GDPR enforcement
Fines and decisions, and what to learn from them
Fines by the Dutch Data Protection Authority and binding EDPB decisions show which mistakes supervisory authorities weigh most heavily. Per case: amount, articles infringed, status and the lesson for your own processing. Only cases read on the authority’s own source.
Reference date of this layer: 15 September 2026. Every item was checked against its source; the date per item is shown. Anything after the reference date is not yet here.
- under appealAutoriteit PersoonsgegevensAP-persbericht 21 augustus 2026€824,990,000
Dutch DPA fines Uber 824.99 million euros for automated driver deactivation
The Dutch DPA found that between 2018 and 2022 Uber deactivated driver accounts fully automatically on suspected fraud or low customer ratings: temporarily, or permanently with persistently low ratings, without any human review, cutting off drivers' income via Uber. The DPA holds this breached the GDPR ban on solely automated decision making, and that Uber did not inform drivers adequately about it. Uber has since ended the breaches. The investigation followed a complaint by the French Ligue des droits de l'Homme on behalf of 171 drivers to the French regulator, with the DPA as lead authority under the one-stop-shop mechanism. The fine of 824,990,000 euros is set against a 2025 global turnover of about 44.5 billion euros. Uber has announced it will object. It is the fourth DPA fine on Uber, after 600,000 euros (2018), 10 million euros (2023) and 290 million euros (2024).
What this means: If your software takes decisions with major effects on people, such as blocking an account or cutting off income, a human must genuinely review the decision before it takes effect. You must also clearly inform people that automated decision making is used and how it works. This is the largest fine the Dutch DPA has imposed so far, so automated decisions about people are high on its enforcement agenda.
- status not establishedAutoriteit PersoonsgegevensAP-kenmerk 2025-005323 (besluit van 1 april 2026, gepubliceerd 8 mei 2026)€100,000,000
100 million euro fine for MLU B.V. (Yango) for transfers to Russia
The Dutch DPA fined MLU B.V. 100 million euros. MLU is the legal successor of the dissolved Ridetech International B.V., the company behind the European Yango app. Personal data of drivers and customers in Norway and Finland went to Yandex.Taxi LLC and Yandex LLC in Russia. This included driving licence details, contact details and location data. Ridetech did not demonstrate that appropriate safeguards were in place. According to the DPA this breaches Articles 44 and 46 GDPR, read with Article 5(1)(a) and 5(2) GDPR. The infringement began on 23 May 2022 and was still ongoing when the decision was taken. The DPA also imposed a processing ban with immediate effect: the transfers to Russia must stop. The investigation was carried out jointly with the Norwegian and Finnish supervisory authorities.
What this means: Transferring data to a country without an adequacy decision? Then you must be able to prove that you use a valid transfer tool. You must also be able to show that the data is equally well protected in practice. Pseudonymisation and encryption do not replace that when the recipient within the group holds the keys or has access. A legal successor remains liable for the breaches of a dissolved company. The fine can be calculated on the worldwide turnover of the whole group.
- finalAutoriteit PersoonsgegevensAP-boetebesluiten 3 februari 2026, kenmerken 2026-002523 (Tilburg), 2026-002526 (Eindhoven), 2026-002528 (Huizen), 2026-002529 (Haarlemmermeer), 2026-002530 (Ede), 2026-002531 (Veenendaal), 2026-002532 (Zoetermeer), 2026-002533 (Delft), 2026-002534 (Hilversum), 2026-002535 (Gooise Meren); persbericht 5 februari 2026€250,000
Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
Ten Dutch municipalities (Delft, Ede, Eindhoven, Gooise Meren, Haarlemmermeer, Hilversum, Huizen, Tilburg, Veenendaal and Zoetermeer) had an external research agency, partly on the advice of the national counterterrorism coordinator, map mosques and Muslim residents through so called force field analyses and quick scans. The reports covered religious beliefs, branch of Islam and in some cases detailed personal profiles, without the data subjects' knowledge. The DPA found that the municipalities held the reports without a legal basis (Article 5(1)(a) with Article 6(1)) and processed special category data in breach of Article 9. The fine concerns holding the reports, not the research itself. Each municipality is fined 25,000 euros. That is below the fining guidelines because the breaches were short, largely time barred and took place under pressure from central government and politics. The DPA also imposed a processing restriction under Article 58(2)(f): until destroyed, the reports may only be used to facilitate data subject rights and for court proceedings. The municipalities acknowledge the breaches and are willing to accept the fines.
