Short answer. You do not request an EVR registration from a single central desk. The External Reference Register (EVR) is a reference register; the substance of the registration is held by the institution that registered you. If an insurer was involved, you submit a subject access request to Stichting CIS and then to that insurer. If a bank was involved, the request goes through the bank, and for the banking EVR through BKR (the Dutch credit registration bureau). Always request two things at the same time: the registration itself and the decision, including its reasoning and the recorded assessment of its duration.
Nederlands: Lees dit artikel in het Nederlands: EVR-registratie inzien en opvragen: zo doet u het, met voorbeeldverzoek
Türkçe: Bu makaleyi Türkçe okuyun: EVR kaydına erişim ve kaydın talep edilmesi: nasıl yapılır, örnek talep metniyle
Written by Onur Arslan, attorney at Arslan Advocaten. Registered in the Netherlands Bar’s register of practice areas for employment law and personal injury. Last updated: 17 September 2026.
Why access is the first step
Without access, you do not know which register you are in, from what date, on what grounds and for how long. And without that information you cannot make a targeted request: you do not know whom to approach, and you do not know what you are defending yourself against. Institutions often send only a notice that a registration has been made. That is not the same as the decision.
There is another reason. Article 5.3.1 of PIFI 2026 (the Dutch financial institutions’ incident warning protocol) requires the institution to remove the registration of its own accord as soon as the conditions of Article 5.2.1 are no longer met. You can only invoke that obligation once you know what the registration is based on.
Whom should you approach?
| Situation | Where to request access | What to do next |
|---|---|---|
| An insurer made the registration | Stichting CIS (subject access request) and the insurer itself | CIS shows the registration; the insurer is responsible for the content and the decision |
| A bank made the registration | The bank (GDPR subject access request); for the banking EVR, also BKR | The bank provides the decision and its reasoning |
| A mortgage application was involved | Stichting Fraudebestrijding Hypotheken (the Dutch mortgage fraud prevention foundation) and the lender | Also request the grounds for the rejection |
| You do not know | Start with the party that sent you the letter | Ask explicitly for the register, the date and the legal basis |
What exactly to ask for
A subject access request under Article 15 of the GDPR entitles you to the personal data itself and to information about the processing. So do not simply ask for "my data", but list the points that matter:
- which register the data is held in: the incident register, the EVR, the Internal Reference Register (IVR) or the CIS database;
- the date of entry in the incident register, because that is when the eight-year period of Article 5.3.2 PIFI starts to run;
- the end date of the registration and the recorded assessment of why that duration is proportionate;
- the conduct on which the registration is based, and the documents that support it;
- whether a report was made to the police, and if not, why not;
- to which parties your data has been disclosed (Article 15(1)(c) GDPR);
- the outcome of the periodic review, if there has been one.
In principle, the institution must respond within one month. If no answer comes, or only a standard letter, that in itself is useful in any follow-up proceedings.
Example of a request for access and explanation
Below is a model you can adapt. Fill in your own details, keep it businesslike and keep a copy together with the proof of sending.
Model: request for access and explanation
Re: subject access request under Article 15 of the GDPR (AVG) and request for the registration decision
Date: [date]
My details: [name, date of birth, address, customer or file number]Dear Sir or Madam,
On [date] I received notice from you that my data has been entered in a warning register. Pursuant to Article 15 of the GDPR, I request access to the personal data that you process about me.
In particular, I ask you to state:
1. in which register my data has been entered (incident register, External Reference Register (Extern Verwijzingsregister), Internal Reference Register (Intern Verwijzingsregister) or the CIS database);
2. the date of entry in the incident register and the intended end date of the registration;
3. the conduct on which the entry is based and the documents on which you rely;
4. the decision to make the entry and the recorded assessment against Article 5.2.1 of the Incident Warning System Protocol for Financial Institutions (Protocol Incidentenwaarschuwingssysteem Financiële Instellingen, PIFI);
5. the recorded assessment of the duration of the registration, as referred to in Articles 4.3.3 and 5.3.2 of that protocol;
6. whether a report was made to the police in this matter, and if not, for what reason;
7. to which recipients my data has been or will be disclosed.I ask you to respond within one month of receipt, as required by Article 12(3) of the GDPR. Should you consider that an exception to the right of access applies, I ask you to identify it expressly and state your reasons.
I enclose a copy of my identity document, on which I have masked my citizen service number (BSN) and passport photograph.
Yours faithfully,
[name and signature]
Identification: what you do and do not need to send
The institution may verify your identity, but may not ask for more information than is needed for that purpose. Send a copy of your identity document on which you have made your citizen service number (BSN) and your passport photograph illegible, and write on the copy for what purpose and to whom you are sending it. Preferably send it through a channel you can prove: by registered post, or via a secure portal of the institution itself.
What you can do after obtaining access
With the documents in hand, you check three things.
- Are the facts correct? If not, that concerns Article 5.2.1(b): it must be sufficiently established that you were involved in the conduct.
- Was the assessment made and recorded? If there is only a standard sentence about the duration, or nothing at all, the decision lacks the reasoning that the protocol requires.
- Is the duration still necessary? Article 5(1)(e) GDPR does not permit data to be kept for longer than is necessary for the purpose. Eight years is a maximum, not a standard duration.
You then submit a request for correction, removal or shortening to the party that made the registration. If that is refused, the routes are an internal complaint, Kifid (the Dutch Financial Services Complaints Tribunal) and the courts. Which route fits when is explained in removing a registration: the legal routes.
Frequently asked questions about accessing an EVR registration
Can I check for myself whether I am in the EVR?
Not in a single step. The EVR is not a register you can search yourself. You request access from the institution that registered you and, for an insurance registration, also from Stichting CIS. For the banking EVR, the check is carried out through BKR’s EVA.
What does a subject access request cost?
A first subject access request is free of charge under the GDPR. Only for manifestly unfounded or excessive requests may a reasonable fee be charged.
How long may the institution take?
In principle, one month after receipt. That period may be extended by two months if the request is complex, but the institution must inform you of this within the first month.
Will I also receive the investigation report?
Not always in full. The right of access has exceptions, for example to protect the rights of others. However, the institution must then state which exception it is applying and why. In any event, you are entitled to the data processed about you and to the information about the processing.
Do I need to request access before asking for removal?
It is not required, but it is almost always sensible. A request that does not address the established facts and the recorded assessment is easy for the institution to reject.
Further reading
- Removing or shortening an EVR registration
- CIS registration by insurers
- EVR, IVR, CIS and the incident register: the differences
- Lawyer for an EVR or CIS registration
Sources and methodology
The access and correction route follows Stichting CIS on access and on amending registrations, which states that the insurer concerned is responsible for the content. Articles 5.2.1, 5.3.1, 5.3.2 and 4.3.3 are taken from PIFI 2026, in force since 1 April 2026. The time limits and the free-of-charge nature of the subject access request follow from Articles 12 and 15 GDPR. Source texts checked on 17 September 2026. The example request is a model; it is not a substitute for an assessment of your case.
Legally reviewed by Onur Arslan, attorney at Arslan Advocaten. Reviewed on 17 September 2026.



