TL;DR for the DPO
The Dutch authority has published where it will concentrate enforcement until 2028: mass surveillance, AI and algorithms, digital resilience. The stated criterion is scale and societal impact, not whether the controller is public or private. If a client of yours runs a system touching many people, they are in scope.
The three priorities
- Mass surveillance: the authority states it wants to discourage and limit broad surveillance techniques where necessary, with particular attention to the security domain and the balance between freedom and safety within it, and with the explicit aim of preventing discrimination.
- Artificial intelligence: the AP is allocating more capacity to AI and algorithms, and its position on generative AI and GDPR requirements is expected.
- Digital resilience: work continues on awareness around cyber security, including information on dependencies on third countries in digital services.
The criterion that matters more than the three headings
In updating its supervisory strategy the AP states that it is focusing on large-scale systems with significant societal impact, both in public and in private hands. That formulation deserves attention, because it shifts the selection criterion from sector to scale. A mid-sized private company running a system with many users can fall within scope; a small public body with ordinary processing can fall outside it.
The method, which works for any country
Data protection authorities publish, every year, the document in which they say where they will look. It is free, it is public and almost nobody reads it. The Dutch AP's annual plan, the Italian authority's inspection plan, the Polish UODO president's sectoral inspection plan: three documents you can read in half an hour that tell you which clients in your portfolio carry higher risk this year. It is the reading with the best ratio of time spent to value, and it belongs in January, not in the week the letter arrives.
What to do, concretely
If you have clients present or with users in the Netherlands, the priority check is not documentary but substantive: which systems process data on many people, which use algorithms to assess or classify, and whether each of them has an impact assessment carried out before go-live. The sequence in time is the point authorities challenge most often, and it cannot be recovered afterwards.
If you are considering entering the Dutch market as an external DPO, these three themes are also the map of demand: where the authority looks, controllers seek help.
Official source:Autoriteit Persoonsgegevens - Strategic focus 2026-2028 and 2026 annual planLooking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free