Ruling
Interim judge suspends DPA penalty order against Northwave: exhaust powers against the hosting provider first
- Date
- Status
- final
- Body
- Rechtbank Midden-Nederland, voorzieningenrechter (zittingsplaats Utrecht)
- Reference
- ECLI:NL:RBMNE:2024:1804; zaaknummer UTR 24/885
What it is about
A large hosting provider reported a data breach in August 2023 and hired Northwave to investigate. The DPA demanded the investigation report from the provider, which in the DPA's view did not fully comply. The DPA then demanded the information from Northwave itself and imposed a penalty order in February 2024. The interim judge held that under Article 58(1)(a) GDPR the DPA must first address the party the obligation applies to, here the hosting provider. The DPA had not exhausted its powers against the provider and never imposed the penalty order it had threatened. Demanding information from a third party outside the DPA's supervision was therefore not reasonably necessary (Article 5:13 of the Dutch General Administrative Law Act, subsidiarity). The order was suspended until two weeks after the decision on the objection; the DPA must reimburse court fees and legal costs.
What this means in practice
The DPA must first seek information from the controller or processor itself and exhaust its powers there before using enforcement tools against a supplier or adviser. Incident response and forensic firms can challenge an information demand if the DPA has not yet used its powers against the supervised organisation. This is a provisional view, and the controller itself must still hand over investigation reports when demanded. Agree contractually who reports to the DPA and how investigation reports are handled.
The GDPR articles concerned
Source: Rechtspraak.nlchecked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
- Article 3 AI Act: Definitions
- Article 26 AI Act: Obligations of deployers of high-risk AI systems
- Article 70 AI Act: Designation of national competent authorities and single points of contact
- Article 73 AI Act: Reporting of serious incidents
- Article 74 AI Act: Market surveillance and control of AI systems in the Union market
- Article 99 AI Act: Penalties
Case law
- Reddit's summary proceedings against the DPA over a penalty order and legal privilege dismissed
2026-03-04 · status not established, Rechtbank Den Haag, voorzieningenrechter
- Deutsche Wohnen: a fine on a legal person needs no identified natural person, but does require fault
2023-12-05 · final, Hof van Justitie van de EU (Grote kamer), Deutsche Wohnen SE tegen Staatsanwaltschaft Berlin
- Land Hessen: the supervisory authority need not always fine where the organisation already remedied the breach
2024-09-26 · final, Hof van Justitie van de EU (Eerste kamer), TR tegen Land Hessen
- Schrems II: Privacy Shield invalid, transfers under standard clauses only with essentially equivalent protection
2020-07-16 · final, Hof van Justitie van de EU (Grote kamer), Data Protection Commissioner tegen Facebook Ireland Ltd en Maximillian Schrems
- Council of State: DPA could fine DPG Media for routinely demanding ID copies, fine halved to 262,500 euros
2025-09-24 · final, Raad van State, Afdeling bestuursrechtspraak
Guidelines
- EDPB Template for personal data breach notification
2026-06-10 · adopted, European Data Protection Board (EDPB)
- Consultation on the Dutch DPA's enforcement policy (April 2026)
2026-04-13 · under consultation, Autoriteit Persoonsgegevens
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
2021-12-14 · final, European Data Protection Board (EDPB)
- Guidelines 9/2022 on personal data breach notification under GDPR
2023-03-28 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
Enforcement and fines
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Formal warning to the Dutch Minister of Education, Culture and Science not to put the CABR war archive online and searchable
2024-11-26 · final, Autoriteit Persoonsgegevens
Legislation in motion
- Amendment to the Dutch GDPR Implementation Act: DPA must publish GDPR sanctions from 1 September 2026
2026-09-01 · in force, Wetgever (Tweede Kamer) en Autoriteit Persoonsgegevens
- Proposal: breach notification only for high risk, within 96 hours, via a single entry point (Article 33 GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie