GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Dutch DPA

Country
Netherlands
Fine
7,500 EUR
Date
2021-05-11
Sector
Dutch Political Party
Articles
Art. 33(1) GDPR

Not reporting a data breach, which leaked people's political views. In the event of a serious data breach, a reporting obligation applies.

The Dutch Data Protection Authority (AP) imposes a fine of 7,500 euros on the Party for Freedom (PVV) Overijssel. The PVV Overijssel receives this fine because the party has not reported a data breach to the AP. This data breach has leaked people's political views. The data breach originated via an e-mail about a grassroots meeting. In it, 101 addressees were referred to as 'friends of the PVV'. Due to a mistake by a group employee, the e-mail addresses (and therefore usually the names) of the recipients were visible to everyone who received the invitation. As a result, the political views of the addressees are shared.

Additional information

In this case according to the principle of proportionality the AP considers the financial capacity of the PVV Overijssel limited and concludes that the PVV Overijssel cannot financially bear the fine of € 525,000. On this basis, the AP sees reason to reduce the fine. The AP considers a fine of € 7,500 appropriate in this case. The PVV Overijssel does indicate that it has taken measures to prevent such a data breach in the future.