In our March newsletter, you will find the following topics: |
|
|
|
|
|
|
|
Commission publishes draft guidelines on the application of the Cyber Resilience Act |
On 3 March, the European Commission (the Commission) published draft guidelines for the application of the Cyber Resilience Act (CRA) for public consultation.
The CRA, which has been in force since 10 December 2024, sets out cybersecurity requirements for products with digital elements and obliges manufacturers, importers and distributors to ensure compliance with these requirements. These obligations under Chapter IV apply from 11 June 2026. From 11 September 2026 onward, manufacturers must also actively report exploited vulnerabilities and serious cyber incidents involving their products with digital elements to the computer security incident response team and ENISA.
The guidelines have been drawn up pursuant to Article 26 CRA and are particularly intended to support SMEs in implementing the CRA. The Commission emphasises that timely guidance is necessary to enable manufacturers and developers to adapt their compliance processes before the CRA enters into force.
Among other things, the guidelines clarify the scope of the CRA, the criteria for substantial changes, the definition of the support period, and the role of remote data processing in the context of cybersecurity requirements. The guidelines also elaborate on the conformity assessment framework for important and critical products, including the relationship between notified bodies and harmonised standards.
The draft guidelines are open for consultation until 13 April 2026. Stakeholders may submit feedback on the draft guidelines via the Commission’s feedback portal until that date. |
|
|
|
| |
|
|
Reddit’s claims regarding guarantees of privilege dismissed |
On 4 March, the District Court of The Hague ruled in summary proceedings between Reddit Netherlands B.V., Reddit Inc. (collectively Reddit) and the Dutch Data Protection Authority (DDPA).
The case stems from a DDPA investigation into Reddit’s processing of personal data, specifically the sharing and sale of public content from the platform’s users, which Reddit provides to developers of AI models for further development. During the investigation, a dispute arose regarding the DDPA’s access to various Reddit systems, including Jira, Google Vault and SWAT Tables. Reddit refused to grant full access, arguing that these systems contain privileged information protected by the privilege of confidentiality. Reddit also claimed that access to these systems by the DDPA would constitute a breach of the US Stored Communications Act. On 26 January 2026, the DDPA imposed a penalty payment for breach of the duty to cooperate.
In these proceedings, Reddit sought a written confirmation from the DDPA as to whether it holds information covered by the privilege of non-disclosure, that the DDPA secures copies of this information, and that the DDPA must guarantee the privilege of non-disclosure in accordance with the Dutch Supreme Court’s judgment of 12 March 2024. Reddit also requested the court to grant leave for the precautionary seizure of this information.
The court ruled that Reddit’s claims were inadmissible, as an administrative legal procedure offering sufficient safeguards was still open. Reddit’s objections to the DDPA’s methods – including the way in which the right to refuse to give evidence is handled – can be raised in administrative proceedings against the order subject to a penalty payment. On 21 January 2026, the DDPA had already confirmed that, with the exception of one document provided by Reddit itself, it does not possess any privileged information. Reddit has not provided sufficient concrete evidence to the contrary, according to the judge hearing the application for interim relief. |
|
|
|
| |
|
|
Court of Appeal rejects rectification of personal data in court documents and police reports |
On 5 March, the Arnhem-Leeuwarden Court of Appeal published a judgment in a case concerning the scope of the right to rectification of personal data in civil court documents and a criminal complaint. The court ruled that Article 16 GDPR does not provide for the possibility of having statements in court documents corrected retrospectively, even if these statements prove to be incorrect.
The case concerned a former civil servant at the municipality of Rotterdam who requested the correction of personal data in court documents relating to civil proceedings for damages and a report filed by the Stichting Divosa (Divosa) concerning forgery and money laundering. Central to the case were statements regarding the civil servant’s authority to approve invoices and regarding alleged invoice fraud by the civil servant at the expense of the Municipality of Rotterdam and Divosa. The civil servant argued that these statements concerned incorrect personal data which, in his view, needed to be corrected.
In 2017, the Court of Appeal in The Hague ordered the civil servant to pay damages in the civil proceedings brought by the municipality of Rotterdam and Divosa. The criminal proceedings arising from the report were still ongoing in the appeal stage at the time of the judgment.
According to the court, the assessment of whether personal data is inaccurate must be based on the purpose of processing that data. In civil proceedings, pleadings serve to substantiate claims and to put forward a defence. A position taken by a party to the proceedings and included in a pleading is not inaccurate within the meaning of Article 16 GDPR, even if it subsequently transpires that it is not accurate. The Court of Appeal compares this to an incorrect answer in an examination: given the purpose of that processing, there is no question of inaccurate personal data. Applying Article 16 GDPR to a dispute that has been definitively settled by the court would lead to a partial re-assessment of the proceedings, which is contrary to the closed system of legal remedies and the legal certainty and effectiveness of the administration of justice, according to the Court of Appeal.
