GDPR developments
What is moving in the GDPR
The text of the GDPR has not changed since 2018, but what it means has: through Commission proposals, EDPB and Dutch DPA guidelines, Court of Justice rulings and fines. This page collects that by type, with date, status and source.
Reference date of this layer: 15 September 2026. Every item was checked against its source; the date per item is shown. Anything after the reference date is not yet here.
Legislation in motion
Everything in this section (19)- under negotiationRaad van de Europese Unie, Iers voorzitterschapCM 3890/26 (voorlopige agenda Antici-groep vereenvoudiging, 11 september 2026); ST 12535/26 en WK 13065/26 (herziene compromistekst en toelichting, aangekondigd); ST 12955/26 (AOB-nota stand van zaken omnibuspakketten voor Raad Algemene Zaken 22 september 2026); 2025/0360(COD)
Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
What this means: The Council is still negotiating. Expect new compromise texts and possibly a mandate in autumn 2026, but that is not certain. Follow the Antici Group and Coreper agendas for the moment a mandate is confirmed.
Art. 4Art. 6Art. 9Art. 88Raad van de EU, register (CM 3890/26 en ST 12955/26)checked on 15 September 2026 - in forceWetgever (Tweede Kamer) en Autoriteit PersoonsgegevensWijziging Uitvoeringswet AVG via amendement Tweede Kamer (AP-bericht 27 augustus 2026)
Amendment to the Dutch GDPR Implementation Act: DPA must publish GDPR sanctions from 1 September 2026
What this means: Assume every GDPR sanction by the DPA will become public, including penalty orders and processing bans, not only fines. Respond to the notice of intended publication, and expect publication from ten working days after receiving the final publication decision; to try to stop publication, object within that period and seek court relief if needed. Prepare communications and a legal response in advance. Publication also clarifies the DPA's standards, so use published decisions as a checklist.
Art. 58Art. 83Autoriteit Persoonsgegevens, nieuwsbericht 27 augustus 2026checked on 15 September 2026 - under negotiationEuropees Parlement, commissies ITRE en LIBE (gezamenlijke commissie)Procedure 2025/0360(COD); COM(2025)0837; ontwerpverslag PE786.818; amendementen PE786.820, PE790.967, PE790.968, PE791.071, PE791.072, PE791.073, PE791.873, PE791.874, PE791.883
European Parliament: joint ITRE-LIBE draft report, amendments tabled, no committee vote yet
What this means: Parliament has no position yet and trilogues with the Council and Commission have not started. The proposed GDPR changes, such as those to the definition of personal data and Article 22, are therefore not law and may still change substantially. Keep working under the current GDPR for now. Because the committee vote, the plenary position and the trilogues are still to come, a final text is not to be expected in the short term.
- under negotiationRaad van de Europese Unie, Antici-groep (vereenvoudiging) en CoreperST 10729/26 (nota aan Coreper, 22 juni 2026); ST 10677/26 (compromis 18 juni 2026); procedure 2025/0360(COD)
Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
What this means: The Council has no position yet, and Member States differ mainly on pseudonymisation, AI training and cookies. The Council compromises show the final text will likely differ from the Commission proposal, so do not build compliance on the proposal text.
- finalEuropees Comité van de Regio'sCOR-2025-04240 (CELEX 52025AR4240)
Committee of the Regions adopts opinion on the Digital Omnibus
What this means: No direct consequence for you. The opinion is non-binding and is a procedural step in the legislative procedure, which is still ongoing on 15 September 2026.
EUR-Lex, procedurepagina 2025/0360(COD)checked on 15 September 2026
Case law
Everything in this section (27)- finalRaad van State, Afdeling bestuursrechtspraakECLI:NL:RVS:2026:4403, zaaknummer 202401622/1/A3€600,000
Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
What this means: The DPA must fully prove at the decision stage that personal data and a breach are involved; evidence or new reasoning first raised in court does not count. This is no licence for wifi tracking: the court did not say MAC addresses are not personal data and did not assess on the merits the position on direct identification through unique counts. Anyone deploying sensors must still justify necessity, legal basis and anonymisation.
