Autoriteit Persoonsgegevens (AP)

Government & open data

Autoriteit Persoonsgegevens (AP)

The Autoriteit Persoonsgegevens is the Dutch data protection authority and the national supervisory authority under the GDPR. Its website holds a document archive of all public material from 25 May 2018, the day the GDPR became applicable: fines, orders subject to penalty payments, warnings, decisions on objection, approved codes of conduct, legislative reviews, normative interpretations, practical guidance and annual reports. For IT and privacy law this is where the regulator's enforcement practice becomes visible alongside the regulation itself.

Go to the publisher’s website

Which products consult this source

  • LEO — Direct consultation

    The source is consulted directly while the work is being done.

  • BEVER — Direct consultation

    The source is consulted directly while the work is being done.

  • IRMA — Direct consultation

    The source is consulted directly while the work is being done.

Availability depends on your organisation’s configuration and access rights.

What this source does not give you

The archive starts on 25 May 2018; anything published earlier under the previous Dutch Data Protection Act survives only in the AP's web archive. More importantly: the AP is a regulator, not a court. Normative interpretations, guidance and positions are the AP's view of how the GDPR should be read — authoritative, but reviewable; the administrative courts and the Court of Justice have the last word and have in fact corrected AP positions.

Legal domains for which LEO consults this source

Dutch legal domains; each link opens the domain page on leo.prudai.com.

Frequently asked questions

What types of document does the Dutch data protection authority publish?
The document overview is organised by document type, and that distinction matters legally. There are enforcement documents (fines, sanctions, orders subject to penalty payments, warnings, processing bans), decisions (including licences, decisions on objection, decisions on codes of conduct and freedom-of-information decisions), policy material (policy documents, policy rules, normative interpretation), advice to the legislator (legislative reviews, by far the largest category), reports and annual reports, and practical aids such as guidance notes, model letters and infographics. A legislative review and a fining decision do not carry the same weight and should not be cited as the same kind of source.
Is an AP position binding law?
No. Binding law is the GDPR, the Dutch GDPR Implementation Act and the case law on them. An AP position or normative interpretation tells you how the regulator applies the norm, and therefore what to expect in an investigation — highly relevant in practice, but not the same as a judicial ruling. A fining decision is binding, but only on the party it is addressed to, and it can be challenged by objection and appeal. For advice this means: cite the regulation for the norm, and the AP document for the enforcement expectation.
Is the AP's material also available in English?
The AP runs a full English-language version of its site, with its own themes, news items and a documents section. This is not a word-for-word translation of the Dutch archive: the English side carries a selection, and many decisions and legislative reviews remain available in Dutch only. For an international client the English page is usable as an explanation, but the source document remains the Dutch version.
Why does the archive contain so many legislative reviews?
Under Article 36(4) GDPR the AP must be consulted on proposals for legislation and regulation that affect personal data. This happens systematically, for practically every relevant proposal, which makes legislative reviews numerically the largest category in the archive. They are useful for seeing how the AP thinks about a forthcoming regime, but they say nothing about how the law was finally enacted: the advice concerns the draft, not the final text.
Will I find data breach notifications here?
Individual breach notifications are not public and do not appear in the archive. What is published are aggregated breach reports: numbers, sectors and types of incident over a period. These are useful for context and risk assessment, not for checking whether a specific organisation has reported something.
All sourcesLooking for the full picture? The knowledge-source map shows every source at once: view all knowledge sources.