TL;DR for the DPO
The Dutch Council of State did not rule that pseudonymised MAC addresses are not personal data. It ruled that the authority did not prove it. This is a defeat for the regulator on evidentiary grounds, not a green light for wifi tracking. Anyone citing this judgment to a client as 'permission to count passers-by' is misusing it.
The facts
From 25 May 2018 the municipality of Enschede installed sensors in the city centre that captured the MAC addresses of mobile devices with wifi switched on, in order to map visitor flows across the different retail areas. In March 2021 the Autoriteit Persoonsgegevens imposed an administrative fine of EUR 600,000, taking the view that the municipality had processed personal data without a legal basis. The municipality's administrative objection was rejected, and it took the matter to court.
In February 2024 the Overijssel District Court annulled the penalty decision. The reasoning is precise: the authority had not sufficiently demonstrated that the MAC addresses collected could be classified as personal data and that processing of personal data had occurred. The authority appealed. On 29 July 2026 the Administrative Jurisdiction Division of the Raad van State sided with the District Court (judgment 202401622/1/A3).
The point almost everyone is reading wrong
Be careful how you cite this judgment
Several reports summarised the decision as 'the encrypted device code and the location data cannot be traced back to people'. That conclusion cannot be drawn from the judgment. The administrative court stopped earlier: the authority should have reasoned its decision better. It is not excluded that, with a proper investigation, identifiability could have been established in this very case.
The distinction matters. A ruling declaring MAC addresses captured by urban sensors to be anonymous would be a systemic novelty, in tension with the case law of the Court of Justice on pseudonymous data and with the EDPB's positions. A ruling that annuls a fine for failure to state adequate reasons says something far narrower: the authority did not discharge its burden of proof.
What a DPO should take away
- If a client uses counting sensors (wifi, bluetooth, cameras with analytics), this judgment is NOT a basis for dropping the assessment. The legal basis and the DPIA remain due: the court never got to examine them.
- In proceedings against an authority, the burden of showing that personal data is being processed lies with the party alleging it. Documenting your pseudonymisation process precisely - hash length, use of a salt, key rotation, retention period - is what makes your position defensible.
- Time is a risk variable: eight years passed between the start of the processing (2018) and the final decision (2026). A challenged decision is not a closed decision, and in the meantime the provision stays on the client's balance sheet.
- In the Art. 30 records, visitor counting should be logged as a processing activity in its own right, with its purpose and legal basis, even where the controller argues the data is anonymous. If it truly is anonymous, write it down and explain why: that explanation is what serves you on inspection day.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free