Dutch DPA Releases Complaints Report for First Half of 2019
Time 2 Minute Read

On September 9, 2019, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, the “Dutch DPA”) published a report on the privacy complaints it received between January 2019 and June 2019 (the “Report”).

Read the full Report and the press release (in Dutch).

Overview

During the first half of 2019, 19,020 individuals and organizations have contacted the Dutch DPA with EU General Data Protection Regulation or privacy-related issues and concerns. From this number, the Dutch DPA identified 15,313 cases as privacy complaints, while the remaining cases were identified as requests for information. This represents a 59% increase compared to the number of complaints received in the last six months of 2018, which results in a four to six month delay in the complaint handling process – though serious complaints are processed faster.

Facts and Figures

In the first six months of 2019, the Dutch DPA has processed:

  • 452 international complaints versus 331 in the second half of 2018. Among the 452 international complaints, 66 were introduced directly to the Dutch DPA, whereas the others were indirectly referred to the Dutch DPA by other EU supervisory authorities.
  • 36% of the complaints processed related to data subjects’ own personal data.
  • 68 of the complaints filed to the Dutch DPA resulted in further investigations, eight of which were transferred to the enforcement department of the Dutch DPA to determine the measures that should be taken.
  • 32% of the complaints related to data subjects’ rights, 13% to the transfer of personal data to third parties, 11% to the absence of legal basis to justify the processing of personal data, 10% to direct marketing, and 1% to the processing of personal data of children.
  • 46% of the complaints received affect the service provider sector, 14% the public sector, 13% the IT sector, and 8% the health care sector.

In addition, the Report explains how the complaint process was resolved in those cases:

  • In 29% of the cases, by providing guidelines on how to resolve the issue;
  • In 10% of the cases, by sending a letter to the named company explaining the applicable requirement;
  • In 5% of the cases, by discussing the alleged violation with the company and actions to remediate the violation; and
  • Once, by mediating between the claimant and the named company.

In specific cases, the Dutch DPA may also prematurely close the proceedings, for example, when the assessment of the complaint does not show an infringement or when the complaint was already remediated by the company.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 6 Minute Read

On February 9, 2026, trade association NetChoice filed a lawsuit challenging South Carolina’s newly passed Age-Appropriate Code Design (“SC AACD”) on First and Fourteenth Amendment grounds. The SC AACD was signed into law on February 5, 2026, making South Carolina the fifth U.S. state to enact such a law, following California, Maryland, Nebraska and Vermont.

Time 2 Minute Read

Congress has extended the Cybersecurity Information Sharing Act of 2015 through September 30, 2026 as part of the Consolidated Appropriations Act, a government funding package enacted in early February 2026.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page