Since 1 September 2026, publishing sanctions has become the legal default for the Dutch Data Protection Authority. A fine no longer disappears quietly into a file, it becomes a permanent, searchable public record. What exactly changes, and what does it mean for your organisation?
Until recently, fines from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) often disappeared quietly into a file. An organisation received a sanction, paid the bill or appealed, and the outside world rarely learned anything about it. That changed on 1 September 2026. Under the Verzamelwet gegevensbescherming, which amends the Dutch GDPR implementation act, publishing administrative sanctions has become the legal default.
For directors of Dutch organisations, this fundamentally changes the calculation around privacy risk. A fine was already an unpleasant experience, with legal costs and internal disruption. Now it comes with a lasting, searchable public record that customers, journalists and competitors can find with a simple search.
The amendment reverses the starting point. Where the AP previously decided itself whether and when a sanction became public, publication is now the norm and confidentiality the exception. Only information that may not be disclosed under the Dutch Open Government Act stays out of the notice. For the vast majority of fines, periodic penalty payments and processing bans, that changes little about the outcome: they come out.
An organisation is not named and shamed immediately. Publication takes place at the earliest ten working days after the sanction was communicated to the offender. During that period, an organisation can go to the preliminary relief judge to request postponement or full prevention of publication, for example if disclosure would cause disproportionate harm. That court route is now the only remedy, no longer a policy arrangement with the regulator.
A fine that once stayed in an internal memo will soon carry your organisation's name permanently in a search engine. Customers assessing a supplier, insurers underwriting a cyber policy and municipalities running a tender increasingly check actively for this kind of sanction. A public fine then affects procurement processes that have nothing to do with the original violation.
The AP already published part of its sanctions before, but based on its own policy and with room for exceptions. That discretion has now been replaced by a structural obligation. Enforcement becomes more visible and more predictable, which also means you can assess your risk better before anything goes wrong.
Most directors associate the GDPR with a register of processing activities that was drawn up once and then left in a folder. With a public sanctions file on the horizon, it pays to update that register, the related data processing agreements and any DPIAs this quarter. Ask yourself concretely: do you know who you share personal data with, is that contractually arranged properly, and can you report a data breach within 72 hours if one occurs?
Your incident process matters too. An organisation that reports a data breach quickly and fully is in a better position in case of a sanction than one that only acts after a complaint. The size of a fine, and the likelihood it gets published, partly depends on how you acted after something went wrong, not only on the violation itself.
Most GDPR sanctions do not stem from malicious intent but from a data breach that could have been prevented: an unsecured account, a misconfigured backup, a phishing email that landed. Basic measures such as password managers, mandatory two-factor authentication and a working patch policy prevent most of these incidents, and with them the risk of a sanction that will now become public.
For self-employed professionals and organisations with up to fifty employees and annual revenue up to ten million euros, the Dutch NCSC's Mijn Cyberweerbare Zaak subsidy scheme runs until 30 November 2026. It covers half the cost of this kind of basic measure, up to a maximum of 1,250 euros per applicant, as long as this year's budget lasts. It is a direct, temporary way to strengthen resilience before an incident happens.
The message for directors is simple. Do not assume a privacy problem will resolve itself within the walls of your organisation. Make sure your data processing, contracts and reporting procedures are in order, and invest in the basic security that prevents most incidents. Want to know where the biggest risks in your organisation lie, or need help getting your compliance and security in order? Zarioh is happy to think it through with you.
Zarioh Digital Solutions
IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony, and share what we learn in practice. Follow us on LinkedIn

Branding & Design

AI & Automation

Security