Dutch DPA must publish GDPR sanctions from September 1, 2026
On August 27, 2026, the Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, announced that from September 1, 2026 it is legally required to publish General Data Protection Regulation (GDPR) administrative sanctions. Until now the AP already published many sanctions under its own policy. A change to the Dutch GDPR Implementation Act (Uitvoeringswet Algemene verordening gegevensbescherming, or UAVG) makes publication a statutory duty.
The change sits in the Verzamelwet gegevensbescherming (Staatsblad 2026, 154). A Royal Decree (Staatsblad 2026, 196) set most of that package, including the new publication rule, to take effect on September 1, 2026.
What changed
Starting September 1, 2026 (now in force), the AP must publish decisions that impose administrative sanctions such as fines, penalty payments (last onder dwangsom), and processing bans, unless Dutch open-government exceptions block disclosure. The AP said it will first tell the organization it plans to publish, then take a final publication decision.
Two timing rules apply:
- Publication generally waits at least 10 working days after the organization receives the decision to publish (earlier if the organization already went public or does not object)
- If the organization seeks interim court relief against publication, publication is paused until the court rules or the request is withdrawn
The same package also updates other UAVG rules that affect day-to-day GDPR work in the Netherlands, including how consent and data-subject rights work for children (notably ages 12 and 16) and a narrower exception for biometric access control. The EU GDPR text itself is unchanged; these are Dutch implementing-law updates for organizations under AP supervision.
What is not changing
The GDPR remains the same EU regulation. This announcement does not create a new EU-wide publication mandate for other supervisory authorities. Organizations outside Dutch jurisdiction are not newly covered by the UAVG amendments, though they may still face public enforcement decisions from their own regulators under local practice.
What to do now
- If you process personal data of people in the Netherlands or are otherwise under AP supervision, treat AP enforcement as carrying a near-certain public naming risk now that the publication duty is in force.
- Update incident and enforcement playbooks so legal, privacy, and communications teams can act inside the 10-working-day publication window, including whether to seek interim relief.
- Review Dutch-facing consent and rights workflows for minors against the revised UAVG age rules, and re-check any biometric access controls against the narrower security exception.
- Read the AP announcement and the Verzamelwet text rather than relying on secondary summaries.
- Follow GDPR on this site for later EDPB and national supervisory updates.
Sources
- AP maakt AVG-sancties voortaan verplicht openbaar (August 27, 2026)
- Staatsblad 2026, 196 (inwerkingtreding Verzamelwet gegevensbescherming) (July 13, 2026)
- Staatsblad 2026, 154 (Verzamelwet gegevensbescherming) (June 26, 2026)