Jan Dop

partner

Jan is a specialist in employment law and corporate law

jan.dop@russell.nl
+31 20 301 55 55

Reinier Russell

managing partner

Reinier advises national and international companies

reinier.russell@russell.nl
+31 20 301 55 55

Privacy: Possible fines of up to EUR 100 million or more

Publication date 23 december 2014

The bill for the new European General Data Protection Regulation includes extremely high fines of up to EUR 100 million or 5% of the global annual turnover of a company. When are you likely to incur such a fine?

persoonsgegevens - ubo

High fines

In our recent newsletter on privacy, we reported that there will be a new law to provide the same data protection regulations throughout the European Union. One important aspect of these regulations will be the introduction of new penalties including extremely severe sanctions for (repeated) breaches of privacy of EU citizens.

In the Netherlands, fines are imposed by the CBP (College bescherming persoonsgegevens; Data Protection Agency). At the moment, the CBP can impose a maximum fine of EUR 4,500. The latest fines however, could be up to maximum of EUR 100,000,000 or 5% of the global annual turnover of a company, depending on which amount is higher.

Violations

You may be fined for the following violations, for instance:

  • Processing of personal data without consent or legal basis.
  • Processing of personal data with regard to:
    • racial or ethnic origin,
    • political opinions,
    • religious or philosophical beliefs,
    • trade union membership,
    • genetic information,
    • health,
    • sex life,
    • criminal convictions and related security measures.
  • Not taking appropriate technical and organizational measures to prevent data leaks, unauthorized access to and elimination of data.
  • Not reporting data leaks in time, as, for instance loss of a USB device or website hacking.
  • Non-performance of data protection impact assessment upon processing data that involve special privacy risks, for instance regarding health.

Action

Be sure to organize your data processing (HRM, ICT, online shop, website, software, cameras, GPS, etc.) in conformity with the new General European Data Protection Regulation. This regulation is expected to become effective in the course of 2015/2016. Thus, there is still plenty of time to make necessary adjustments in order to prevent fines.

More information

Russell Advocaten will inform you regularly on the most recent developments regarding this General European Data Protection Regulation and its potential consequences for your business. Would you like to know more about the application of the new General Data Protection Regulation, or do you have any other questions on how to organize your company in the context of the new data protection regulation? Please contact:

    We process the personal data above with your permission. You can withdraw your permission at any time. For more information please see our Privacy Statement.

    Related publications

    Amendment or termination of the share scheme: is the consent of the works council required?

    The works council has the right of consent when establishing, amending or withdrawing a remuneration system. Is an amendment to a share scheme an amendment to the remuneration system?

    Read more

    Digital General Meeting for Private Law Legal Entities Act adopted

    On 16 December 2025, the House of Representatives of the Netherlands adopted the Digital General Meeting for Private Law Legal Entities Act. This Act makes it possible to hold general meetings entirely digitally. What does this mean for directors and shareholders of private limited companies, public limited companies and other legal entities?

    Read more

    Highly skilled migrants: salary thresholds for 2026 and possible stricter rules

    The salary thresholds for highly skilled migrants and European Blue Card holders are adjusted annually. What will be the amounts for 2026? Also, stricter rules for the highly skilled migrant scheme are proposed. What might change?

    Read more

    1 January 2026: Wwft prohibits cash payments of 3,000 euros or more

    As of 1 January 2026, the Money Laundering and Terrorist Financing (Prevention) Act (Wwft) will change. Cash payments of EUR 3,000 or more will then be prohibited. What does this mean for the retail sector and the art trade?

    Read more

    On-call employees

    On-call contracts offer many advantages for both employers and on-call employees. However, there are also a few rules that they need to take into account. What are they?

    Read more

    Personnel: Are you allowed to dismiss a drunken employee?

    What shall we do with the drunken employee? Sack him? That isn’t always allowed. Alcohol abuse may be the result of an addiction and in that case the prohibition on termination during illness may apply. What do you have to take into account when dismissing an employee due to alcohol consumption?

    Read more