MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
In 2022, the Dutch Data Protection Authority (AP) again handed out substantial GDPR fines, the heaviest being the €3.7 million fine for the Dutch Tax and Customs Administration due to the illegal FSV “blacklist.” The figures show how important it is to have your privacy affairs in order — a GDPR fine can amount to up to €20 million or 4% of global annual turnover. Below you will find the heaviest fines of 2022, a comparison with 2021, and how the AP’s fine policy works.
The heaviest GDPR fines of 2022
The AP imposed hefty fines again in 2022. The best known:
- Tax and Customs Administration – 3,700,000 euros for the FSV (Fraud Detection System) blacklist, with incorrect personal data, insufficient security, and too little involvement of the internal privacy supervisor;
- Foreign Affairs – 565,000 euros for poor security of visa applications;
- DPG Media – 525,000 euros for unnecessarily requesting proof of identity;
- Police – 50,000 euros for the lack of a risk analysis on camera cars deployed during the corona period.
Some of the fines imposed in 2022 were not yet public at the time of publication of the original overview; more may have followed.
For comparison: the fines of 2021
The AP was no stranger to this kind of thing with the multi-million euro fine for the Tax and Customs Administration. Heavy fines were also imposed in 2021:
- Tax and Customs Administration – 2.75 million euros (imposed on 7 December 2021);
- TikTok – 750,000 euros for violating children's privacy;
- Municipality of Enschede – 600,000 euros for Wi-Fi tracking;
- LocateFamily.com – 525,000 euros for the lack of a representative in the EU.
How does the AP's fine policy work?
The Dutch Data Protection Authority has various powers to safeguard privacy; imposing fines is one of them. Key features:
- a fine may amount to a maximum of 20 million euros or 4% of the worldwide annual turnover (whichever amount applies);
- Larger companies generally receive higher fines, so that they too feel the consequences of a GDPR violation;
- The Central Judicial Collection Agency (CJIB) collects the fines; the proceeds go into the treasury.
How the AP determines the amount is set out in the Dutch Data Protection Authority Fine Policy Rules 2019.These establish fine ranges per category and indicate under which category violations fall. The AP takes into account, among other things:
- the duration of the violation;
- the categories of personal data to which the infringement relates;
- the financial capacity of the offender (which may lead to mitigation).
TODO_VERIFY: The DPA updates its fine policy periodically — check the most recent fine policy rules and any new European fine guidelines.
What does this mean for your business?
The fines primarily affect large organizations, but the GDPR applies to every enterprise that processes personal data. The recurring causes — insufficient security, processing too much or incorrect data, and inadequate internal oversight — are also relevant for SMEs. Therefore, ensure:
- a proper basis and data minimization (do not request more data than necessary);
- appropriate technical and organizational security;
- proper documentation (processing register, processor agreements) and internal oversight.
Frequently Asked Questions
How high can a GDPR fine be?
Maximum of 20 million euros or 4% of global annual turnover, whichever amount is higher and which infringement is involved.
Who imposes GDPR fines in the Netherlands?
The Dutch Data Protection Authority (AP). The CJIB collects the fines on behalf of the AP.
Will SMEs also face GDPR fines?
The heaviest fines primarily affect large organizations, but the GDPR applies to anyone who processes personal data. Smaller businesses can also be held liable for violations.
What does the AP take into account regarding the amount of a fine?
Including the duration of the infringement, the type of personal data, and the financial capacity of the offender, in accordance with the Penalty Policy Rules.
Getting your privacy matters in order?
GDPR fines show that good privacy management is not a luxury. We help you make your processing, security, and documentation GDPR-compliant so that you prevent risks.
View our privacy and data protection and our GDPR package, or schedule a no-obligation intake meeting.