Seven years of GDPR-fines in the Netherlands: What have we learned?

Since the General Data Protection Regulation (GDPR) came into force in May 2018, the Dutch Data Protection Authority (DPA) has issued dozens of fines. These range from modest sums to hundreds of millions of euros, depending on the violation's scope and severity.

Privacy & AI Compliance

Privacy & AI Compliance

Seven years of GDPR-fines in the Netherlands: What have we learned?

Since the General Data Protection Regulation (GDPR) came into force in May 2018, the Dutch Data Protection Authority (DPA) has issued dozens of fines. These range from modest sums to hundreds of millions of euros, depending on the violation's scope and severity.

Privacy & AI Compliance

📅 Period: 2018 - 2024
📍 Source: Recht.nl & Dutch DPA decisions

Since the General Data Protection Regulation (GDPR) took effect in May 2018, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) has issued dozens of fines. This overview highlights the most common violations — and the key players involved.

The Heaviest GDPR Fines So Far

The data shows that international tech companies are under the most scrutiny, with Uber and Clearview topping the list. Dutch institutions such as the

Tax Authority and BKR have also faced multi-million euro penalties from the Dutch DPA.

🔍 Some standout fines:

  • Uber (US): €290 million for unauthorized data transfers to the US (2024)

  • Clearview AI: €30.5 million for unlawful processing of biometric data (2024)

  • Netflix: €4.75 million for lack of transparency about personal data processing (2024)

  • Dutch Tax Authority: two fines of €3.7 million and €2.75 million related to the FSV blacklist and child benefits discrimination scandal


🔍 Key insights:

  • Most fines were issued for inadequate security and lack of transparency.

  • Violations related to data subject rights and unlawful processing are also frequent.

  • Less frequent, but still sanctioned: tracking without consent, no DPIA, or lack of EU representation.

Why It Matters

These cases illustrate the broad scope and power of the GDPR — from hospitals and municipalities to multinational tech firms. Organizations that fail to invest in data security, transparency, or lawful processing risk serious penalties.

💬 “Compliance is not a checkbox exercise. It’s a continuous commitment.”

🔍 Key insights:

  • Most fines were issued for inadequate security and lack of transparency.

  • Violations related to data subject rights and unlawful processing are also frequent.

  • Less frequent, but still sanctioned: tracking without consent, no DPIA, or lack of EU representation.

Why It Matters

These cases illustrate the broad scope and power of the GDPR — from hospitals and municipalities to multinational tech firms. Organizations that fail to invest in data security, transparency, or lawful processing risk serious penalties.

💬 “Compliance is not a checkbox exercise. It’s a continuous commitment.”

Contact Us for a Free Consultation

Do you have a question about one of our services, or do you need advice? Get in touch with us.

Contact Us for a Free Consultation

Do you have a question about one of our services, or do you need advice? Get in touch with us.

Contact Us for a Free Consultation

Do you have a question about one of our services, or do you need advice? Get in touch with us.

Contact Us

Bakemastraat 48 3544MT Utrecht

+31-615234409

KVK: 66569346

© The Data Compliance Builders

Created by

Contact Us

Bakemastraat 48 3544MT Utrecht

+31-615234409

KVK: 66569346

© The Data Compliance Builders

Created by

Contact Us

Bakemastraat 48 3544MT Utrecht

+31-615234409

KVK: 66569346

© The Data Compliance Builders

Created by