MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Five years after the introduction of the GDPR (May 25, 2018), it is clear: the Netherlands issues relatively few fines, but when one is imposed, it is substantial — and the rules apply just as much to small businesses as to tech giants. It appears that SMEs, in particular, do not always comply with privacy regulations. Below is a look back at the fines and what the GDPR means for your business.
GDPR fines in perspective
The Dutch Data Protection Authority (AP) imposes relatively few fines compared to other EU countries — but when it does, they are usually substantial. Apart from the occasional fine of €7,500, they generally amount to tens of thousands of euros. Examples from recent years:
- In 2022: the police received €50,000 for the lack of a risk analysis for camera cars; DPG Media €525,000 for unnecessarily requesting proof of identity;
- in 2021: LocateFamily.com €525,000 due to the absence of a representative in the EU.
The Netherlands does not have the highest fines. That honor goes to Ireland, where tech giants like Meta are based. Because fines are linked to revenue, they run high there: an absolute record is a fine of €1.2 billion for unlawful data transfer to the United States. By comparison, the highest Dutch fine was €3.7 million for the Tax and Customs Administration. TODO_VERIFY: these fine amounts are snapshots — check the most recent figures if you use them.
The consequences for smaller businesses
Although the highest fines primarily affect large tech companies, the GDPR applies to every company that processes personal data. Research by the Dutch Consumers Association shows that smaller Dutch companies do not always comply with the rules: they do not always respond adequately to access requests and often fail to adequately warn victims in the event of data breaches. This is often because they are insufficiently familiar with the privacy rules.
That is exactly where we can help: with drafting a privacy policy, handling access requests, and responding adequately to data breaches.
Frequently Asked Questions
Does the GDPR also apply to my small business?
Yes. The GDPR applies to everyone who processes personal data, regardless of the size of the company. SMEs can also be held liable for violations.
How high can a GDPR fine be?
Up to 20 million euros or 4% of global annual turnover, depending on the violation. In the Netherlands, fines are usually lower than in countries where large tech companies are based.
What are common mistakes in SMEs?
Including, among other things, the failure to handle access requests (in a timely manner) and the insufficient informing of data subjects in the event of data breaches.
Why is GDPR compliance important, besides avoiding fines?
Good compliance strengthens your customers' trust and your reputation. Respecting privacy is also commercially valuable.
Ensure your company is GDPR-compliant
Good GDPR compliance prevents fines and strengthens customer trust. We help you navigate the complexity of privacy regulations and ensure your business stays on track.
View our privacy and data protection and our GDPR package, or schedule a no-obligation intake meeting.