# From 1 September, a Dutch GDPR fine goes online with your name on it

  [Home](https://mijnevent.nl/en) / [Blog](https://mijnevent.nl/en/blog) / From 1 September, a Dutch GDPR fine goes online with your name on it   legislation gdpr privacy organisers 

# From 1 September, a Dutch GDPR fine goes online with your name on it

 The Dutch data protection authority was already allowed to publish its sanctions. From 1 September 2026 it has to. For an event organisation that changes one thing above all: the bill is no longer the only consequence.

 MijnEvent · 31 August 2026 · 7 min read 

  ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/dutch-privacy-fines-public-from-september.webp)  Photo: [Jonathan Gong](https://unsplash.com/@jonathangongphotography?utm_source=MijnEvent&utm_medium=referral) / [Unsplash](https://unsplash.com/?utm_source=MijnEvent&utm_medium=referral)     In short

- From 1 September 2026 the Dutch Data Protection Authority is legally obliged to publish any decision imposing an administrative sanction — a fine, an order subject to a penalty payment, or a processing ban. Until now publication was policy, not duty.
- The basis is the new Article 21b of the Dutch GDPR Implementation Act, introduced by the Verzamelwet gegevensbescherming (Bulletin of Acts 2026, 154) and brought into force on 1 September (Bulletin of Acts 2026, 196).
- You get ten working days between the decision and publication. Apply for interim relief in that window and publication is suspended until the court has ruled.
- The odds of a fine are low — the authority issued four in 2025 — but the odds of a data breach are not: over 39,000 reports in 2025, most of them misaddressed post and email.
- The sharpest rise is in compromised accounts: from 607 in 2024 to 1,742 in 2025. That is exactly the kind of login your volunteers and team members use.

        Not legal advice

This article explains the rules as we read them, on the date of publication. It is general information, not legal advice — your situation may differ.

  Something changes in Dutch privacy law tomorrow that is easy to miss, because it is not about what you have to do. It is about what happens when you don't.

From **1 September 2026** the Dutch Data Protection Authority — the Autoriteit Persoonsgegevens, the national supervisory authority that enforces the GDPR in the Netherlands — is obliged to publish any sanction it imposes. With the name of the organisation attached. Until now it did so of its own accord, under its own policy. From tomorrow it is written into law.

For most event organisations nothing changes about the rules themselves. What changes is the scale you weigh them on.

# What has actually been put into the law

The change comes from the **Verzamelwet gegevensbescherming**, an omnibus act that tidies up and extends the Dutch GDPR Implementation Act (UAVG). The text is in [Bulletin of Acts 2026, 154](https://zoek.officielebekendmakingen.nl/stb-2026-154.html); the [commencement decree](https://zoek.officielebekendmakingen.nl/stb-2026-196.html) brings it into force on 1 September 2026, with the exception of one clause that still needs supplementing.

The new **Article 21b** is short. The authority publishes a decision imposing an administrative sanction, "except insofar as Article 5.1 (…) of the Open Government Act stands in the way of publication". Three things are packed into that:

- **It covers administrative sanctions.** A fine, then, but also an order subject to a penalty payment or a processing ban. Not every measure the authority takes is an administrative sanction — a reprimand, for instance, is not.
- **Publication is the rule, not a choice.** Where the authority previously weighed it up case by case, publishing is now the starting point.
- **The [Open Government Act](https://wetten.overheid.nl/BWBR0045754/) remains the brake.** Commercially confidential information and the personal data of individual employees get redacted.

That follows the course the authority had already set. In March 2026 it adopted new [publication policy rules](https://zoek.officielebekendmakingen.nl/stcrt-2026-14351.html) built on the principle "public, unless". The statute now extends that line.

# Ten working days, and what you can do with them

There is a pause between the decision and publication. The authority may only publish **once ten working days have passed** since the day the decision was served on the offender. That period lapses if you have gone public yourself — an organisation that tells its own story first does not have to wait for the regulator.

If within those ten working days you apply for **interim relief** at the administrative court, publication is suspended until the judge has ruled. That is not an escape route, but it is a real safeguard: you can have a publication tested before it goes live.

# How likely is this to touch you?

Honest answer: a fine is unlikely. The authority issued [four fines in 2025](https://ibestuur.nl/data-en-ai/datagedreven-werken/meer-klachten-en-datalekken-maar-minder-boetes), against six in 2024, and gave nine reprimands. Complaints and tip-offs rose by 75 percent, but the regulator shifted visibly towards warning, advising and investigating. A village festival or a brass band is not high on that list.

Except: most organisations do not meet the authority through a fine. They meet it through the **data breach notification desk**. And there the numbers are far less theoretical. From the authority's [2025 data breach report](https://www.autoriteitpersoonsgegevens.nl/rapportages-datalekken):

- **Over 39,000 notifications** in 2025, against nearly 38,000 in 2024.
- **More than 25,000 of those concerned post** — largely misaddressed.
- **More than 4,200 concerned email**, mostly addressing errors.
- **2,400 concerned cyberattacks**, over 1,700 of which were compromised accounts. In 2024 that figure was 607. Close to a threefold rise, and the authority points squarely at AI phishing: faster, more convincing and at scale.

Put those two lists side by side and the picture is clear. The risk to an event organisation rarely sits in some principled legal misstep. It sits in a wrongly addressed email and a stolen login.

# Where events go wrong

Three situations we see most often, and what to do about them.

**The attendee list in the cc field.** You send a final update to a hundred and fifty attendees and put the addresses in cc instead of bcc. That is a data breach: a hundred and fifty people now see each other's email address, tied to the fact that they are coming to your event. For a private or sensitive event that is more than a cosmetic slip. It is also precisely the category the authority receives most. The structural fix is not "pay closer attention" but making manual emailing unnecessary — mailing from your ticketing system sends per recipient, and at MijnEvent [email addresses are masked by default](/en/blog/privacy-email-masking) from anyone who does not need them.

**The shared account.** One login the whole committee uses, with a password unchanged since 2021. If that account is taken over you cannot even establish who did what. Give every team member their own access and [exactly the permissions their role calls for](/en/blog/set-permissions-per-team-member) — a volunteer scanning tickets has no business exporting visitor data.

**The list that never goes away.** The attendee export from the 2021 festival is still in a shared folder and nobody remembers why. Retention periods are the dullest part of the GDPR and simultaneously the most effective: data you no longer hold cannot leak. Our [overview of the GDPR for event organisers](/en/blog/gdpr-visitor-data-events) sets out a reasonable period per data type.

And when a visitor asks what you hold on them, or wants it erased: handle it within a month. [Handling a GDPR request](/en/blog/handling-gdpr-requests) explains how.

# Why a published sanction weighs differently

A fine is money. Unpleasant, but you can budget for it. A published decision is something else: it is out there, with a date and a name, and it stays findable. For an event organisation that is an unusually heavy penalty, because you work with parties who judge you on trust. The council that grants your permit. The sponsor who puts their logo on your banner. The association considering handing you its membership administration.

Which is exactly what the legislator intended: visibility, a deterrent effect, and organisations able to learn from each other's cases. That last part is the most useful side of it for you. Public decisions also mean public norms: you will be able to read what the authority genuinely considered a step too far, instead of guessing.

# What you can do this month

No big project. Four things that fit in one morning:

1. **Find out where your visitor data lives.** Not just in your ticketing system — also in exports, mailing lists, WhatsApp groups and the treasurer's laptop.
2. **Throw away what you no longer need.** Every old export you delete is a data breach that can no longer happen.
3. **Give everyone their own login with their own permissions,** and switch on two-factor authentication where you can. That is the direct countermeasure to the fastest-growing category of breaches.
4. **Agree who does what when it goes wrong.** You have 72 hours to report a breach. That is enough time, but not if you spend the first hours working out whose job it is.

At MijnEvent part of this sits in the product: masked email addresses, permissions per team member, an activity log recording who did what and when, and retention periods that expire on their own. No supplier takes over your responsibility — you remain the controller — but it matters whether your system thinks along with you or works against you.

[See what MijnEvent costs](/en/pricing) or [create your organiser account](/registreer); you can be selling your first ticket the same week.

*This article is general information, not legal advice. The published statutory text governs your specific situation; consult a lawyer or the Dutch Data Protection Authority if you are in any doubt.*

 Legislation changes and tariffs are revised annually. We do our best to keep this article current and link to the source where we can, but we cannot guarantee everything still holds at the moment you read it. If a decision carries financial or legal consequences, check with the authority itself or put it to a lawyer or adviser. See also our [general disclaimer](https://mijnevent.nl/en/disclaimer).

   Frequently asked questions

## Frequently asked questions

## Wasn't the Dutch DPA already publishing fines?

  It was, but on its own policy. It had published fine decisions for years and formalised that in new publication policy rules in March 2026, with 'public unless' as the principle. What changes on 1 September is that it becomes a statutory duty: the discretion to keep a sanction quiet disappears.

## Does this apply to a reprimand or a warning too?

  Not automatically. Article 21b covers decisions imposing an administrative sanction — a fine, an order subject to a penalty payment, or a processing ban. A reprimand is formally not one of those. The authority may still publish such a measure on its own initiative under its own policy rules.

## Can I stop publication?

  Rarely stop, often delay. Ten working days sit between the decision being served and publication. Apply for interim relief in that window and the authority waits for the court. The exemptions in Article 5.1 of the Dutch Open Government Act also stay in place: commercially confidential data and staff personal data do not belong in a published decision.

## Does this apply outside the Netherlands?

  The GDPR is EU-wide, but how a supervisory authority publishes its enforcement is national law. This particular duty is Dutch. If you sell tickets to a Dutch audience through a Dutch entity, it is the Dutch authority you deal with — and the underlying housekeeping in this article travels well regardless of jurisdiction.

  [    Back to blog ](https://mijnevent.nl/en/blog) 

  MijnEvent

## Read more

 [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/stadsbon-direct-in-je-kassa.webp) stadspas 

 Jasper Koers · 30 August 2026 · 4 min read

## City voucher straight into your till: scan the amount, done

New for shopkeepers: after redeeming a city voucher, the shop app shows a barcode carrying the amount. One scan with your own till scanner and the line is in your register — no retyping.

 ](https://mijnevent.nl/en/blog/city-voucher-straight-into-your-till) [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/een-platform-in-plaats-van-vijf-losse-tools.webp) modules 

 Jasper Koers · 29 August 2026 · 9 min read

## One platform instead of five separate tools — and now your website too

A ticket shop here, a web shop there, the membership list in a spreadsheet and a website built by yet another agency. What that collection really costs you, and what changes once it is one system with one Mollie connection.

 ](https://mijnevent.nl/en/blog/one-platform-instead-of-five-separate-tools) [ ![](https://regify-mijnevent.s3.eu-central-1.amazonaws.com/blog/covers/gdpr-visitor-data-events.webp) gdpr 

 Jasper Koers · 26 August 2026 · 8 min read

## GDPR for event organisers: handling visitor data properly

You collect names, e-mail addresses and payment details. That comes with obligations — here are the ones that matter, in plain language.

 ](https://mijnevent.nl/en/blog/gdpr-visitor-data-events) 

   MijnEvent

## Ready to get started?

Create a free account and sell your first tickets today.

 [Start free](https://mijnevent.nl/registreer) [Pricing](https://mijnevent.nl/en/pricing)
