In our February newsletter, you will find the following topics: |
|
|
|
|
|
|
|
Ten municipalities fined for unlawful processing of special categories of personal data |
On 3 February, the Dutch Data Protection Authority (DDPA) published ten separate fining decisions. The trigger was the use of so‑called “power field analyses” (krachtenveldanalyses) and quick scans of local Islamic communities.
These analyses were used between 2017 and 2021 as part of local counter‑radicalisation strategies, often on the advice of the National Coordinator for Counterterrorism and Security (NCTV). The assessments mapped social structures, key figures, and internal dynamics within Muslim communities.
The DDPA found that municipalities not only received these documents but also stored, consulted, and shared them. The documents contained between 16 and 266 personal dossiers per municipality, including personal profiles with data relating to religious belief, ethnic origin, family relations, social roles, and in several cases also criminal data. In none of the cases could the municipality identify a specific statutory obligation or sufficiently defined public task that made the processing of these data necessary.
The DDPA emphasises that municipalities, even in a politically and administratively complex context, remain bound by the principle of data minimisation and the prohibition on processing special categories of personal data unless a limitative exception under the GDPR applies. Publicly available social media data could, in some cases, fall under an exception, but this did not apply to the compiled information and interpretations drawn from non‑public sources, which formed the core of the analyses.
As aggravating circumstances, the DDPA notes the nature and sensitivity of the data processed, the policy context of security and radicalisation, the absence of an explicit mandate, and the significant impact on the affected Muslim communities. At the same time, the regulator observes that many violations occurred in the past and that most municipalities have since taken steps to rebuild relationships with local communities.
The DDPA concludes that, in all cases, municipalities processed personal data and special categories of personal data without a lawful basis or applicable exception under the GDPR. Each municipality receives an administrative fine of €25,000 and - in most cases - an additional requirement to retain the documents solely for the purpose of facilitating data subject rights (such as access requests) and for use in legal proceedings. |
|
|
|
| |
|
|
Over 6 million Odido users victim of largescale data breach |
On 8 February, Odido announced that a significant cyberattack had occurred, resulting in personal data being leaked from its customer contact system. The incident concerns data relating to both current and former customers. The AP is monitoring the handling of the incident.
The attackers obtained employee login credentials through phishing. They then bypassed a second authentication step by impersonating Odido’s IT department over the phone, gaining access to Odido’s Salesforce environment where customer data are stored.
The attackers downloaded large volumes of data automatically. According to Odido, this includes personal data such as full name, address, telephone number, customer number, email address, IBAN, date of birth, and identification‑document numbers for approximately 6.2 million customer accounts. Passwords, billing and call records, and BSN numbers were not leaked, according to Odido. The company stresses that operational services were not disrupted and that external cybersecurity experts have been engaged.
The breach may have significant consequences for those affected. The combination of contact and identification data can enable convincing phishing and social engineering attacks. Odido advises customers to remain alert to unexpected communications, refrain from sharing confidential information, and check invoices carefully. The NOS reported on 24 February that cybercriminals claiming responsibility for the Odido hack are threatening to publish the stolen data on the dark web. |
|
|
|
| |
|
|
Binding EDPB decisions can be challenged by organisations |
On 10 February, the Court of Justice of the European Union (CJEU) issued an important judgment concerning binding decisions of the European Data Protection Board (EDPB) and the availability of annulment actions against such decisions.
The judgment resolves an appeal brought by WhatsApp against EDPB Binding Decision 1/2021 of 28 July 2021. The decision was issued under the GDPR dispute‑resolution mechanism after several supervisory authorities raised objections to a draft decision by the Irish Data Protection Commission (DPC). The EDPB required the DPC to identify additional infringements, including violations of the transparency principle, and to consider imposing higher fines.
The CJEU emphasises that an EDPB decision constitutes a definitive act of an EU body that produces binding legal effects for the supervisory authorities involved. A binding EDPB decision obliges all relevant authorities to base their final decisions on it. Therefore, it meets the criteria for a legally binding act that may be challenged under Article 263 TFEU. The fact that the decision is not formally addressed to the controller is irrelevant. What matters is that the EDPB decision directly affects WhatsApp’s legal position, for example by qualifying certain data as personal data and by mandating the establishment of additional GDPR infringements. WhatsApp is both individually and directly concerned.
