Skip to main content
Praxikon

Enforcement

Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents

Date
Status
final
Body
Autoriteit Persoonsgegevens
Reference
AP-boetebesluiten 3 februari 2026, kenmerken 2026-002523 (Tilburg), 2026-002526 (Eindhoven), 2026-002528 (Huizen), 2026-002529 (Haarlemmermeer), 2026-002530 (Ede), 2026-002531 (Veenendaal), 2026-002532 (Zoetermeer), 2026-002533 (Delft), 2026-002534 (Hilversum), 2026-002535 (Gooise Meren); persbericht 5 februari 2026
Amount
€250,000

What it is about

Ten Dutch municipalities (Delft, Ede, Eindhoven, Gooise Meren, Haarlemmermeer, Hilversum, Huizen, Tilburg, Veenendaal and Zoetermeer) had an external research agency, partly on the advice of the national counterterrorism coordinator, map mosques and Muslim residents through so called force field analyses and quick scans. The reports covered religious beliefs, branch of Islam and in some cases detailed personal profiles, without the data subjects' knowledge. The DPA found that the municipalities held the reports without a legal basis (Article 5(1)(a) with Article 6(1)) and processed special category data in breach of Article 9. The fine concerns holding the reports, not the research itself. Each municipality is fined 25,000 euros. That is below the fining guidelines because the breaches were short, largely time barred and took place under pressure from central government and politics. The DPA also imposed a processing restriction under Article 58(2)(f): until destroyed, the reports may only be used to facilitate data subject rights and for court proceedings. The municipalities acknowledge the breaches and are willing to accept the fines.

What this means in practice

Even when central government or a national coordinator urges a particular approach, the commissioning body remains the controller and needs a legal basis beforehand. Data about religion or political views may almost never be processed. Outsourcing the research to an agency changes nothing: merely keeping such a report can be a breach. Partial time bars do not prevent a fine, and the DPA can restrict any further use of such reports.

The GDPR articles concerned

Source: Autoriteit Persoonsgegevens, persbericht (5 februari 2026) en boetebesluiten (3 februari 2026)checked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

The counterpart in the other law

Case law8 of 17

Guidelines8 of 12

Enforcement and fines8 of 10

Legislation in motion6 of 9