In our April newsletter, you will find the following topics: |
|
|
|
|
|
|
|
Supervisory authorities, the police, and the Public Prosecution Service call for a European ban on ‘AI nudify apps and websites’ |
On 1 April, the Authority for Consumers and Markets (ACM), the Dutch Data Protection Authority (DDPA), the Public Prosecution Service (PPS), the Police and three other public authorities jointly expressed their support for a European ban on so‑called nudify tools: apps and websites that digitally “undress” people in photos. The generated images are often misused to blackmail or extort victims, or to coerce them into sending sexually explicit images of themselves.
Current legislation provides insufficient tools to tackle the nudify tools themselves and focuses primarily on individual perpetrators. The authorities therefore support the proposed ban in the European AI Act and stress that the ban should also apply where the depicted person has given consent. A judgment that contributes to this approach is the decision of the preliminary relief judge of the Amsterdam court of 26 March prohibiting Grok and X from generating and distributing undressing images and child sexual abuse material. The prohibition applies to images of persons residing in the Netherlands and to the creation and dissemination of images in the Netherlands.
Pending European legislation, the ACM, the DDPA, Police and PPS are making use of the instruments currently available to them. They will handle individual reports, exchange information and cooperate on joint case analyses. They are also exploring ways to strengthen the digital resilience of young people, as they observe that nudify tools are being used by minors to create and disseminate sexually explicit material of other minors.
Victims are encouraged to file a report, enabling enforcement action and improving insight into the scale and frequency of these practices. In addition, they may lodge a complaint with the DDPA for infringement of data protection law. If a platform fails to respond in a timely manner to a request for removal, this may be reported to the ACM. |
|
|
|
| |
|
|
EDPB publishes 2025 annual report |
On 9 April, the European Data Protection Board (EDPB) published its 2025 annual report. The report reflects on a year in which the digital regulatory landscape became significantly more complex and in which the EDPB focused on three pillars: increasing legal certainty, simplifying compliance and strengthening cooperation.
A central milestone in 2025 was the adoption of the Helsinki Statement, in which the EDPB announced new initiatives to simplify GDPR compliance, enhance consistency and improve dialogue with organisations. As a result, the EDPB developed practical tools, such as templates, and organised several stakeholder events.
Another key priority was clarifying the interaction between the GDPR and other digital legislation. The EDPB adopted guidelines on the Digital Services Act, approved joint guidelines on the interaction between the Digital Markets Act and the GDPR, and made progress on the interplay between the GDPR and the AI Act. In addition, the EDPB issued five adequacy opinions, a joint opinion with the European Data Protection Supervisor (EDPS) on legislative simplification, and 29 opinions under Article 64 GDPR.
Effective enforcement also remained a core priority. Through the Coordinated Enforcement Framework (CEF), the Support Pool of Experts (SPE) and dedicated task forces, cooperation between national data protection authorities was further strengthened. In 2025, 414 cross‑border cases were registered and 1,299 procedures were initiated under the One‑Stop‑Shop mechanism of Article 60 GDPR. This mechanism provides that, in the case of cross‑border processing, a single lead supervisory authority acts on behalf of all concerned authorities, working towards a joint and binding decision through a formal cooperation procedure. |
|
|
|
| |
|
|
DDPA opens consultation on new enforcement policy |
On 13 April, the DDPA opened a public consultation on its draft enforcement policy. With this document, the DDPA aims to provide greater clarity on how it enforces compliance with, among other things, the GDPR, the Data Act, the Digital Services Act and the Dutch Telecommunications Act.
The draft enforcement policy sets out the principles applied by the DDPA once an infringement has been established. Central elements include the duty to enforce, the effect‑oriented nature of enforcement action, and the possibility of engaging in dialogue with the infringing party on bringing the infringement to an end. The DDPA emphasises that enforcement must be effective, proportionate and dissuasive, in line with the case law of the Court of Justice. At the same time, there remains scope to determine, on a case‑by‑case basis, which enforcement instrument is most appropriate.
