Enforcement
150,000 euro fine for ICS for missing DPIA on digital identity checks
- Date
- Status
- final
- Body
- Autoriteit Persoonsgegevens
- Reference
- Besluit boete ICS (18 december 2023, gepubliceerd 15 januari 2024)
- Amount
- €150,000
What it is about
In 2019 International Card Services started digitally identifying about 1.5 million customers using selfies compared with ID copies, without first carrying out a data protection impact assessment. That breaches Article 35(1) GDPR. ICS did not object; the DPA states the fine is final.
What this means in practice
Large scale processing of sensitive data such as ID documents and facial photos requires a DPIA before you start, even where the identification itself is legally required. Missing the DPIA is fineable on its own, regardless of whether anything went wrong. Record the DPIA and its conclusion before processing begins.
The GDPR articles concerned
Source: Autoriteit Persoonsgegevens, persbericht en boetebesluitchecked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
Case law
- The Hague District Court cuts DPA fine on police for mobile camera cars without completed DPIA to 30,000 euros
2024-10-08 · status not established, Rechtbank Den Haag
Guidelines8 of 9
- Consultation on the draft list of processing operations for which no DPIA is required (Dutch DPA)
2026-06-24 · under consultation, Autoriteit Persoonsgegevens (AP)
- EDPB Template for Data Protection Impact Assessment
2026-04-14 · under consultation, European Data Protection Board (EDPB)
- Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is likely to result in a high risk
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Decision on the list of processing operations for which a DPIA is mandatory (Dutch DPA)
2019-11-27 · in force, Autoriteit Persoonsgegevens (AP)
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 02/2025 on processing of personal data through blockchain technologies
2026-07-07 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
Enforcement and fines
- Formal warning to the Dutch Minister of Education, Culture and Science not to put the CABR war archive online and searchable
2024-11-26 · final, Autoriteit Persoonsgegevens
Legislation in motion
- Proposal: EU-wide DPIA lists, template and methodology (Articles 35, 57, 64 and 70 GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie
Analysis6 of 7
- AI DPIA: when it's required + free template (2026)
2026-03-23
- EU AI Act Article 26: deployer obligations explained
2026-03-21
- DPIA vs FRIA: 5 key differences, when you need both, plus a free FRIA template (2026)
2025-08-05
- AI Act regulator inspection: which documents must your organisation be able to show?
2026-07-07
- What is FRIA? Fundamental rights impact assessment explained (EU AI Act)
2026-02-28
- EU AI Act in the public sector: 2025 government guide
2025-06-16