery.
The difference is that RDM has at least been described in detail in an own product document of 3 March 2015, whereas the operation of the FSV and the second nationality selection at Toeslagen only came to light via PwC and KPMG. This offers a unique opportunity to reconstruct the system and to hold the responsible officials accountable for their responsibility. The wait is for the AP report and the Auditdienst Rijk’s judgment in September 2025.
References
Official documents
- KPMG Report investigation Risk Analysis Model (RAM), 25 February 2025, section 6.6.10 Regio Data Model (RDM), 165 pages
- House letter policy response external investigation RAM, 6 March 2025, State Secretary Van Oostenbruggen
- Written consultation on the Risk Analysis Model, 26 May 2025, State Secretary T. van Oostenbruggen, Our reference 2025-0000101261
- Decision note written consultation RAM, 7 May 2025, Ministry of Finance, note number 2025-0000123285
- AP report investigation into RAM and the ‘systems comparable to RAM’, 9 July 2025, Autoriteit Persoonsgegevens, signed by board member Katja Mur, Our reference 2025-002145
- House letter policy response to AP report RAM, 10 July 2025, State Secretary Van Oostenbruggen
- AP news release: “Tax and Customs Administration must shut down systems with privacy risks”, 10 July 2025
- Government.nl, Annex 1 report investigation RAM
- Ministry of Finance, “The Regio Data Model — A description of the history to date”, internal product document 3 March 2015
- “Reporting Sweep Action applications nationality, medical and criminal data (Prio 1a)”, Tax and Customs Administration HVB programme, final v2.1, 17 February 2022, 55 pages
Annexes KPMG submission
- Annex 1A KPMG submission (1,637 pages), contains: memo 11 April 2018 with 2017 RAM usage figures, second-hand car trade project report 1 June 2015 with working name Risicomodel Rivierenland, confidential nationality memo 2 February 2021
- Annex 1B KPMG submission (910 pages), contains: original RDM documentation 3 March 2015, operational inventory tables with RisicoDataModel as functional working name
- Annex 1C KPMG submission (628 pages), contains: ODW-RAM-FleXviewer explanation with “06b Region by nationality” template, confidential RAM migration timeline 29 January 2021
OpenBrief investigation reports
- RAM never disappeared: the state profiles on, 27 May 2026
- RAM and MKB Profiling: The Tip of the Iceberg, 14 May 2026
- Data vault: 64 million hidden files discovered, 13 March 2026
Relevant jurisprudence and legal texts
- Equal Treatment Act (Wgb)
- General Data Protection Regulation (GDPR), Article 9 (special categories of personal data) and Article 22 (profiling)
- Compensation Act for Selection at the Gate (Wet compensatie wegens selectie aan de poort)
- Personal Data Protection Act (Wbp, predecessor of GDPR)
- Constitution Article 1 (equal treatment)
- ECHR Article 8 (private life), 14 (prohibition of discrimination), 6 (fair trial), 1 P1 (property protection)
Methodological notes
- The text exports of Annex 1A (108,830 lines), Annex 1B (58,677 lines), Annex 1C (52,904 lines) and KPMG RAM report (13,166 lines) have been fully searched for the terms RDM, Regio Data Model, RisicoDataModel, Risicomodel Rivierenland and Risicodatamodel Rivierenland
- All quotes in this investigation can be traced line-by-line to the text exports
- The interpretation of the four names is based on distributional analysis: 26 of 29 mentions in Annex 1B use Regio, 3 use Risico; in Annex 1A, Risicomodel Rivierenland and Risicodatamodel Rivierenland each appear once
- The conclusion that RDM was a data layer on top of RAM is derived from section 6.6.10 of the KPMG report and is supported by the own RDM description from 2015 in which RAM is mentioned as the source
- The investigation methodology for the 14 nationality spreadsheets is the methodology of the Compensation Act for Selection at the Gate; the result is expected in September 2025
Sources
- KPMG Report investigation Risk Analysis Model (RAM), 25 February 2025 (165 pages), section 6.6.10 Regio Data Model (RDM)
- Ministry of Finance, 'The Regio Data Model — A description of the history to date', 3 March 2015 (own product document)
- Annex 1A KPMG submission (1,637 pages), memo 11 April 2018 with 2017 RAM usage figures; second-hand car trade project report 1 June 2015; confidential nationality memo 2 February 2021
- Annex 1B KPMG submission (910 pages), including original RDM documentation 3 March 2015
- Annex 1C KPMG submission (628 pages), confidential RAM migration timeline 29 January 2021; ODW-RAM-FleXviewer explanation
- Decision note written consultation RAM, 7 May 2025, Ministry of Finance (note number 2025-0000123285)
- Written consultation on the Risk Analysis Model, 26 May 2025, State Secretary T. van Oostenbruggen (Our reference 2025-0000101261)
- Open.overheid.nl, document 4d9352c5-75dd-424a-8dbb-5674b719b196
- Government.nl, House letter policy response external investigation RAM, 6 March 2025
- OpenBrief, 'RAM never disappeared: the state profiles on', 27 May 2026
- OpenBrief, 'RAM and MKB Profiling: The Tip of the Iceberg', 14 May 2026