The binding nature of the EDPB decision leaves the DPC with no discretion regarding the matters submitted to the EDPB. As such, the decision requires no further implementing measures, meaning it directly affects the controller’s legal position. The fact that the DPC formally issues the final fine decision does not change this: the EDPB dictates, in a legally binding manner, which infringements must be found.
This judgment has significant consequences for cross‑border GDPR enforcement. Controllers may directly challenge binding EDPB decisions that affect them. The CJEU confirms that the GDPR consistency mechanism is not merely an internal coordination tool for regulators but a safeguard ensuring uniform application of EU law, with the EDPB operating as an EU body capable of issuing binding acts subject to judicial review. This may lead to parallel proceedings: one before the CJEU against the EDPB decision, and one before national courts against the final decision of the lead authority. |
|
|
|
| |
|
|
Belgian Court of Cassation confirms possibility of symbolic GDPR fines |
On 10 February, the Belgian Court of Cassation issued a judgment in a case between the Belgian Data Protection Authority (BDPA) and the National Railway Company of Belgium (NMBS). Central to the case was whether a symbolic fine of one euro is compatible with the GDPR’s requirements of effectiveness and deterrence, and whether the Belgian Market Court had the power to impose such a fine itself.
The case arose from the distribution of the “Hello Belgium Railpass” in 2020. The NMBS sent millions of applicants an email about using the pass and their travel destinations. The BDPA’s Inspection Service concluded that the NMBS lacked a valid legal basis for this email activity and had not adequately facilitated the right to object. The Litigation Chamber therefore imposed a fine of €10,000 on 4 May 2022 for violations of Articles 5, 6, 12 and 21 GDPR. The Market Court partially annulled the sanction and reduced the fine, citing mitigating circumstances, to a symbolic fine of EUR 1.
In cassation, the BDPA argued that the Market Court exceeded its powers and should have annulled and remitted the case rather than setting a new fine. It also argued that a symbolic sanction is incompatible with the GDPR’s effectiveness and deterrence requirements.
The Court of Cassation rejected both arguments. It held that the Market Court exercises “full jurisdiction” in GDPR appeal cases. This means that the Market Court may assess both legality and proportionality and may adjust the fine if necessary. The Market Court may therefore substitute its own decision for that of the BDPA.
The Court of Cassation also confirmed that the GDPR does not prescribe minimum fines and that symbolic sanctions are not excluded. A fine of EUR 1 may still be effective, proportionate and deterrent depending on the circumstances. The assessment is case‑specific, and supervisory and judicial authorities must consider all relevant facts.
The judgment underscores that, within the Belgian enforcement model, judicial review of GDPR decisions involves a full reassessment of sanctions. For organisations, this means the Market Court has broad discretion to adjust fines and that even low or symbolic fines are legally permissible if properly reasoned. Within the Dutch enforcement model, full judicial review of a DDPA decision can also take place: Dutch courts both assess whether the DDPA rightfully imposed a fine in the specific case, and also whether the fining amount is proportionate, A Dutch court can adjust the fine if it deems this necessary. |
|
|
|
| |
|
|
EDPB and EDPS publish joint opinion on the Digital Omnibus proposal |
On 10 February, the EDPB and the European Data Protection Supervisor (EDPS) published a second joint opinion on the proposed Digital Omnibus Regulation (the Opinion). The proposal contains extensive amendments to EU digital legislation, including the GDPR, the ePrivacy Directive and the Data Act.
The Opinion stresses that several proposed amendments to the GDPR framework go beyond mere technical adjustments. The authorities strongly criticise the proposed change to the definition of “personal data.” The amendment to Article 4(1) GDPR would mean that data are no longer considered personal data for a controller that cannot identify individuals itself, even if another party could. According to the EDPB and EDPS, this contradicts established CJEU case law, including the SRB ruling from last year, which confirmed that data must be treated as personal data if the recipient has reasonable means to identify the data subject. The authorities warn that the change would significantly narrow the GDPR’s scope and could invite circumvention. They recommend removing the amendment entirely. The Council has supposedly also deleted the amendment to Article 4(1) of the GDPR in its negotiating proposal.
