Skip to main content
Praxikon

Ruling

Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros

Date
Status
status not established
Body
Rechtbank Gelderland
Reference
ECLI:NL:RBGEL:2025:6547 (zaaknummer ARN 22/4633)
Amount
€58,125

What it is about

At the auction of a bankrupt healthcare foundation's estate, the trustee sold a server whose hard drive held large amounts of (special category) personal data on clients and staff, including citizen service numbers, salary and medical data. On 9 December 2021 the DPA fined the trustee 310,000 euros for breaching Article 5(1)(f) with Article 32(1) and (2) GDPR, and on objection reduced the fine to 148,750 euros on 25 August 2022. The court held that the trustee in that capacity is the controller because he could reasonably access the data, and that the fine was justified. It reduced the fine to 58,125 euros for reduced culpability and excessive length of proceedings.

What this means in practice

Whoever gains actual control over data carriers, such as a bankruptcy trustee, becomes the controller and must arrange security, including when selling hardware. Inventory all data carriers and wipe or destroy them verifiably before equipment leaves. Instructing an auction house to remove drives is not enough without checking. Fines for security failures are reduced for lower culpability, not removed.

The GDPR articles concerned

Source: Rechtspraak.nlchecked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

The counterpart in the other law

Case law8 of 13

Guidelines8 of 14

Enforcement and fines8 of 11

Legislation in motion6 of 8