MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Seven years after the introduction of the GDPR, it is clear that privacy legislation is not a paper tiger. The Dutch Data Protection Authority actively enforces the law and issues fines to a wide range of organizations — from tech companies to sports federations, political parties, and the government. The message: take privacy seriously.
Privacy is a powerful reality
Since 2018, the GDPR has compelled organizations to be transparent, careful, and accountable in their handling of personal data. What began as new legislation has grown into a fixed reality that every organization takes into account. Those who do not comply run a real risk.
Strict, but broad
The Dutch Data Protection Authority has by now imposed countless fines, and not only on large tech companies. Sports federations, political parties, hospitals, webshops, and even government agencies have also been fined. This shows that the rules apply to everyone and that the regulator enforces them broadly.
What is fined?
Common causes include insufficient security leading to a data breach, processing data without a legal basis, excessive access to personal data, failure to report data breaches or reporting them too late, and insufficient notification of data subjects. Each of these can be prevented with proper measures.
What does this mean for your organization?
Do not treat privacy as an afterthought. Map out your processing activities, ensure a legal basis and appropriate security, maintain a processing register, enter into data processing agreements, and establish a process for data breaches and requests. This way, you comply with the GDPR and limit the risk of fines and damage claims.
Frequently Asked Questions
Does the Dutch Data Protection Authority really enforce the rules?
Yes, actively and broadly: from tech companies to sports federations, political parties, and the government have been fined.
For what do organizations receive fines?
Among other things for poor security, processing without a legal basis, excessive access, and unreported data breaches.
How do I reduce my risk?
With a legal basis, security, a processing register, processor agreements, and a sound data breach and request process.
Is your privacy demonstrably in order?
Our legal experts conduct a privacy scan and bring your data processing operations into compliance. View our privacyteam or schedule a free consultation.