Law / Netherlands

AP Enforcement, GDPR Article 82 and the WAMCA Collective-Action Regime

Regulation (EU) 2016/679, Arts. 82-83; UAVG, Arts. 16-18; Wet Afwikkeling Massaschade in Collectieve Actie (WAMCA)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • Expect the AP to have General Data Protection Regulation (GDPR) Article 83 fining power, plus UAVG's own administrative powers, over your processing of personal data of a person in the Netherlands.
  • Expect any person in the Netherlands who suffered material or non-material damage from an infringement to have a direct GDPR Article 82 right to compensation, potentially pursued as part of a WAMCA collective action.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

GDPR Article 83(5) sets the higher fine tier, up to EUR 20,000,000 or 4% of total worldwide annual turnover, applied directly by the Autoriteit Persoonsgegevens under UAVG Article 14(1). UAVG Article 17 additionally lets the AP impose an administrative fine at the same ceiling for unlawful processing of the criminal-conviction-and-offence-data category (GDPR Article 10, UAVG Article 31); despite its heading naming data of a criminal-law nature, Article 17 authorises an administrative fine only, not a criminal-law penalty on the controller. UAVG Article 18 confirms the AP may fine a government authority or public body at the same GDPR Article 83(4) to (6) tiers as a private undertaking, unlike some other member states that cap public-sector fines lower.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Autoriteit Persoonsgegevens (AP), the Netherlands' supervisory authority under the GDPR and the Uitvoeringswet AVG.

Enforcement record

Counts the Autoriteit Persoonsgegevens' own enforcement-file table for calendar year 2024 (Jaarverslag AP 2024, published 2025-03-14): 6 boetes (fines), down from 8 in 2023, alongside 4 last onder dwangsom (periodic penalty orders), 7 berispingen (reprimands) and 4 nacontrole en invordering (post-check and collection) actions. Named amounts for 3 of the 6 fines are disclosed in the same report (two separate Uber fines of EUR 10,000,000 and EUR 290,000,000, and a Netflix fine of EUR 4,750,000), a known partial total of at least EUR 304,750,000; the report explains organisations frequently contest publication of their sanction decision and the AP withholds a decision until that publication procedure concludes, so the remaining three fines are unnamed and fines_per_year is not recorded as a computed total. Public enforcement actions only; no private WAMCA claim count is published by the AP.

As of
2 September 2026
Trend
Falling
Currency
EUR
Source link
https://www.autoriteitpersoonsgegevens.nl/system/files?file=2025-03%2FJaarverslag+AP+2024.pdf
Actions per year
6

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Autoriteit Persoonsgegevens (AP) is the Dutch supervisory authority, with General Data Protection Regulation (GDPR) Article 83 fines plus UAVG's own administrative powers including a fine specific to unlawful processing of criminal-conviction data (Art. 17) and administrative fines against government bodies (Art. 18).

GDPR Article 82 arms an individual with a direct private right of action, and the Netherlands' WAMCA collective-action regime is a live vehicle for privacy mass claims: a Consumentenbond and Stichting Take Back Your Privacy claim against TikTok, over unauthorized collection of children's personal data, is currently paused pending a Hoge Raad ruling in a related Oracle/Salesforce case expected 4 September 2026.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice
  • high_risk_decisions

Read the law

GDPR Arts. 82-83
UAVG Arts. 6-21a, 16-18 (table of contents); Consumentenbond TikTok case page

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app