Skip to content
Esta e uma traducao de conveniencia. A versao em ingles e a versao oficial e legalmente vinculativa. Ver versao em ingles
EUMEDIUM coverage2 enforcement actions

Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens): AI Compliance Requirements

The Dutch DPA (AP) is a leading EU enforcement authority on AI profiling and automated decision-making, having fined Uber three times: €600K (2018), €10M (2023, over driver privacy rights), and — most significantly, verified this cycle — **€825 million on 2026-08-17** for automated driver-account suspensions (2018-2022 violations) without adequate human review, the second-largest GDPR fine ever issued (behind only Meta Ireland's €1.2B). Mandatory DPIAs for AI profiling systems and strict human review requirements for automated decisions are AP enforcement priorities.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

June 1, 2023

Maximum Penalty

€20,000,000 or 4% global annual turnover (GDPR statutory ceiling) — though the AP's actual imposed fines have been calculated well above nominal turnover-percentage guidance in practice (see the €825M Uber fine, 2026-08-17, under appeal).

What Your Business Must Do

2 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Mandatory DPIA for AI Profiling Systems (Netherlands)

Critical

Dutch AP mandates a DPIA before deploying AI systems that profile individuals. The AP has issued specific DPIA guidance for AI profiling — follow the AP checklist.

GDPR Art. 35 (as applied by Dutch AP)

Human Review for Automated Decisions (Dutch AP Enforcement)

High Priority

Dutch AP enforces GDPR Art. 22 strictly: automated decisions with significant effects must have genuine human review. Document the human review process, not just a human rubber-stamp.

GDPR Art. 22 (as applied by Dutch AP)

Who Does This Apply To?

Applies to any organisation deploying AI systems that process the personal data of individuals in the Netherlands — the Dutch DPA (Autoriteit Persoonsgegevens, AP) is a leading EU enforcement authority on AI profiling and automated decision-making. In scope: any business that profiles individuals with AI (a DPIA is mandatory before deployment, following the AP profiling checklist), and operators of automated decision systems with significant effects (the 2023 Uber €10M fine, and far more significantly the 2026-08-17 Uber €825M fine — the second-largest GDPR fine ever — established that GDPR Art. 22 requires genuine human review, not a rubber-stamp, before AI-driven account suspension/deactivation or comparable decisions). Maximum exposure: €20M or 4% of global annual turnover (statutory ceiling — actual AP fines in this area have exceeded nominal guidance).

Recent Enforcement Actions

2026-08-17Source verified· as of 2026-08-22

Against:

2023-08Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2024-05

Dutch AP — DPIA Checklist for AI Profiling Systems (2024)

AP published a practical DPIA checklist for AI profiling covering: necessity and proportionality of profiling, accuracy of training data, automated decision logic documentation, individual rights mechanisms, and third-party AI vendor assessment. Checklist available at autoriteitpersoonsgegevens.nl/ai.

Industry Playbooks covering Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens)

These industry playbooks include jurisdiction-specific checklist items and guidance for Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens).

Frequently Asked Questions

Does Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens) apply to my business?

The Dutch DPA (AP) is a leading EU enforcement authority on AI profiling and automated decision-making, having fined Uber three times: €600K (2018), €10M (2023, over driver privacy rights), and — most significantly, verified this cycle — **€825… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens) is: €20,000,000 or 4% global annual turnover (GDPR statutory ceiling) — though the AP's actual imposed fines have been calculated well above nominal turnover-percentage guidance in practice (see the €825M Uber fine, 2026-08-17, under appeal).. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Netherlands — AI Governance under GDPR (Autoriteit Persoonsgegevens)?

The 2 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.autoriteitpersoonsgegevens.nl/en/themes/artificial-intelligence

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan