FAQ

Frequently asked questions

Every question clients ask us about digital transformation, information security, AI and the public sector — with short, concrete answers, gathered in one place.

Knowledge hubs & articles

From gatekeeper to partner: gathering citizen input for property valuation

Read more →
Why does citizen input matter more since the Environment Act?

The Environment Act (2024) brought fewer permits, so government misses a wealth of data that permit applications provided — precisely the details that feed tasks such as property valuation (WOZ). Without that data, value becomes harder and less accurate to determine, forcing alternative methods to gather it; citizen input is the most direct.

What are the KOUDVL factors in the WOZ?

The secondary, value-determining characteristics of a home: quality, maintenance, appearance, functionality, amenities and location. They are subjective and hard to keep current by model — exactly where citizen input helps.

What is the risk of inaccurate WOZ valuations?

A value set on incomplete data is more likely to be experienced as wrong. That leads to objections and sometimes a formal appeal before the courts — with considerable extra workload and cost, and added pressure on an already overburdened judiciary. Better data up front, for example via citizen input, prevents that expensive chain.

How do you gather good citizen input?

Reverse the question: present what you already think you know ('this is what we have; is it still correct?') and let the citizen confirm or correct it. Ask at the right moment, keep it short, give feedback, and combine input with your model-based data.

How do you prevent citizens from colouring their input?

Safeguard quality with verification: sampling, a trail of who supplied what, and healthy scepticism towards input that comes out too conveniently. Transparency about use builds trust, turning the citizen into a partner rather than an objector.

Can you process citizen input under the GDPR?

Yes, if done carefully: purpose limitation (ask only what you need), clarity about retention periods and transparency about use. That keeps input-gathering GDPR-compliant.

5 signs you have lost control of your data

Read more →
What are signs you have lost control of your data?

Among others: no one owns a data set, on a request you cannot quickly find where data sits, shadow data grows unnoticed, you don't trust your own figures, and people keep the data correct by hand.

What is shadow data?

Stray spreadsheets, exports and copies that live outside your systems and outside your view. It goes unnoticed while things go well, but it is exactly where things go wrong the moment someone asks about it or it leaks.

Why is a data owner important?

Without an identifiable owner, no one is accountable for quality, access and use, and data rots by itself. Ownership belongs to someone from the process who feels the consequences of errors, not to IT.

Why don't I trust my own figures?

Usually because data quality is not safeguarded on completeness, correctness and currency. Two reports with different numbers are a sign that governance is missing — and every dashboard or AI model inherits that doubt.

How do you take back control of your data?

Start small: pick one core registration, appoint an owner, record quality agreements and put it in a simple register. Then ask the same question of every new registration: whose data is this, is it correct, and is this allowed?

Data governance: from by-product to managed asset

Read more →
What is data governance ('regie op data')?

Data governance means being in the driving seat over your data: you know what you hold, who is responsible, whether it is correct and who may access it. It has two sides: your organisation steers its data, and the individual can exercise control over their own data through their GDPR rights.

Why is data governance two-sided?

Alongside the organisation steering its data, the individual (citizen or customer) has control over their own data. They can exercise their GDPR rights — access, rectification, erasure, portability and objection — and in government the 'citizen control over data' movement lets people decide with whom they share.

What are the risks of having no data governance?

Without governance, shadow data emerges: stray spreadsheets and exports no one manages. It goes unnoticed until a data breach, privacy request or audit — when no one can say which data sits where. That is a compliance risk, and every dashboard or AI model inherits the mess beneath it.

Who is responsible for data within an organisation?

The data owner. Every important data set should have a single responsible person who decides on quality, access and use. That is deliberately not an IT role, but someone from the process who feels the consequences of errors.

What is a data register and why do I need one?

A simple overview of which data you hold, where it sits, who owns it and how sensitive it is. Paired with classification, it is the backbone of governance: you can only arrange security, privacy and access in a targeted way once you know what you have.

What is data quality?

The degree to which your data is complete, correct and current. Those three properties determine whether you can build decisions and AI models on it. Quality is cheapest to safeguard at the source, with clear definitions and periodic checks.

What does data governance mean for government?

It adds a grip on replication: data from national base registrations (population, addresses, property valuation) is replicated locally, and the message traffic often takes a lot of manual work. Governance means knowing which registration is the source, guarding the currency of copies and automating mutation processing.

What role do the Privacy Officer and CISO play?

They are the assurance mechanism. Internally they test the policy (privacy by design, security by design); externally they are the anchor for audits — ENSIA, NIS2 and the Data Protection Authority. That makes governance not just workable, but demonstrable.

How does data governance relate to the BIO and NIS2?

Information security (BIO/NIS2) protects the data; governance steers it (ownership, quality, access, lifecycle). They reinforce each other: without governance you don't know what you are protecting. Governance is also the precondition for reliable AI and data sovereignty.

How do I approach data governance in practice?

Start small: pick one core registration, appoint an owner, record the purpose and quality agreements, put it in a register and classify by sensitivity. Then ask the same question of every new registration: whose data is this, is it correct, and is this allowed?

How long may I keep personal data?

The GDPR says no longer than necessary for the purpose. In the public sector, the Archives Act and retention schedules also determine which data you must keep for a set period or archive permanently.

Data sovereignty: reducing dependence on US big tech

Read more →
What is data sovereignty?

Data sovereignty is the degree to which you keep a grip on your own data: where it physically sits, which law it falls under and who has access. It is about control, not about avoiding technology.

Do EU servers fall under the US CLOUD Act?

Yes, they can. If a cloud service's parent company is American, the service can fall under the CLOUD Act — even if the data physically sits in Europe. US authorities can then in principle request access.

Can a government use ChatGPT or Copilot?

Yes, if done carefully. Deliberately choose which data you process, record it in a data-processing agreement, and where possible use an enterprise or government variant with data residency in the EU. The free consumer version is not suitable for sensitive data.

How do I avoid vendor lock-in?

Make sure you can leave: choose exportable, open data formats, record an exit scenario per supplier, and avoid tying your entire work process to one provider. An exit strategy protects your negotiating position and freedom.

NIS2 for (semi-)government: the complete guide

Read more →
What is NIS2?

NIS2 (Network and Information Security Directive 2) is the EU directive for network and information security that replaces and significantly expands the original NIS directive. The Netherlands transposes it into the Cybersecurity Act (Cbw), and it explicitly brings government within its scope.

Who does NIS2 apply to?

NIS2 distinguishes essential and important entities. For the public sector, municipalities, provinces, water authorities and implementing agencies are expected to fall under the law; the precise scope is set via the Cbw. Don't assume you are out of scope.

Which obligations does NIS2 bring?

Four: the duty of care (appropriate measures), the reporting duty (report incidents within tight deadlines), the registration duty (register with the competent authority) and supervision. New is the explicit responsibility and liability of the management body.

What does the NIS2 duty of care involve?

Risk-based measures: among others risk analysis and security policy, incident handling, business continuity, supply-chain security, access control, cryptography and cyber hygiene with training. It's not a checklist, but demonstrably appropriate measures for your risks.

What are the NIS2 reporting deadlines?

For a significant incident: an early warning within 24 hours, a full incident notification within 72 hours and a final report within one month, to the competent authority or CSIRT.

Are board members personally liable under NIS2?

Yes. The management body must approve the cybersecurity measures and oversee implementation, and can be held personally accountable for negligence. Board members must also follow training to assess risks.

What is the difference between NIS2 and the BIO?

The BIO is the Dutch measures framework for government information security; NIS2 is the EU directive layered on top. Many BIO measures already cover NIS2 — the biggest additions are the reporting duty with deadlines, supply-chain security and board accountability.

What can I already do to prepare for NIS2?

Don't wait for the final text. Start with a risk analysis, map your systems and data chains (including suppliers), set up or test your incident and reporting process, and anchor it in your existing BIO/ENSIA cycle.

When does the Dutch Cybersecurity Act (NIS2) take effect?

The EU deadline was 17 October 2024; the Netherlands missed it and implementation is delayed, expected during 2025-2026. Don't wait — the core obligations are already set.

Sustainability as a revenue model, not a cost centre

Read more →
Why is sustainability an opportunity and not a cost?

Because sustainability requirements (such as the CSRD) force you into substantiation you can also use commercially. Those who make their impact demonstrable stand out with the customer and can tap (European) funding — turning sustainability into a revenue model.

What is the prove-profile-finance model?

A three-step approach: Prove (substantiate your impact with independent data, e.g. an LCA), Profile (make that evidence visible at the customer's moment of choice) and Finance (extract value from it, up to European budgets).

How do you substantiate sustainability claims under the CSRD and Green Claims Directive?

With independent, verifiable data instead of general claims — for example a life-cycle assessment (LCA). The CSRD and Green Claims Directive make greenwashing risky; an audited figure is both compliant and credible.

How do you differentiate with sustainability evidence?

By making the evidence visible exactly where the customer chooses — for example with a per-product sustainability score. Owned, indexable evidence (not generic supplier content) also builds domain authority.

Which European budgets stimulate circular models?

There are various EU and national schemes for sustainability, circularity and innovation. By making your impact demonstrable, you qualify sooner for (co-)funding — the third step, 'finance', in the model.

What does it cost to make a product carbon-neutral?

That depends on the footprint and the chosen offset; as an indication there are offset prices via labels such as Gold Standard/Fairtrade. For exact figures use an independent LCA — don't estimate it.

What does this mean for my organisation?

Treat sustainability as a strategic topic, not a compliance afterthought: substantiate your impact, make it distinctively visible and use the funding that follows. That turns an obligation into an advantage.

The information security compass: from BIO and ENSIA to NIS2 and DORA

Read more →
Why is information security layered?

Because different frameworks stack on top of each other: from international standards (ISO 27001) and the BIO/ENSIA baseline to NIS2, and sector layers like DORA and NEN 7510. Each covers its own layer; together they form the landscape your organisation is measured against.

What are the BIO and ENSIA?

The BIO (government information-security baseline) is the shared measures framework for Dutch government, based on ISO 27001/27002. ENSIA is the annual self-assessment and accountability report with which authorities demonstrate BIO compliance.

How does NIS2 fit the information-security landscape?

NIS2 sits a layer above the BIO: the EU directive (the Cybersecurity Act in the Netherlands) adds a reporting duty with deadlines, supply-chain security and board accountability. Get the BIO in order and you're largely NIS2-ready.

What are DORA and NEN 7510?

Sector-specific layers: DORA (Digital Operational Resilience Act) sets requirements for the financial sector's digital resilience, and NEN 7510 is the information-security standard for healthcare. They build on the same base, with extra requirements for their sector.

How do you turn compliance into an ambition rather than a burden?

By treating stricter frameworks not as a tick-box exercise but as guidance for where you want to go. Use the highest relevant framework as your ambition level; then you build demonstrable resilience instead of paperwork for paperwork's sake.

Does layered information security apply outside government too?

Yes. Even without a legal duty it is wise to deliberately choose a level that fits your risks and clients. For many businesses information security is shifting from an obligation to a conscious, differentiating choice.

Where does information security go wrong in practice?

Usually not in the technology, but in the coherence: isolated measures without overview, frameworks living side by side, and compliance experienced as a burden. Without a register and ownership, no one knows what is protected where.

How do you tackle layered information security pragmatically?

Start with the basics (BIO/ENSIA), map which additional frameworks apply to you, and build up from there in a targeted way. Choose one ambition level, assign ownership and work in the right order instead of everything at once.

Services & vouchers

What is a digitalisation voucher?

A clearly scoped service at a fixed price — you know upfront exactly what you get and what it costs. From a one-off scan or second opinion to ongoing monthly interim support.

Can I book a single voucher?

Yes. The one-off vouchers (scan, second opinion, SEO, dashboarding) stand entirely on their own. The monthly interim vouchers work like a subscription with a fixed one-year term.

What's the difference between Light, Target and Focus?

The monthly interim vouchers work like a subscription: you commit upfront to a fixed number of hours per month, on a one-year term. They scale in size — Light (from €450/mo) for focused input, Target (from €950/mo) for more room, and Focus (from €1,850/mo) when support moves toward project steering.

Are prices including VAT?

No, all prices shown are excluding VAT.

Information security & governance

Read more →
What's the difference between BIO, ENSIA and NIS2?

BIO is the Dutch government information-security baseline, ENSIA the annual accountability report on it, and NIS2 the EU directive tightening digital-resilience requirements — for (semi-)government too. We implement them coherently.

Do you also help with the EU AI Act?

Yes. We translate the AI Act into concrete policy and governance: risk classification, obligations per role, and anchoring in your existing security and privacy framework.

Do you deliver or just advise?

Both. We set the direction and execute — from baseline assessment and policy to implementation and the annual ENSIA report.

AI consultancy

Read more →
Where does AI consultancy at DWDA start?

With value and responsibility, not the tool. We begin with an AI-readiness scan: where does AI deliver concrete value, and what's needed in data, governance and compliance (incl. the EU AI Act)?

Is AI safe for the public sector?

When set up well, yes. We anchor AI in your existing information-security and privacy framework, with clear risk classification and human oversight of decisions.

Do you build AI solutions or only strategy?

Both — from strategy and governance to working, responsible applications running in production.

Public sector

Read more →
Which government organisations do you work for?

(Semi-)government bodies that want to modernise — from municipalities and tax collaborations to implementing agencies. Specialisms: information security, WOZ/data, Best Value and AI.

What is Best Value and why do you use it?

Best Value procurement selects suppliers on demonstrable expertise and performance rather than lowest price. It leads to better, more manageable projects — we guide both clients and delivery.

Do you know the WOZ practice?

Yes. We build WOZ and data dashboards a tax organisation steers on daily — from workload and objections to valuation and collection, with data quality as the foundation.

Sustainability marketing

Read more →
What is sustainability marketing at DWDA?

Turning sustainability into a revenue model instead of a cost: prove (independent substantiation), profile (make it visible at the decision moment) and finance (incl. via tendering and European budgets).

How do I avoid greenwashing?

By substantiating claims with independent data (for example an LCA) before you communicate them. Our approach ties evidence to message — in line with CSRD and the EU Green Claims directive.

Who is this relevant for?

Organisations facing a sustainability obligation (CSRD) that want to turn it into positioning and revenue — SMEs, multinationals and the public sector.

Digital strategy

Read more →
What exactly is a digital strategy?

A sharp choice that moves your business goals forward — not a thick report that gathers dust, but a direction we also execute. AI speeds it up: you test scenarios and business cases in days, not months.

How long does a strategy project take?

With AI-supported scenario and business-case testing, a well-founded course is often ready in weeks rather than months. We agree the scope upfront, at a fixed, plannable price.

Do you build the strategy or only advise?

Both. We set the direction and execute — strategy that runs in production, not a plan left on the shelf.

Digital transformation

Read more →
Where does a successful digital transformation start?

With the business and its optimisation, not the newest platform. We make sharp choices around your business goals and weave in AI where it delivers business-critical value.

What is AI changing about transformation?

In 2025-2026 AI shifted from experiment to business-critical tool — woven into processes, not a standalone chatbot. Moving from pilots to production now wins tempo.

Do you do both strategy and delivery?

Yes — from setting the course to working solutions that run in production.

Digital growth & maturity

Read more →
What is digital maturity?

Not buying as many tools as possible, but your organisation's ability to deliver digital value — across knowledge, skills and investment. AI keeps raising that bar.

How do I measure where my organisation stands?

Our free digital maturity scan instantly gives you your level, scores per dimension and concrete next-step advice.

What is AI changing about digital maturity?

AI raises the bar in every layer: what counted as mature yesterday is the baseline today. We help you keep up without chasing every hype.

E-commerce

Read more →
Is e-commerce still a separate channel?

No — it has grown from an additional sales channel into a company-wide commercial foundation. The choice touches your whole organisation, not just marketing.

What is AI changing about e-commerce?

Customers no longer always click through your webshop themselves: conversational and headless commerce, visual search and AI assistants change the journey. Your offer must be findable beyond your own site too.

Do you build the webshop or only advise?

Both — from strategy and platform choice to working, headless-ready commerce.

Data, analytics & insights

Read more →
Where does a good data project start?

With a sharply formulated question. We sharpen it into something measurable, determine which data is needed, and turn raw data into insight you actually steer on.

What is AI changing about BI?

LLM copilots are built into the tools you already use — analytics has fundamentally accelerated. But technology only delivers value with data quality as the foundation.

Do you also build dashboards?

Yes — from research question to a working dashboard an organisation steers on daily (see our data showcase).

Technology & building blocks

Read more →
How do you choose the right technology?

We look at the business and the goal first, and only then at the building blocks. Technology serves your strategy, not the other way around.

What is composable architecture?

Modular building blocks that move with your organisation, instead of a monolithic system locked in for years. We guide the step towards it.

Are you vendor-independent?

Yes — we choose building blocks based on your goal and manageability, not on a single vendor.

Online marketing & execution

Read more →
What is AI changing about online marketing?

People increasingly ask their question directly to ChatGPT, Gemini or Google's AI overviews. In 2026, visibility means more than a top position in Google.

What's the difference between SEO, GEO and AEO?

SEO = being found in classic search results; GEO (Generative Engine Optimization) = being picked up by AI answer engines; AEO (Answer Engine Optimization) = appearing as the answer. We make them reinforce each other.

Do you do both strategy and delivery?

Yes — we connect strategy to working execution, from visibility to conversion.