The policy also provides an overview of the enforcement instruments available to the DDPA, ranging from reprimands and penalty payments to processing restrictions, processing bans and administrative fines. It explains the factors relevant to the choice of instrument, such as the nature, gravity and duration of the infringement, previous infringements and the degree of cooperation by the organisation. The policy further outlines the course of the enforcement procedure, including the right to be heard, publication of decisions and the introduction of a new option for expedited settlement by mutual agreement with the DDPA.
The expedited settlement by mutual agreement allows an enforcement procedure to be concluded more swiftly. In such cases, the infringer acknowledges the infringement, waives the right to lodge legal remedies, consents to publication and undertakes to compensate any damage suffered by data subjects. In return, the DDPA will reduce the fine by a maximum of 35%.
Finally, the policy addresses cooperation with other national and European supervisory authorities, in particular in the context of cross‑border processing and the GDPR’s One‑Stop‑Shop mechanism. The consultation offers organisations the opportunity to share practical experience before the policy is finalised. |
|
|
|
| |
|
|
X must disclose user’s personal data |
On 14 April, the Amsterdam Court of Appeal ruled that X must provide access to the personal data of a platform user.
In October 2023, the user experienced a temporary restriction of his X account following a critical post about European plans to combat child sexual abuse material. After the restriction was lifted, the user submitted a request for access under Article 15 GDPR. X provided only partial access, with extensive redactions, invoking business secrets and the privacy of its employees. X was required to provide specific information, including information about the Guano Notes system. According to X, full disclosure of these notes would reveal confidential business information. The user subsequently initiated proceedings, in which the district court ordered X to provide full access, subject to a penalty payment. X appealed this decision on the ground of protection of trade secrets.
The Court of Appeal emphasised that Article 15(4) GDPR allows restrictions on access in order to protect the rights and freedoms of others, including trade secrets, but that this requires a balancing of interests. The court weighed X’s interests against those of the user and confirmed the user’s right to almost full access to his personal data held by X, with the exception of the names of employees and the exact timestamps of actions. The interest of transparency and control by the data subject outweighs X’s business interests. The penalty payment imposed by the district court remains in force. |
|
|
|
| |
|
|
DDPA to carry out preventive inspections of ICT service providers |
On 16 April, the DDPA announced that it will increasingly focus on preventing data breaches and cyberattacks, rather than acting solely after the fact. By proactively inspecting organisations’ digital security, problems can be identified and addressed at an early stage.
In practice, this means that the DDPA will soon scrutinise the security measures of a number of Dutch ICT service providers. These parties typically process large volumes of personal data for multiple clients simultaneously, meaning that a data breach at such a provider can quickly have far‑reaching consequences. The DDPA therefore regards preventive supervision of ICT service providers as an efficient way to deploy its limited supervisory capacity. Where necessary, organisations will receive advice and guidance. This approach demonstrates that also processors have direct obligations under the GDPR, in this case under article 32 GDPR.
In addition, the DDPA has recently started conducting inspections at healthcare institutions, with cybersecurity as an explicit focus area. One of the triggers for these inspections is last year’s data breach at Clinical Diagnostics. Here too, the objective is to help organisations bring the protection of personal data up to the appropriate standard. |
|
|
|
| |
|
|
|
|
Marc Elshof attorney-at-law | partner
T: +31 70 376 06 87 M:+31 6 46 37 61 08 marc.elshof@barentskrans.nl
|
|
|
|
|
Lars Groeneveld attorney-at-law | senior associate
T: +31 70 376 06 48 M:+31 6 46 11 04 57 lars.groeneveld@barentskrans.nl
|
|
|
|
|
Job Julicher attorney-at-law
T: +31 70 376 08 10 M:+31 6 27 42 99 77 job.julicher@barentskrans.nl
|
|
|
|
|
Julius Louter attorney-at-law
T: +31 70 376 06 40 M:+31 6 15 43 37 52 julius.louter@barentskrans.nl
|
|
|
|
|
|
BarentsKrans
The Hague | Amsterdam +31 70 376 06 06 communicatie@barentskrans.nl www.barentskrans.nl |
| |
|
|
| |
|
|
|