The Dutch Data Protection Authority: tasks, powers and complaints

Office space with security cameras on wall

The Autoriteit Persoonsgegevens (AP) is the Dutch Data Protection Authority: the independent supervisory authority that enforces the GDPR in the Netherlands. It was established by the GDPR Implementation Act (Uitvoeringswet AVG), which designates it as the supervisory authority referred to in article 51 of the GDPR and gives it legal personality. The AP supervises organisations in the public and private sector, handles complaints from individuals, receives data breach notifications and can impose orders and fines.

What the AP is not is a court. It does not settle disputes between an individual and a company, and it cannot award compensation; those routes run through the civil courts and follow their own deadlines. This article sets out the AP’s tasks and powers, how a complaint works in practice, what happens if the AP starts an investigation into your organisation, and how supervision by the AP relates to proceedings before the courts.

What the AP is and where its powers come from

The AP is an independent administrative body. Its independence is required by the GDPR itself and worked out in the Implementation Act: the government cannot instruct it on individual cases, and its board members are appointed for a fixed term. At the same time it is an administrative authority in the Dutch sense, which means the General Administrative Law Act governs how it prepares and takes decisions, and how those decisions can be challenged.

Its remit is wider than the GDPR alone. Alongside the GDPR and the Implementation Act, the AP supervises specific data protection legislation, including the rules on police and judicial data, and it grants the licences that private parties need for certain warning lists and registers containing criminal-law data. It also has a coordinating role in the supervision of algorithms, and further tasks in the field of artificial intelligence follow from the national designation of supervisory authorities under the European AI Regulation, which is laid down in implementing legislation.

Territorially, the AP supervises processing carried out by organisations established in the Netherlands, and processing directed at people in the Netherlands by organisations established outside the European Union. Where the latter offer goods or services to, or monitor the behaviour of, people in the Union, they must designate a representative in the Union. The absence of such a representative has been an independent ground for enforcement by the AP in practice.

What the AP does: supervision, guidance and licences

Article 57 of the GDPR lists the tasks of every supervisory authority, and the AP’s work follows it closely. It monitors and enforces application of the GDPR, promotes public awareness, advises the government and parliament on legislation affecting personal data, handles complaints, cooperates with the other European authorities, and publishes guidance on how the rules should be applied in practice. Its guidance is not legislation, but it does show how the regulator will approach a case, which makes it worth reading before designing a processing operation rather than afterwards.

Two specific functions deserve mention because they involve going to the AP in advance rather than being called to account afterwards. The first is prior consultation: where a data protection impact assessment shows a high residual risk that the controller cannot mitigate, article 36 of the GDPR requires the controller to consult the AP before processing starts. The second is the licence regime for certain warning lists, under which private parties may only share information on, for example, fraud, if the AP has authorised the arrangement.

The AP’s powers: investigation and correction

Article 58 of the GDPR divides the AP’s powers into two groups, and the difference matters for how you respond. The investigative powers allow the AP to order a controller or processor to provide information, to carry out audits and reviews, to obtain access to personal data and to premises and equipment. Cooperation is compulsory, and in a Dutch setting the general rules on supervision in the General Administrative Law Act fill in how inspectors exercise those powers.

The corrective powers run from light to heavy. The AP can issue a warning that intended processing is likely to infringe the rules, or a reprimand where processing has infringed them. It can order a controller to comply with a data subject’s request, to bring processing into line with the GDPR within a specified period, or to inform individuals of a data breach. It can impose a temporary or definitive limitation on processing, including a ban, and it can order the suspension of data transfers to a country outside the Union. Finally, it can impose an administrative fine, either instead of or in addition to any of these measures.

Two features of the Dutch practice are worth knowing. An order is usually combined with a periodic penalty payment, so that continued non-compliance costs money automatically without a new decision being needed. And the level of a fine is not chosen freely: the GDPR sets the statutory maximum and the AP has published fining policy rules that place a violation in a category and set a bandwidth within it, taking into account seriousness, duration, intent, the number of people affected and cooperation with the investigation. Because a fine is a punitive sanction, the safeguards described below apply from the moment the AP starts asking questions. Our article on the administrative fine in the Netherlands explains that regime in general terms.

Filing a complaint with the AP

Article 77 of the GDPR gives every person the right to lodge a complaint with a supervisory authority if they consider that the processing of their personal data infringes the rules. In the Netherlands that authority is the AP, and complaints are submitted through its own complaint channel.

The sequence that produces results is straightforward. Put the request or objection to the organisation itself first, in writing, and identify the right you are invoking; the organisation must respond without undue delay and in principle within one month. Keep everything: the request, the reply, the dates, the privacy notice as it stood at the time and any screenshots. Then submit the complaint, describing who processed what data, when, which right was infringed and what the consequence was for you. A complaint that sets out documents and dates is assessed far more quickly than one that describes a feeling of unease.

Be realistic about what follows. The AP receives far more complaints than it can investigate individually and selects on the basis of published priorities, so a complaint may be registered as a signal rather than result in an investigation. It cannot order the organisation to pay you compensation, and it does not act as your representative. What it can do is order the organisation to comply, and a well-documented complaint about a structural problem is the type of case that leads to supervision. Under article 78 of the GDPR you are entitled to be informed of the progress or the outcome of your complaint within three months, and if the AP fails to act you can take that failure to court.

