Enforcement
Dutch Tax Administration fined 3.7 million euros for the FSV fraud blacklist
- Date
- Status
- status not established
- Body
- Autoriteit Persoonsgegevens
- Reference
- AP, besluit tot boeteoplegging aan de minister van Financiën van 7 april 2022 (Fraude Signalering Voorziening), bekendgemaakt op 12 april 2022
- Amount
- €3,700,000
What it is about
From 4 November 2013 to 27 February 2020 the Tax Administration kept signals of possible fraud on around 270,000 people in the Fraud Signalling Facility (FSV). The Dutch DPA imposed six fines on the Minister of Finance as controller, 3.7 million euros in total: no legal basis (Article 5(1)(a) with Article 6(1), 1 million euros), no purpose specified in advance (Article 5(1)(b), 750,000 euros), inaccurate and outdated data (Article 5(1)(d), 750,000 euros), excessive retention (Article 5(1)(e), 250,000 euros), insufficient security (Article 32(1), 500,000 euros) and asking the data protection officer for advice on the DPIA too late (Article 35(2), 450,000 euros). According to the DPA, staff were also instructed to base the fraud risk partly on nationality and appearance.
What this means in practice
A public body that flags people as possible fraudsters through a list, score or risk model needs a specific legal basis, a purpose set in advance, accurate and current data, a retention period and a timely DPIA with advice from the DPO. Characteristics such as nationality do not belong in such a model as a risk factor.
The GDPR articles concerned
Source: Autoriteit Persoonsgegevens, persbericht 12 april 2022 en boetebesluit 7 april 2022checked on 10 October 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
- Article 9 AI Act: Risk management system
- Article 10 AI Act: Data and data governance
- Article 11 AI Act: Technical documentation
via Keeping records: record of processing, technical documentation and logs
- Article 12 AI Act: Record-keeping
via Keeping records: record of processing, technical documentation and logs
- Article 14 AI Act: Human oversight
- Article 15 AI Act: Accuracy, robustness and cybersecurity
- Article 16 AI Act: Obligations of providers of high-risk AI systems
- Article 18 AI Act: Documentation keeping
via Keeping records: record of processing, technical documentation and logs
- Article 19 AI Act: Automatically generated logs
via Keeping records: record of processing, technical documentation and logs
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
via Keeping records: record of processing, technical documentation and logs
- Article 27 AI Act: Fundamental rights impact assessment for high-risk AI systems
- Article 86 AI Act: Right to explanation of individual decision-making
Case law8 of 13
- Noord-Nederland District Court upholds DPA fine for village livestream, reduces it to 375 euros
2025-01-09 · status not established, Rechtbank Noord-Nederland
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland
- Mousse: asking for Mr or Ms when selling a train ticket is not necessary
2025-01-09 · final, Hof van Justitie van de EU (Eerste kamer), Mousse tegen Commission nationale de l'informatique et des libertés (CNIL) en SNCF Connect
- Overijssel District Court revokes DPA fine for wifi tracking in Enschede
2024-02-02 · final, Rechtbank Overijssel
- Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
2024-05-31 · status not established, Rechtbank Den Haag, voorzieningenrechter (kort geding, team handel)
- The Hague District Court cuts DPA fine on police for mobile camera cars without completed DPIA to 30,000 euros
2024-10-08 · status not established, Rechtbank Den Haag
- EU Court of Justice in KNLTB: a purely commercial interest can be a legitimate interest
2024-10-04 · final, Hof van Justitie van de Europese Unie
Guidelines8 of 17
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
2020-10-20 · final, European Data Protection Board (EDPB)
- Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR (legitimate interest)
2024-10-08 · adopted, European Data Protection Board (EDPB)
- Consultation on the draft list of processing operations for which no DPIA is required (Dutch DPA)
2026-06-24 · under consultation, Autoriteit Persoonsgegevens (AP)
- Guidelines 02/2025 on processing of personal data through blockchain technologies
2026-07-07 · final, European Data Protection Board (EDPB)
- EDPB Template for Data Protection Impact Assessment
2026-04-14 · under consultation, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
Enforcement and fines8 of 13
- Dutch DPA and tennis federation KNLTB end litigation: fine cut from 525,000 to at most 250,000 euros
2025-10-18 · status not established, Autoriteit Persoonsgegevens
- 600,000 euro fine for AS Watson (Kruidvat) over tracking cookies without consent
2024-05-02 · annulled, Autoriteit Persoonsgegevens
- 500 euro fine and penalty order for Stichting Oud Lemmer over webcam livestream
2021-07-09 · status not established, Autoriteit Persoonsgegevens
- DPA cuts Kruidvat fine to 50,000 euros on objection
2025-05-27 · status not established, Autoriteit Persoonsgegevens
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
2025-10-16 · final, Autoriteit Persoonsgegevens
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
- HAN University of Applied Sciences fined 175,000 euros for inadequate security
2025-12-15 · final, Autoriteit Persoonsgegevens
Legislation in motion6 of 8
- Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: exception for biometric verification under the data subject's sole control (Article 9(2)(l) GDPR)
2025-11-19 · proposal, Europese Commissie
- Proposal: legitimate interest for development and operation of AI (new Article 88c GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- Proposal: cookie rules move from ePrivacy to the GDPR, with new exceptions and a six-month rule (new Article 88a GDPR and Article 5(3) ePrivacy)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: EU-wide DPIA lists, template and methodology (Articles 35, 57, 64 and 70 GDPR)
2025-11-19 · proposal, Europese Commissie
Analysis
- AI DPIA: when is it required? Five-step check (2026)
2026-03-23
- DPIA vs FRIA: what is the difference? 5 points (2026)
2025-08-05
- FRIA AI Act: what it is, who needs one and how to complete it
2026-02-19
- AI Act regulator inspection: which documents must your organisation be able to show?
2026-07-07
- EU AI Act in the public sector: 2025 government guide
2025-06-16
- EU AI Act and GDPR compliance: the AI privacy guide (2026)
2025-01-03