Privacy

Five years of GDPR: a look back at fines and compliance

Five years after the introduction of the GDPR (May 25, 2018), it is clear: the Netherlands issues relatively few fines, but when one is imposed, it is substantial — and the rules apply just as much to...

Published on July 3, 2023 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

Five years after the introduction of the GDPR (May 25, 2018), it is clear: the Netherlands issues relatively few fines, but when one is imposed, it is substantial — and the rules apply just as much to small businesses as to tech giants. It appears that SMEs, in particular, do not always comply with privacy regulations. Below is a look back at the fines and what the GDPR means for your business.

GDPR fines in perspective

The Dutch Data Protection Authority (AP) imposes relatively few fines compared to other EU countries — but when it does, they are usually substantial. Apart from the occasional fine of €7,500, they generally amount to tens of thousands of euros. Examples from recent years:

  • In 2022: the police received €50,000 for the lack of a risk analysis for camera cars; DPG Media €525,000 for unnecessarily requesting proof of identity;
  • in 2021: LocateFamily.com €525,000 due to the absence of a representative in the EU.

The Netherlands does not have the highest fines. That honor goes to Ireland, where tech giants like Meta are based. Because fines are linked to revenue, they run high there: an absolute record is a fine of €1.2 billion for unlawful data transfer to the United States. By comparison, the highest Dutch fine was €3.7 million for the Tax and Customs Administration. TODO_VERIFY: these fine amounts are snapshots — check the most recent figures if you use them.

The consequences for smaller businesses

Although the highest fines primarily affect large tech companies, the GDPR applies to every company that processes personal data. Research by the Dutch Consumers Association shows that smaller Dutch companies do not always comply with the rules: they do not always respond adequately to access requests and often fail to adequately warn victims in the event of data breaches. This is often because they are insufficiently familiar with the privacy rules.

That is exactly where we can help: with drafting a privacy policy, handling access requests, and responding adequately to data breaches.

Frequently Asked Questions

Does the GDPR also apply to my small business?

Yes. The GDPR applies to everyone who processes personal data, regardless of the size of the company. SMEs can also be held liable for violations.

How high can a GDPR fine be?

Up to 20 million euros or 4% of global annual turnover, depending on the violation. In the Netherlands, fines are usually lower than in countries where large tech companies are based.

What are common mistakes in SMEs?

Including, among other things, the failure to handle access requests (in a timely manner) and the insufficient informing of data subjects in the event of data breaches.

Why is GDPR compliance important, besides avoiding fines?

Good compliance strengthens your customers' trust and your reputation. Respecting privacy is also commercially valuable.

Ensure your company is GDPR-compliant

Good GDPR compliance prevents fines and strengthens customer trust. We help you navigate the complexity of privacy regulations and ensure your business stays on track.

View our privacy and data protection and our GDPR package, or schedule a no-obligation intake meeting.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

July 25, 2026

IT contracts for SMEs: which ones do you need?

IT contracts for SMEs: SLA, Data Processing Agreement/DPA, SaaS, licensing, maintenance, and development. What each is for and how they relate.

July 24, 2026

Having general terms and conditions drafted for the website: costs and process

Having general terms and conditions for the website drafted by a lawyer: what does it cost, how does the process work, and when should you choose custom-made...

July 24, 2026

Having a non-compete clause drafted: costs and process

Having a non-compete clause drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom draft over a template.

July 24, 2026

Checking contracts: step-by-step plan for SME entrepreneurs

Checking or reviewing a contract before signing: step-by-step plan, red flags, checklist, and when you need a lawyer.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation