Skip to main content
Praxikon

Ruling

Interim judge suspends DPA penalty order against Northwave: exhaust powers against the hosting provider first

Date
Status
final
Body
Rechtbank Midden-Nederland, voorzieningenrechter (zittingsplaats Utrecht)
Reference
ECLI:NL:RBMNE:2024:1804; zaaknummer UTR 24/885

What it is about

A large hosting provider reported a data breach in August 2023 and hired Northwave to investigate. The DPA demanded the investigation report from the provider, which in the DPA's view did not fully comply. The DPA then demanded the information from Northwave itself and imposed a penalty order in February 2024. The interim judge held that under Article 58(1)(a) GDPR the DPA must first address the party the obligation applies to, here the hosting provider. The DPA had not exhausted its powers against the provider and never imposed the penalty order it had threatened. Demanding information from a third party outside the DPA's supervision was therefore not reasonably necessary (Article 5:13 of the Dutch General Administrative Law Act, subsidiarity). The order was suspended until two weeks after the decision on the objection; the DPA must reimburse court fees and legal costs.

What this means in practice

The DPA must first seek information from the controller or processor itself and exhaust its powers there before using enforcement tools against a supplier or adviser. Incident response and forensic firms can challenge an information demand if the DPA has not yet used its powers against the supervised organisation. This is a provisional view, and the controller itself must still hand over investigation reports when demanded. Agree contractually who reports to the DPA and how investigation reports are handled.

The GDPR articles concerned

Source: Rechtspraak.nlchecked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

Case law

Guidelines

Legislation in motion