What this means: Even when central government or a national coordinator urges a particular approach, the commissioning body remains the controller and needs a legal basis beforehand. Data about religion or political views may almost never be processed. Outsourcing the research to an agency changes nothing: merely keeping such a report can be a breach. Partial time bars do not prevent a fine, and the DPA can restrict any further use of such reports.
- finalAutoriteit PersoonsgegevensBoetebesluit AP, ons kenmerk 2024-024797 (besluit 15 december 2025, gepubliceerd 17 december 2025)€175,000
HAN University of Applied Sciences fined 175,000 euros for inadequate security
In 2021 a hacker used SQL injection through a web form to reach a HAN web server and database server. The server held several hundred thousand records, including names with passwords, special category data, 407 citizen service numbers and 183 identity document numbers. The hacker demanded a ransom, which was not paid. The Dutch DPA found four shortcomings. Measures against SQL injection were insufficient and logging and monitoring were too limited. A database account had unrestricted rights across 282 databases. Data from retired applications was kept unnecessarily. Passwords were stored in plain text or hashed with MD5/SHA1. This breached Article 32 GDPR. The base fine of 310,000 euros was reduced to 175,000 euros because HAN actively limited the impact on data subjects, already had a security programme under way and shares lessons with other organisations. The DPA settled the case; HAN will not object.
What this means: A data breach is not itself a violation, but missing risk assessment and inadequate measures are. A security policy on paper is not enough: least privilege and deletion policies must actually be implemented. Restrict account rights to what is needed, log and monitor database activity, purge data from retired applications and keep password hashing up to date. Actively limiting harm to data subjects, investing in security already under way and sharing lessons with others substantially reduces the fine.
- status not establishedAutoriteit PersoonsgegevensAP persbericht 18 oktober 2025; oorspronkelijk boetebesluit 2019 (gepubliceerd 3 maart 2020), besluit op bezwaar; HvJ EU C-621/22 (arrest 2024)€250,000
Dutch DPA and tennis federation KNLTB end litigation: fine cut from 525,000 to at most 250,000 euros
In June and July 2018 the tennis federation KNLTB shared member data with a lottery organisation and a tennis shop, which then approached members with marketing. The DPA fined it 525,000 euros in 2019. In 2024 the Court of Justice held that the DPA had read legitimate interest too strictly: a commercial interest can qualify, but only under strict conditions. After talks the KNLTB admits the disclosure should not have happened that way and launches a privacy awareness campaign together with the DPA. The DPA cuts the fine to 250,000 euros minus the costs of the campaign and any other measures, with a final fining decision due by June 2026.
What this means: A commercial interest can be a legal basis, but only if the processing is genuinely necessary, the intrusion is limited and people can reasonably expect it and are properly informed. Providing member data to sponsors for payment without that test remains a breach. Admission, cooperation and remedial measures can substantially cut a fine.
- finalAutoriteit PersoonsgegevensAP, beslissing op bezwaar Experian Nederland B.V. van 16 oktober 2025 (herroept boetebesluit van 6 december 2023; kenmerk vertrouwelijk)€2,700,000
Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
Until 1 January 2025 Experian supplied credit reports with credit scores on individuals to clients such as telecom firms, web shops and landlords, using public and non public sources such as the trade register and telecom and energy companies. The Dutch DPA found processing without a valid legal basis (Article 5(1)(a) with Article 6(1)) and insufficient information to data subjects (Article 12(1) with Article 14(1) and (2)). On objection the DPA declared the objection well founded, revoked the primary decision of 6 December 2023 and set the fine at 2.7 million euros. Experian admits the breach, will not appeal, has stopped its Dutch activities and is deleting the database.
What this means: Anyone building profiles from sources other than the data subject must actively inform those people (Article 14) and be able to explain why each type of data is needed. A legitimate interest basis fails where consequences for people are serious and the balancing was not done properly, especially when people cannot check the data used in time.
- status not establishedAutoriteit PersoonsgegevensBeslissing op bezwaar AS Watson Health & Beauty Continental Europe B.V., 27 mei 2025 (kenmerk vertrouwelijk), herroept boetebesluit van 3 mei 2024; gepubliceerd 12 juni 2025€50,000
DPA cuts Kruidvat fine to 50,000 euros on objection
AS Watson, the company behind Kruidvat, objected to the 600,000 euro fine from 2024 for placing tracking cookies on kruidvat.nl without consent. The DPA upheld the objection as to the amount of the fine. It revoked the original decision, maintained that Article 6(1) read with Article 5(1)(a) GDPR was breached and set the fine at 50,000 euros. The DPA reduced the fine because of the unjustified length of its own proceedings, AS Watson's full acknowledgement of the breach, the low seriousness of the breach and a comparable fine in another cookie case. An appeal to the district court was available within six weeks.
What this means: The rule is unchanged: tracking cookies that process personal data require valid consent, otherwise there is no lawful basis. The decision does show that an objection can lead to a much lower fine. That applies when the organisation fully acknowledges the breach, the DPA's proceedings took unjustifiably long and the breach is not serious. The DPA also looks at fines in comparable cookie cases.
Art. 6Art. 5Art. 83Autoriteit Persoonsgegevens, besluit op bezwaar AS Watson - Kruidvatchecked on 15 September 2026 - under appealAutoriteit PersoonsgegevensBesluit tot het opleggen van een bestuurlijke boete aan Netflix International B.V., 26 november 2024 (kenmerk vertrouwelijk), gepubliceerd 18 december 2024€4,750,000
Netflix fined 4.75 million euros for failing to properly inform customers
From 25 May 2018 to 30 July 2020 Netflix's privacy statement gave customers too little, and partly unclear, information about purposes and legal bases, recipients, retention periods and safeguards for transfers outside Europe. Access requests between 25 October 2018 and 19 November 2019 were answered without sufficient specificity. The Dutch DPA found breaches of Article 5(1)(a) with Article 12(1), Article 13(1)(c), (e) and (f) and 13(2)(a), and Article 15(1)(a), (c) and (d) and 15(2). The investigation started in 2019 after noyb complaints to the Austrian authority; the Dutch DPA led because Netflix's European headquarters is in the Netherlands and coordinated the case and fine with other European authorities. Netflix has since updated its privacy statement and has objected to the fine.
What this means: A privacy notice must state the legal basis per purpose, say concretely with whom you share data and why, how long you keep it and which safeguards apply to transfers outside Europe, in clear and well-organised language. An access request must be answered just as specifically, including on recipients, retention and transfers. Large companies with many customers are judged more strictly.
Art. 5Art. 12Art. 13Art. 15Autoriteit Persoonsgegevens, persbericht en boetebesluitchecked on 15 September 2026 - finalAutoriteit PersoonsgegevensAP kenmerk z2024-010120, Formele waarschuwing CABR (brief 26 november 2024, gepubliceerd 6 december 2024)
Formal warning to the Dutch Minister of Education, Culture and Science not to put the CABR war archive online and searchable
The Dutch National Archives planned to publish the Central Archive of Special Jurisdiction (CABR), the largest Dutch war archive with about 485,000 files, online for everyone and full-text searchable in stages from 2 January 2025. The DPA issued a formal warning to the Minister of Education, Culture and Science as controller. According to the DPA, this form of publication goes beyond what Article 14 of the Archives Act requires, and is therefore likely to breach Article 6(1)(e) GDPR. The files contain special category and criminal data, also about third parties who are still alive. No statutory exception covers this, and Article 2a of the Archives Act prohibits making such data available. The DPA therefore also finds a likely breach of Articles 9 and 10 GDPR. A DPO opinion and a prior consultation were also missing. No objection can be lodged against the warning.
