Skip to main content
Praxikon

Ruling

Overijssel District Court revokes DPA fine for wifi tracking in Enschede

Date
Status
final
Body
Rechtbank Overijssel
Reference
ECLI:NL:RBOVE:2024:594 (zaaknummer ZWO 22/775)
Amount
€600,000

What it is about

The court upheld the municipality of Enschede's appeal, annulled the objection decision of 6 April 2022 and revoked the fine decision of 11 March 2021 (a fine of 600,000 euros for processing without a legal basis, Article 5(1)(a) read with Article 6(1) GDPR). The DPA had not sufficiently investigated or proven that natural persons were identifiable through hashed and truncated MAC addresses combined with location data, as recital 26 GDPR requires. The Council of State confirmed this ruling on 29 July 2026 (ECLI:NL:RVS:2026:4403).

What this means in practice

Whether pseudonymised or hashed identifiers are personal data depends on concrete evidence of identifiability in your setting, assessed against the means reasonably likely to be used under recital 26 GDPR; for a fine, the regulator must deliver that evidence in the decision itself. Record yourself which steps you take to rule out identification. The Council of State left open whether counting unique visitors via MAC addresses is in itself direct identification, so counting with MAC addresses remains risky.

The GDPR articles concerned

Source: Rechtspraak.nlchecked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

The counterpart in the other law

Case law8 of 14

Guidelines8 of 13

Enforcement and fines8 of 11

Legislation in motion6 of 10