A Dutch legislative proposal would change how potentially privileged data is filtered in criminal investigations. Initial selection would move from the investigating judge to the Public Prosecution Service. The proposal is still being developed. It would not create a general compliance duty for businesses.
Why this matters
Legal advice can sit beside invoices, payroll files, draft contracts and supplier emails. Copies then spread through shared mailboxes, chat tools, personal devices and backups. Confidential does not always mean legally privileged. Status depends on the professional role, the communication and its context. Mixed files take longer to review. Legal, forensic and IT costs can rise while managers are pulled from cash, customers and staff.
Example
A founder needs the acquisition file. The signed contract is on the shared drive. Drafts are in email. Finance received a lawyer’s advice with routine tax questions. An attachment remains on a former employee’s laptop. The business finds documents but cannot reconstruct the approved version or who opened the advice. A complete file links the proposal, adviser emails, drafts, approval, signed contract and accounting entry. It also records access rights and version history.
XTROVERSO tips
- Map where sensitive records are stored. List shared mailboxes, cloud drives, finance systems, chat tools, laptops, mobile devices and backups. Include files held by external providers.
- Give each record group an owner. Assign responsibility for contracts, board decisions, legal correspondence, tax files, payroll records and customer data.
- Separate records by purpose. Keep sensitive professional communications apart from routine invoices, supplier messages and internal planning where practical. A folder label alone does not change legal status.
- Review access rights. Check who can open, download, forward or delete files. Remove outdated access after staff departures, adviser changes, acquisitions and restructurings.
- Test one complete business file. Choose a major contract or decision. Retrieve every draft, approval, attachment, signed document and related accounting record.
- Check logs, exports and backups. Ask your IT provider what the system records. Confirm whether permissions survive exports and migrations, and how long deleted files remain in backups.
Need a practical review of record ownership and access controls? We can help identify the first fixes
The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.
References
- Rechtspraak — Modernisering van het filteren van verschoningsgerechtigde informatie
- Raad voor de rechtspraak — Advies Tweede Aanvullingswet nieuw Wetboek van Strafvordering
- Rechtspraak — Werkwijze filteren digitaal verschoningsgerechtigd materiaal
- Hoge Raad via Rechtspraak — ECLI:NL:HR:2024:314
- Rijksoverheid — Wetgevingstraject nieuw Wetboek van Strafvordering