Reporting a data breach to the AP

A personal data breach must be notified to the AP without undue delay and, where feasible, within seventy-two hours of the controller becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals (article 33 of the GDPR). If the breach is likely to result in a high risk, the individuals concerned must be informed as well, in clear language and without undue delay (article 34). Every breach must be recorded internally, whether or not it is notified, and that register is the first thing the AP asks for.

Three practical points decide how these cases go. The seventy-two hours run from awareness, not from the moment the investigation is complete; an incomplete notification that is supplemented later is better than a late one. The assessment of risk must be documented, because a decision not to notify has to be justified afterwards. And where the organisation has a main establishment elsewhere in the Union, the notification goes to the lead authority of that country rather than to the AP. A processor that discovers a breach must inform its controller without undue delay, which is why the data processing agreement should set an internal deadline that is shorter than the statutory one.

If the AP starts an investigation into your organisation

An investigation usually begins with a written request for information rather than with inspectors at the door. Answer it accurately and on time, and keep the response consistent with your own documentation; contradictions between what you write and what your records show cause more damage than the original shortcoming. Appoint one person to coordinate, normally the data protection officer, and keep a log of what was provided and when.

The safeguards that apply are those of Dutch administrative law. Before the AP takes a decision that is adverse to you, it must give you the opportunity to be heard and to see the report of findings on which it relies. Where the AP is considering a punitive sanction such as a fine, the person questioned is not obliged to make statements about the alleged infringement and must be cautioned to that effect; that right belongs to the organisation being investigated as well. The burden of proving the infringement lies with the AP.

Once a decision has been taken, the clock starts. You have six weeks to lodge a notice of objection with the AP, and a further six weeks to appeal to the district court against the decision on that objection, with a final appeal to the Administrative Jurisdiction Division of the Council of State. In urgent cases, for example where a processing ban would halt operations, a provisional measure can be requested from the court alongside the objection. Publication is a separate consideration: the AP publishes its enforcement decisions, and the timing of that publication can itself be challenged.

The AP and the courts: two separate routes

Supervision by the AP and proceedings before a court are parallel routes, not stages of the same process, and choosing the wrong one costs time and sometimes the claim itself.

Where a private organisation refuses or ignores a request to exercise your rights, the GDPR Implementation Act provides a specific procedure: the data subject can apply to the district court by petition, and must do so within six weeks of receiving the controller’s answer. That period is short and is easily missed while a complaint to the AP is still pending, because a complaint to the AP does not extend it. Where the organisation is an administrative body, its decision on a rights request is an administrative decision, so the objection and appeal route of the General Administrative Law Act applies instead.

Compensation is exclusively a matter for the courts. Article 82 of the GDPR gives a right to compensation for material and non-material damage caused by an infringement, and such claims are brought before the civil court; Dutch courts award modest sums for non-material damage and require the claimant to show concrete adverse consequences rather than mere upset. The AP plays no role in that claim, although its findings can be used as evidence. Conversely, a decision of the AP on your complaint, including a decision to take no action, is itself an administrative decision that can be challenged through objection and appeal.

Cross-border cases and the one-stop-shop

Where processing affects people in more than one member state, the GDPR assigns the leading role to the supervisory authority of the country in which the organisation has its main establishment. If that is the Netherlands, the AP acts as lead authority and coordinates with the other authorities concerned; if it is elsewhere, the AP participates as a concerned authority and can require that its objections be taken into account. Disagreements between authorities are resolved by the European Data Protection Board, whose binding decisions have decided several high-profile cases.

For organisations, the consequences are practical. Establish which authority is your lead authority before an incident occurs, and record the reasoning, because a main establishment is where decisions on the purposes and means of processing are actually taken, not where the group happens to be registered. Notify breaches to that authority. And do not assume that having a lead authority elsewhere puts the AP out of the picture: it retains powers in respect of processing that is not cross-border, and in respect of establishments in the Netherlands.

Preparing for the AP’s attention

Most enforcement follows a pattern: a complaint or a breach notification draws attention to an organisation, and the questions that follow are about accountability rather than about the incident alone. The file that answers them is the same file you should have anyway. It records the purposes and legal bases for each processing operation, the retention periods and how they are enforced, the privacy information actually shown to people, the technical and organisational security measures and who has access to what, the impact assessments carried out for high-risk processing, the processing agreements with suppliers, the safeguards used for transfers outside the Union, and the register of breaches and rights requests with the dates on which they were answered.

Two things make the difference in practice. The first is a working process for rights requests, with a log and a standard response, because failing to answer within a month is the most common reason for a complaint. The second is a privacy statement that matches what actually happens in the organisation. Regulators do not need an investigation to see a discrepancy between a published statement and a cookie banner or an app permission; that is what they look at first. Further material on this area is collected in our IT law guides, and the AP publishes its own guidance and forms on its website.

Law & More advises organisations and individuals on dealings with the Autoriteit Persoonsgegevens: complaints, breach notifications, requests for information, objections and appeals against orders and fines, and the parallel proceedings before the civil and administrative courts. If the AP has approached you, or you want to know whether a complaint is the right route in your case, the privacy lawyers at Law & More are happy to advise.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

Cybersecurity is no longer purely a technical matter. It is also a legal and governance

Dutch law takes a two-sided approach to keeping customer data. Business records like financial documents

Copyright on AI-generated content only exists under Dutch law if a human made creative choices

The orientation year permit (zoekjaar hoogopgeleiden) gives recent graduates and researchers twelve months of free

To get to grips with biometric data and GDPR compliance, we first need to answer

E-commerce legal requirements in the Netherlands come from three layers of rules: the identification and

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.