The same applies to the criminal complaint: the purpose of the processing is decisive, which consists of reporting conduct that Divosa considers to be criminal and of which it has been a victim. It is then up to the police, the Public Prosecution Service and the criminal court to investigate the material truth and rule on the matter. The court also points to the possibility of restricting the rights of data subjects to safeguard the investigation, detection and prosecution of criminal offences under Article 23(1)(d) GDPR and Article 41(1)(d) Dutch GDPR Implementation Act, and the restriction on the right to rectification with regard to witness statements under Article 28(1) Dutch Police Data Act. |
|
|
|
| |
|
|
CJEU clarifies when a request for access may be ‘excessive’ |
On 19 March, the Court of Justice of the European Union (CJEU) ruled on the question of when a request for access qualifies as ‘excessive’ and the controller may refuse it. In addition, the CJEU answered the question of whether a breach of the right of access may give rise to an obligation to pay compensation.
The case concerned an individual who had signed up for an opticians’ newsletter and submitted a data access request very shortly afterwards. The company refused to comply, citing abuse of the right of access. Public online sources revealed that the data subject had systematically submitted requests for access with the sole aim of claiming compensation once the statutory period had expired.
The CJEU ruled that a single request for access may already be “excessive” if the controller can demonstrate that there is deliberate abuse. This requires an objective and a subjective element: on the one hand, it must be shown that the intended purpose of the GDPR is not achieved through the exercise of the right of access; on the other hand, it must be demonstrated that the data subject is not submitting the request with the intention of taking note of the processing and verifying its lawfulness, but solely to artificially create the conditions for obtaining a right to compensation granted under the GDPR. In this regard, all the facts and circumstances of the case must be taken into account. The fact that, according to public information, a person has submitted several similar requests can be a relevant factor.
In addition, the CJEU confirms that the right to compensation also applies in the event of a breach of the right of access, even if there is no unlawful data processing. The data subject must, however, demonstrate that they have suffered damage as a consequence of this breach; their own conduct must not have been the decisive cause of that damage. |
|
|
|
| |
|
|
DDPA publishes practical guide ‘Health data in the cloud’ |
On 23 March, the DDPA published the practical guide ‘Health data in the cloud’. The guide is aimed at organisations that use cloud solutions for processing health data and emphasises the need for careful consideration and informed choices.
The practical guide is an update of the previous guide on patient data in the cloud and significantly broadens its scope. Whereas the previous version was limited to patient data within the treatment relationship, the new guide covers health data in the broadest sense, such as medical records, data on health in relation to work, test results and data from digital healthcare applications. The guide covers the responsibilities of the data controller, the role of (sub-)processors, points for attention and risk analysis, data sovereignty and international data transfers, and the interplay between the GDPR and the Dutch Cybersecurity Act (Cyberbeveiligingswet), the Dutch implementing act of the NIS2 Directive.
To help organisations get started, the DDPA has developed a step-by-step plan. This helps organisations identify the key points and then refers to further information in the practical guide. Organisations can use the guide at strategic, tactical and operational levels when making decisions about the processing of health data in the cloud. The DDPA emphasises that organisations remain fully responsible for the processing of health data in the cloud and that this responsibility cannot be outsourced to a cloud provider. |
|
|
|
| |
|
|
Majority of Dutch online shops inaccessible to people with disabilities |
On 24 March, the Dutch Authority for Consumers and Markets (ACM) published a press release revealing that the majority of Dutch online shops are insufficiently accessible to people with physical disabilities, such as the blind and visually impaired.
The ACM’s inspection found that 61% of the largest Dutch online shops have not taken any measures or provided any means to enable people with disabilities to place an order. According to the ACM, placing an order is possible on additional 33% of the websites examined, although it requires considerable effort for people with disabilities compared to those without disabilities.
The European Accessibility Act (EAA) and its Dutch implementing act have been in force since 28 June 2025. The EAA obliges providers of, among other things, online shops in the EU to design their websites in such a way that people with disabilities can use them in an accessible manner and place orders. The EAA applies to organisations with more than 10 employees and/or an annual turnover of more than €2,000,000. In the event of non-compliance, the ACM may impose fines of up to €900,000 or 1% of annual turnover, whichever is higher.
The ACM will notify the largest companies with the poorest performance about their areas for improvement and will take enforcement action if insufficient improvements are made. In addition to this risk, an inaccessible online shop also causes companies to lose revenue, as they miss out on potential customers with disabilities, according to the ACM. |
|
|
|
| |
|
|
|
|
Marc Elshof attorney-at-law | partner
T: +31 70 376 06 87 M:+31 6 46 37 61 08 marc.elshof@barentskrans.nl
|
|
|
|
|
Lars Groeneveld attorney-at-law | senior associate
T: +31 70 376 06 48 M:+31 6 46 11 04 57 lars.groeneveld@barentskrans.nl
|
|
|
|
|
Job Julicher attorney-at-law
T: +31 70 376 08 10 M:+31 6 27 42 99 77 job.julicher@barentskrans.nl
|
|
|
|
|
Julius Louter attorney-at-law
T: +31 70 376 06 40 M:+31 6 15 43 37 52 julius.louter@barentskrans.nl
|
|
|
|
|
|
BarentsKrans
The Hague | Amsterdam +31 70 376 06 06 communicatie@barentskrans.nl www.barentskrans.nl |
| |
|
|
| |
|
|
|