What this means: A statutory publication duty does not allow you to put data about living people online and make it searchable without limits. The Article 6(1)(e) basis covers only what is necessary. If the aim can also be reached in a less intrusive way, for example through access in the reading room, the broader publication falls outside that basis. Do not only check whether the main subject of a file has died: living third parties in the file are protected too. A date of birth is not needed to make someone identifiable. Ask the DPO for advice on a DPIA and consult the DPA in advance if high risks remain. The formal warning is a tool the DPA uses before a breach takes place.
- under appealAutoriteit PersoonsgegevensAP-besluit tot oplegging bestuurlijke boete aan Uber Technologies Inc. en Uber B.V., 22 juli 2024 (kenmerk vertrouwelijk), gepubliceerd 26 augustus 2024€290,000,000
290 million euro fine for Uber over transfers of driver data to the US
From 6 August 2021 to 27 November 2023 Uber transferred European drivers' data to its US headquarters without a transfer tool. The data included account data, taxi licences, location data, photos, payment data, ID documents and sometimes criminal and medical data. Uber stopped using standard contractual clauses in August 2021. According to the Dutch DPA this breaches Article 44 GDPR. The 290 million euro fine is based on a 2023 global turnover of about 34.5 billion euros. Uber has been certified under the EU US Data Privacy Framework since 27 November 2023. Uber announced an objection; according to the DPA press release of 21 August 2026 Uber is still contesting the fine and the procedure is ongoing.
What this means: Every transfer outside the EEA needs a tool: adequacy decision, standard contractual clauses with supplementary measures or another Chapter V mechanism. Dropping SCCs without a replacement is itself a breach, even if the data later fall under the Data Privacy Framework. The fine is calculated on the group's worldwide turnover.
- finalAutoriteit PersoonsgegevensBesluit tot opleggen boetes en lasten onder dwangsom Clearview AI Inc., AP, 16 mei 2024 (kenmerk niet gepubliceerd; bekendgemaakt 3 september 2024)€30,500,000
Clearview AI: 30.5 million euro fine and penalty orders for illegal facial database
Clearview scrapes more than 30 billion face photos from the internet, including of Dutch people, and converts them into biometric codes for intelligence and law enforcement clients. The Dutch DPA imposed two fines. The first, 20 million euros, covers processing without a legal basis (Article 5(1)(a) with Article 6(1)), processing biometric data (Article 9(1)) and failing to inform data subjects (Article 12(1) with Article 14). The second, 10.5 million euros, covers ignoring access requests and not facilitating the right of access (Article 12(2) and (3) with Article 15). Four penalty orders, including one for having no EU representative (Article 27), add up to a maximum of 5.1 million euros. Clearview did not object, so the decision is final. The DPA warns that using Clearview's services is also prohibited.
What this means: Harvesting biometric data from public sources is prohibited even when the photos are public; the internet is not a free source. According to the DPA, Dutch organisations that use Clearview can expect substantial fines. A non EU company processing data of people in the EU falls under the GDPR and must appoint a representative. The DPA is examining whether directors can be held personally liable.
- finalAutoriteit PersoonsgegevensBesluit boete ICS (18 december 2023, gepubliceerd 15 januari 2024)€150,000
150,000 euro fine for ICS for missing DPIA on digital identity checks
In 2019 International Card Services started digitally identifying about 1.5 million customers using selfies compared with ID copies, without first carrying out a data protection impact assessment. That breaches Article 35(1) GDPR. ICS did not object; the DPA states the fine is final.
What this means: Large scale processing of sensitive data such as ID documents and facial photos requires a DPIA before you start, even where the identification itself is legally required. Missing the DPIA is fineable on its own, regardless of whether anything went wrong. Record the DPIA and its conclusion before processing begins.
