Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Regulation August 1, 2026 6 min

The Dutch authority names its 2026-2028 priorities: mass surveillance, artificial intelligence, digital resilience

The AP is focusing supervision on large-scale systems with significant societal impact, in public and private hands. A public document almost nobody reads, and which tells you where they will look

TL;DR for the DPO

The Dutch authority has published where it will concentrate enforcement until 2028: mass surveillance, AI and algorithms, digital resilience. The stated criterion is scale and societal impact, not whether the controller is public or private. If a client of yours runs a system touching many people, they are in scope.

The three priorities

  • Mass surveillance: the authority states it wants to discourage and limit broad surveillance techniques where necessary, with particular attention to the security domain and the balance between freedom and safety within it, and with the explicit aim of preventing discrimination.
  • Artificial intelligence: the AP is allocating more capacity to AI and algorithms, and its position on generative AI and GDPR requirements is expected.
  • Digital resilience: work continues on awareness around cyber security, including information on dependencies on third countries in digital services.

The criterion that matters more than the three headings

In updating its supervisory strategy the AP states that it is focusing on large-scale systems with significant societal impact, both in public and in private hands. That formulation deserves attention, because it shifts the selection criterion from sector to scale. A mid-sized private company running a system with many users can fall within scope; a small public body with ordinary processing can fall outside it.

The method, which works for any country

Data protection authorities publish, every year, the document in which they say where they will look. It is free, it is public and almost nobody reads it. The Dutch AP's annual plan, the Italian authority's inspection plan, the Polish UODO president's sectoral inspection plan: three documents you can read in half an hour that tell you which clients in your portfolio carry higher risk this year. It is the reading with the best ratio of time spent to value, and it belongs in January, not in the week the letter arrives.

What to do, concretely

If you have clients present or with users in the Netherlands, the priority check is not documentary but substantive: which systems process data on many people, which use algorithms to assess or classify, and whether each of them has an impact assessment carried out before go-live. The sequence in time is the point authorities challenge most often, and it cannot be recovered afterwards.

If you are considering entering the Dutch market as an external DPO, these three themes are also the map of demand: where the authority looks, controllers seek help.

Official source:Autoriteit Persoonsgegevens - Strategic focus 2026-2028 and 2026 annual plan

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Regulation
120days to charge you, not to fine you

The 120 days are not the deadline to fine you: they are the deadline to charge you

Anyone who built an appeal on the authority's delay should re-read the calendar. The Court clarifies three things: the complaint procedure and the sanctioning procedure are autonomous, so overrunning the nine-to-twelve months on the complaint does not extinguish the power to fine; the 120 days are for notifying the charge, not for imposing the fine; and they run from the «definitive finding», which is not the first notice but the moment the authority can assess every element — including the hearing of your side. After the charge, only the five-year limitation period remains.

Sep 20, 2026New 7 min
Regulation
4weeks: the shortest period in Europe

Four weeks, not a day more: how long applicant data may be kept in the Netherlands

Four weeks after the procedure ends is the shortest retention period in Europe for this data, and it is not optional guidance: faced with a complaint it is the first thing the Dutch authority checks. The copy of the identity document is the exception that splits the personnel file in three.

Sep 18, 2026New 6 min
Regulation
10years of technical documentation, and two different clocks

The AI Act is a retention problem, and almost nobody is treating it as one

Everyone reads the AI Act as a risk-classification exercise. Underneath it there is a set of retention periods as concrete as anything in tax law: documentation kept ten years from placing on the market, logs kept at least six months, and incident reports due in fifteen, ten or two days. None of it fits in a record of processing that has one row for “AI system”.

Sep 18, 2026New 7 min