- finalHof van Justitie van de EU (Vijfde kamer), ND tegen Legal Newsdesk Sweden AB (voorheen Garrapatica AB)C-199/24, ECLI:EU:C:2026:564
Legal Newsdesk Sweden: paid online publication of criminal convictions is in principle not journalism, national exemptions may not switch off the GDPR
What this means: Providers of data about people, such as screening, background checks, registers or case law databases, cannot simply invoke the press exemption; without a genuine editorial process all GDPR rules apply, including the right to erasure and compensation. Check whether your retention and deletion policy for criminal data (Article 10) holds up. In the Netherlands too, the application of the journalistic exemption in the national implementing act must be measured against this standard.
- finalHof van Justitie van de EU (Vierde kamer), Brillen Rottler GmbH & Co. KG tegen TCC-526/24, ECLI:EU:C:2026:216
Brillen Rottler: even a first access request can be abusive if made solely to claim compensation
What this means: You may not refuse an access request lightly, but you now have a concrete defence against claim farmers, provided you substantiate the abuse with facts. Record in your access procedure how you assess and document indications of abuse, and keep handling ordinary requests within one month. Remain careful: an unjustified refusal remains an infringement that can lead to compensation.
- status not establishedRechtbank Den Haag, voorzieningenrechterECLI:NL:RBDHA:2026:4248; C/09/697042 / KG ZA 26/2
Reddit's summary proceedings against the DPA over a penalty order and legal privilege dismissed
What this means: The DPA can demand access to your internal systems during an investigation and enforce it with an order subject to a penalty. If you dispute such an order and the DPA's handling of privileged material, the route is in principle objection and appeal before the administrative court; civil summary proceedings offer no way around that. Before an investigation starts, record which documents are privileged and how you flag them.
- finalHof van Justitie van de EU (Grote kamer), WhatsApp Ireland Ltd tegen Europees Comité voor gegevensbescherming (EDPB)C-97/23 P, ECLI:EU:C:2026:81
WhatsApp v EDPB: a binding EDPB dispute resolution decision can be challenged directly before the EU courts
What this means: For organisations under the one-stop-shop mechanism there is an extra route: besides appealing the national final decision you can challenge the binding EDPB decision itself before the General Court. Watch the two month time limit after notification or publication of such a decision. This makes the EDPB's role in cross-border enforcement subject to judicial review and may affect the outcome of pending fine cases.
Guidelines
Everything in this section (26)- under consultationEuropean Data Protection Board (EDPB)Guidelines 02/2026, versie 1.0
Guidelines 02/2026 on Anonymisation
What this means: If you want to treat training data, statistics or AI output as anonymous, you must be able to show that the three criteria are met. You can do that in the simplified way, or contextually per receiving entity. The same dataset can be anonymous for one entity and personal data for another. An earlier assessment under Opinion 05/2014 does not need to be redone, but periodic reassessment is good practice. Until the final version this is a draft; comments can be submitted until 30 October 2026.
- under consultationEuropean Data Protection Board (EDPB)Guidelines 03/2026, versie 1.0
Guidelines 03/2026 on web scraping in the context of generative AI
What this means: If you scrape web data for AI yourself on the basis of legitimate interest, you must be able to demonstrate the balancing test, and it helps to exclude sources and data types you do not need, skip websites that refuse scraping and give people a way to object in advance. If you use an already scraped dataset, you as controller assess whether it can lawfully be used and must meet the accountability principle. You must actively try to keep out special category data. It is still a draft; the final text may differ.
- finalEuropean Data Protection Board (EDPB)Guidelines 02/2025, versie 2.0
Guidelines 02/2025 on processing of personal data through blockchain technologies
What this means: If you use blockchain with personal data, assess in advance whether a DPIA is mandatory (likely high risk) and justify in it why blockchain is necessary and proportionate. Design the architecture so that erasure, rectification and objection can be given effect. Establish on the facts who is controller or processor in the network and keep personal data off chain as much as possible.
- under consultationAutoriteit Persoonsgegevens (AP)Conceptlijst DPIA-uitzonderingen, consultatie AP (artikel 35 lid 5 AVG)
Consultation on the draft list of processing operations for which no DPIA is required (Dutch DPA)
What this means: Until final publication nothing changes: you still assess yourself whether a DPIA is needed. The draft covers professionals, self employed persons and employers with up to 250 employees in European Netherlands, for among others HR administration, customer data, website visits and solo healthcare providers, each under conditions. Once adopted you may skip the DPIA for those operations, but all other GDPR obligations and DPIA duties under other legislation continue to apply. Watch the Government Gazette and the DPA website for the final list.
Art. 35Autoriteit Persoonsgegevens, nieuwsbericht en consultatiedocumentchecked on 15 September 2026 - adoptedEuropean Data Protection Board (EDPB)EDPB Template for personal data breach notification v1.0
EDPB Template for personal data breach notification
What this means: You can already set up your internal breach register around the fields of the template, so a future notification to the Dutch DPA goes faster. Until implementation the current DPA notification form continues to apply. Watch the EDPB and the Dutch DPA for the implementation decision.
Enforcement
Everything in this section (17)- under appealAutoriteit PersoonsgegevensAP-persbericht 21 augustus 2026€824,990,000
Dutch DPA fines Uber 824.99 million euros for automated driver deactivation
What this means: If your software takes decisions with major effects on people, such as blocking an account or cutting off income, a human must genuinely review the decision before it takes effect. You must also clearly inform people that automated decision making is used and how it works. This is the largest fine the Dutch DPA has imposed so far, so automated decisions about people are high on its enforcement agenda.
- status not establishedAutoriteit PersoonsgegevensAP-kenmerk 2025-005323 (besluit van 1 april 2026, gepubliceerd 8 mei 2026)€100,000,000
100 million euro fine for MLU B.V. (Yango) for transfers to Russia
What this means: Transferring data to a country without an adequacy decision? Then you must be able to prove that you use a valid transfer tool. You must also be able to show that the data is equally well protected in practice. Pseudonymisation and encryption do not replace that when the recipient within the group holds the keys or has access. A legal successor remains liable for the breaches of a dissolved company. The fine can be calculated on the worldwide turnover of the whole group.
- finalAutoriteit PersoonsgegevensAP-boetebesluiten 3 februari 2026, kenmerken 2026-002523 (Tilburg), 2026-002526 (Eindhoven), 2026-002528 (Huizen), 2026-002529 (Haarlemmermeer), 2026-002530 (Ede), 2026-002531 (Veenendaal), 2026-002532 (Zoetermeer), 2026-002533 (Delft), 2026-002534 (Hilversum), 2026-002535 (Gooise Meren); persbericht 5 februari 2026€250,000
Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
What this means: Even when central government or a national coordinator urges a particular approach, the commissioning body remains the controller and needs a legal basis beforehand. Data about religion or political views may almost never be processed. Outsourcing the research to an agency changes nothing: merely keeping such a report can be a breach. Partial time bars do not prevent a fine, and the DPA can restrict any further use of such reports.
- finalAutoriteit PersoonsgegevensBoetebesluit AP, ons kenmerk 2024-024797 (besluit 15 december 2025, gepubliceerd 17 december 2025)€175,000
HAN University of Applied Sciences fined 175,000 euros for inadequate security
What this means: A data breach is not itself a violation, but missing risk assessment and inadequate measures are. A security policy on paper is not enough: least privilege and deletion policies must actually be implemented. Restrict account rights to what is needed, log and monitor database activity, purge data from retired applications and keep password hashing up to date. Actively limiting harm to data subjects, investing in security already under way and sharing lessons with others substantially reduces the fine.
- status not establishedAutoriteit PersoonsgegevensAP persbericht 18 oktober 2025; oorspronkelijk boetebesluit 2019 (gepubliceerd 3 maart 2020), besluit op bezwaar; HvJ EU C-621/22 (arrest 2024)€250,000
Dutch DPA and tennis federation KNLTB end litigation: fine cut from 525,000 to at most 250,000 euros
What this means: A commercial interest can be a legal basis, but only if the processing is genuinely necessary, the intrusion is limited and people can reasonably expect it and are properly informed. Providing member data to sponsors for payment without that test remains a breach. Admission, cooperation and remedial measures can substantially cut a fine.