Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens): AI Compliance Requirements
The Dutch DPA (AP) is a leading EU enforcement authority on AI profiling and automated decision-making, having fined Uber three times: €600K (2018), €10M (2023, over driver privacy rights), and — most significantly, verified this cycle — **€825 million on 2026-08-17** for automated driver-account suspensions (2018-2022 violations) without adequate human review, the second-largest GDPR fine ever issued (behind only Meta Ireland's €1.2B). Mandatory DPIAs for AI profiling systems and strict human review requirements for automated decisions are AP enforcement priorities.
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
June 1, 2023
€20,000,000 or 4% global annual turnover (GDPR statutory ceiling) — though the AP's actual imposed fines have been calculated well above nominal turnover-percentage guidance in practice (see the €825M Uber fine, 2026-08-17, under appeal).
What Your Business Must Do
2 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
Mandatory DPIA for AI Profiling Systems (Netherlands)
CriticalDutch AP mandates a DPIA before deploying AI systems that profile individuals. The AP has issued specific DPIA guidance for AI profiling — follow the AP checklist.
Human Review for Automated Decisions (Dutch AP Enforcement)
High PriorityDutch AP enforces GDPR Art. 22 strictly: automated decisions with significant effects must have genuine human review. Document the human review process, not just a human rubber-stamp.
Who Does This Apply To?
Applies to any organisation deploying AI systems that process the personal data of individuals in the Netherlands — the Dutch DPA (Autoriteit Persoonsgegevens, AP) is a leading EU enforcement authority on AI profiling and automated decision-making. In scope: any business that profiles individuals with AI (a DPIA is mandatory before deployment, following the AP profiling checklist), and operators of automated decision systems with significant effects (the 2023 Uber €10M fine, and far more significantly the 2026-08-17 Uber €825M fine — the second-largest GDPR fine ever — established that GDPR Art. 22 requires genuine human review, not a rubber-stamp, before AI-driven account suspension/deactivation or comparable decisions). Maximum exposure: €20M or 4% of global annual turnover (statutory ceiling — actual AP fines in this area have exceeded nominal guidance).
Recent Enforcement Actions
Against:
Against:
Recent Regulatory Guidance
Dutch AP — DPIA Checklist for AI Profiling Systems (2024)
AP published a practical DPIA checklist for AI profiling covering: necessity and proportionality of profiling, accuracy of training data, automated decision logic documentation, individual rights mechanisms, and third-party AI vendor assessment. Checklist available at autoriteitpersoonsgegevens.nl/ai.
Industry Playbooks covering Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens)
These industry playbooks include jurisdiction-specific checklist items and guidance for Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens).
Frequently Asked Questions
Does Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens) apply to my business?
The Dutch DPA (AP) is a leading EU enforcement authority on AI profiling and automated decision-making, having fined Uber three times: €600K (2018), €10M (2023, over driver privacy rights), and — most significantly, verified this cycle — **€825… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens) is: €20,000,000 or 4% global annual turnover (GDPR statutory ceiling) — though the AP's actual imposed fines have been calculated well above nominal turnover-percentage guidance in practice (see the €825M Uber fine, 2026-08-17, under appeal).. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens)?
The 2 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://www.autoriteitpersoonsgegevens.nl/en/themes/artificial-intelligenceLast updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan