Skip to main content
Praxikon

Enforcement

6,000 euro fine for Ambitious People Group for ignoring erasure requests

Date
Status
final
Body
Autoriteit Persoonsgegevens
Reference
Besluit boete APG, kenmerk z2019-28837 (30 juli 2020, gepubliceerd 5 juni 2024); ECLI:NL:RBAMS:2024:1214; ECLI:NL:RVS:2024:2221
Amount
€6,000

What it is about

Recruitment firm APG did not erase the data of three people after they asked, and kept approaching them with vacancies. That breaches Article 17(1) read with Article 12(3) GDPR. The DPA found the base fine of 310,000 euros disproportionately high and imposed 6,000 euros. The failures were human errors, APG had a policy for such requests, and it had processed more than 650 other unsubscribe requests since May 2018. The Amsterdam District Court (15 January 2024) and the Council of State (29 May 2024) upheld both the fine and its publication, after which the DPA published the decision.

What this means in practice

An erasure request counts even when it is sent to the recruiter or employee who was in contact with the person, rather than to the privacy address named in the privacy notice. It must be handled within one month. Good policy on paper does not protect you if staff do not follow it; human errors are the controller's responsibility. The DPA may publish even small fines by name; the public interest outweighs the claimed reputational harm.

The GDPR articles concerned

Source: Autoriteit Persoonsgegevens, besluit boetechecked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

Themes where this returns

Case law

Guidelines

Legislation in motion