The authorities also raise concerns about pseudonymisation. Allowing the Commission to determine, via implementing acts, when pseudonymised data are no longer personal data is deemed incompatible with the GDPR’s institutional structure. Determining whether data are personal data is a core GDPR concept that must remain under the supervision of national regulators and the CJEU. Such a power shift could create legal uncertainty.
The Opinion is more positive about other elements of the proposal. The EDPB and EDPS support adding a definition of scientific research, clarifying the application of Article 6(4) GDPR to further processing, and introducing new exceptions to information obligations in research contexts. They also welcome the proposed exception for processing biometric data for verification, provided that templates remain under the exclusive control of the data subject and the necessity test is strictly applied. They further support measures to reduce administrative burdens, such as a higher threshold for breach notifications, extending the notification deadline to 96 hours, and introducing joint templates for breach notifications and DPIAs, while emphasising the need for a strong role for the EDPB in drafting these templates.
In the field of ePrivacy, the EDPB and EDPS support efforts to reduce cookie fatigue, including through machine‑readable preference signals. At the same time, they warn of inconsistencies arising from overlapping regulatory regimes governing access to terminal equipment. They call for clear boundaries, limited exceptions and strong supervisory safeguards. Regarding the Data Act, they welcome the integration of the Data Governance Act and the Open Data Directive but recommend maintaining pseudonymisation requirements for data transfers in emergencies, clarifying oversight structures, and strengthening information sharing between authorities. |
|
|
|
| |
|
|
DDPA warns of serious security risks from autonomous AI agents such as openclaw |
On 12 February, the DDPA issued a warning about the use of OpenClaw and similar autonomous AI assistants. The warning follows the rapid rise of these open‑source systems, which often fail to meet basic security standards and pose significant risks to the protection of personal data.
OpenClaw allows users to install a local AI assistant that autonomously executes tasks on the user’s computer. This means the assistant gains full access to computer systems, files, email accounts and linked online services without requiring prior human approval.
The DDPA characterises such autonomous agents as a Trojan horse: attractive to attackers and vulnerable to misuse. Security research shows that approximately 20% of available plug‑ins contain malware designed to steal login details or cryptocurrency. OpenClaw is also vulnerable to indirect prompt injections, whereby hidden commands are embedded in ordinary websites, emails or messages, creating risks of account takeovers, data exfiltration and theft of authentication tokens. Critical vulnerabilities have also been identified that allow full remote system compromise.
The DDPA advises organisations and individuals not to install such AI agents on systems containing sensitive data, such as customer records, HR files, financial information or identity documents. Users are strongly advised to be cautious with external plug‑ins, apply strict access controls and change credentials when exposure is suspected. Parents are warned that children may install such tools on private devices with access to sensitive information.
The DDPA also stresses the need for EU‑level clarification that autonomous AI agents fall within the scope of the AI Act. The AI Act includes product‑safety requirements for AI systems, including obligations to prevent unsafe uses. Organisations deploying AI agents remain fully responsible for GDPR compliance, regardless of whether they use open‑source tools. Experimental systems do not relieve users of their obligation to mitigate risks and implement appropriate technical and organisational measures.
Organisations are advised not to deploy autonomous AI agents in corporate environments without a thorough risk assessment. With implementation of the AI Act approaching, oversight of such applications is expected to increase, but until then the responsibility to act diligently lies with organisations and users themselves. |
|
|
|
| |
|
|
|
|
Marc Elshof attorney-at-law | partner
T: +31 70 376 06 87 M:+31 6 46 37 61 08 marc.elshof@barentskrans.nl
|
|
|
|
|
Lars Groeneveld attorney-at-law | senior associate
T: +31 70 376 06 48 M:+31 6 46 11 04 57 lars.groeneveld@barentskrans.nl
|
|
|
|
|
Job Julicher attorney-at-law
T: +31 70 376 08 10 M:+31 6 27 42 99 77 job.julicher@barentskrans.nl
|
|
|
|
|
Julius Louter attorney-at-law
T: +31 70 376 06 40 M:+31 6 15 43 37 52 julius.louter@barentskrans.nl
|
|
|
|
|
|
BarentsKrans
The Hague | Amsterdam +31 70 376 06 06 communicatie@barentskrans.nl www.barentskrans.nl |
| |
|
|
| |
|
|
|