BesluitBron only makes data available that is already in the public domain. Each source platform can be accessed without an account and without a key. Each platform publishes under its own legal basis: the Open Government Act for administrative bodies, the Publication Act for official publications, and the publication policy of the Netherlands Council for the Judiciary for rulings.
This determines the design. The MCP addresses of BesluitBron do not require authentication. Logging in to access public data does not add any protection. Such a login does, however, create a barrier to the very use for which that data has been made public. The management console is, however, secured, as it displays the service’s behaviour rather than the data itself.
Personal data in the source
The registers contain personal data: the names of councillors, of those tabling motions, of speakers and, in the rulings, of parties to proceedings, insofar as these have not been anonymised. This data is included because the legislator or the administrative body has made a decision that it is to be made public.
Two of the consequences of this are of particular importance to the reader:
- BesluitBron adds nothing and omits nothing. Whatever the register shows is passed on; whatever the register has redacted is also omitted here. A request for removal should therefore be addressed to the source holder and not to this service;
- Combining multiple sources into a single query may result in a profile that does not exist in any of the sources individually. This is a process for which the user is responsible. The usual considerations regarding purpose limitation and proportionality apply in this regard.
What the service itself records
For each MCP request, the service records which tool was invoked, how long it took, how much data was involved, and from which network it originated. The content of the conversation with the assistant is not sent to BesluitBron and is therefore not recorded. From version 1.3.54 onwards, the organisation named by the client is also recorded, provided the client includes this information. This is the name of an organisation, not a person, and no one verifies it. The retention period and the structure of this log are set out at Logging en Verantwoording.
From 1 March 2010, the IP address is truncated before it is recorded, and any email address in a record is replaced by a non-reversible value. This has implications for requests for access. Such a request may relate to records associated with an IP address and will be processed, but the recorded address identifies a network shared by many people. These records cannot therefore be attributed to a single individual. The service describes and counts the entries but does not disclose the content of those records, as this would involve disclosing other people’s traffic.
The statement on the website
The information recorded by the website itself differs from that recorded by the MCP service. From 1 February 2024, this will be available on a public page entitled ‘Privacy and cookies’, accessible via /nl/privacy and via the footer on every page. That page describes the cookies, visitor tracking and the consent request, who receives the data and how long it is retained. The description reflects what actually happens, rather than what was intended.
Who else is involved
In addition to the service itself, there are other parties that may receive data from a visitor. These are listed on the ‘Processors’ page, which can be accessed via /nl/verwerkers and from the footer of every screen. For each party, it is stated for what purpose, where, in what capacity, and whether that party is actually reached via this system. The latter is necessary because a system that leaves the relevant setting blank does not send any data there.
From version 1.3.58 onwards, the list also includes an entry that does not insert a script into the page: the error page set by the administrator. The service sends every resolved fault to this address, along with the network, the browser identifier and, if a user is logged in, their username. The list refers to the setting as ‘BesluitBron:ErrorHandling:PostUrl’ rather than the address itself, as the administrator chooses which address this is.
The list also specifies who is accessing the site via whom. This site itself simply loads a script from a third party: the tag container. Everything that passes through it is included in the list, along with that container. This makes the chain visible, rather than just the names.
The list is available on a public page, without the need to log in, and is also machine-readable at /processors.json. So anyone wishing to compare the list over time does not need to make an enquiry or ring us.
There is a rule that ensures the list remains complete: adding an entry means updating the list in the same change. An address that the service inserts into a page whilst no rule in the list claims that address is reported at start-up and causes a test to fail. Anything that a tag container adds itself is excluded from this check; this is tracked by the container. From version 1.3.34 onwards.
What this does not cover
This page describes the structure of the service and not the lawfulness of any specific use. Whether a particular query is permitted within an organisation is determined by that organisation’s own processing register and its own policies.