- under appealAutoriteit PersoonsgegevensBoetebesluit 11 december 2023 (gepubliceerd 31 januari 2024); besluit op bezwaar 3 maart 2026 (gepubliceerd 8 mei 2026); kenmerken in gepubliceerde versie zwartgelakt€10,000,000
10 million euro fine for Uber over unclear retention and transfer information, objection rejected
The Dutch DPA fined Uber Technologies Inc. and Uber B.V. a total of 10 million euro in two fines, following complaints by more than 170 French drivers via the Ligue des droits de l'homme. Uber's privacy notice did not clearly state retention periods, the non EEA countries data were transferred to, or the right to data portability. Uber also made the right of access unnecessarily hard: the access form was buried in the driver app, data were supplied in a CSV file without explanation of its structure, and the accompanying guidance notes were only available in English. The DPA found breaches of Article 12(1) and (2) and Article 13(1)(f) and (2)(a) and (b) GDPR. On 3 March 2026 the DPA rejected Uber's objection and upheld the fine. According to the DPA, Uber is appealing to the court.
What this means: Your privacy notice must state concretely how long you keep data, to which non EEA countries you transfer them and which safeguards apply. The access request form must be easy to find, and data supplied in response must be structured and understandable, in plain language suited to the audience. An English only explanation is not enough when many data subjects have limited command of English.
Art. 12Art. 13Autoriteit Persoonsgegevens, besluit op bezwaar boete Uberchecked on 15 September 2026 - status not establishedAutoriteit PersoonsgegevensAP-besluit 9 juli 2021 (kenmerk vertrouwelijk, gepubliceerd 8 juli 2025); beslissing op bezwaar 11 augustus 2022; Rb. Noord-Nederland 9 januari 2025, LEE 22/3460, ECLI:NL:RBNNE:2025:83€500
500 euro fine and penalty order for Stichting Oud Lemmer over webcam livestream
The foundation, which promotes the village of Lemmer, streamed live footage of the waterway and harbour in the village centre on its website from two fixed cameras (installed in 2014 and 2016). People and homes were recognisable. After complaints, the DPA found that the foundation had processed personal data without a legal basis at least from 21 February 2019: legitimate interest (Article 6(1)(f)) did not apply. It found an infringement of Article 5(1)(a) with Article 6(1) and on 9 July 2021 imposed a 500 euro fine, plus a penalty order of 500 euros per week up to 2,000 euros. The objection was rejected on 11 August 2022. On 6 September 2022 the foundation stopped the livestream, and the DPA did not collect the penalty. On 9 January 2025 the Noord-Nederland District Court held that the processing was unlawful but reduced the fine to 375 euros because the reasonable time had been exceeded.
What this means: Even a small foundation or association is a controller when it puts footage of public space online. Promoting a village does not outweigh residents and homes being recognisable on camera. Limit what is in view, make people unrecognisable, or stop streaming. The fine may be low, but the penalty order forces real change.
Art. 5Art. 6Autoriteit Persoonsgegevens, besluit boete; Rechtbank Noord-Nederland ECLI:NL:RBNNE:2025:83checked on 15 September 2026 - finalAutoriteit PersoonsgegevensBesluit boete APG, kenmerk z2019-28837 (30 juli 2020, gepubliceerd 5 juni 2024); ECLI:NL:RBAMS:2024:1214; ECLI:NL:RVS:2024:2221€6,000
6,000 euro fine for Ambitious People Group for ignoring erasure requests
Recruitment firm APG did not erase the data of three people after they asked, and kept approaching them with vacancies. That breaches Article 17(1) read with Article 12(3) GDPR. The DPA found the base fine of 310,000 euros disproportionately high and imposed 6,000 euros. The failures were human errors, APG had a policy for such requests, and it had processed more than 650 other unsubscribe requests since May 2018. The Amsterdam District Court (15 January 2024) and the Council of State (29 May 2024) upheld both the fine and its publication, after which the DPA published the decision.
What this means: An erasure request counts even when it is sent to the recruiter or employee who was in contact with the person, rather than to the privacy address named in the privacy notice. It must be handled within one month. Good policy on paper does not protect you if staff do not follow it; human errors are the controller's responsibility. The DPA may publish even small fines by name; the public interest outweighs the claimed reputational harm.