Your cookie preferences

EDPB guidance · Art. 7 GDPR

We use technical cookies essential for the platform to work (login, security, sessions). We would also like to use analytics cookies to understand how to improve it.

You can accept all, reject all, or choose which categories to switch on.Your consent is valid for 6 months and you can withdraw it at any time from the footer.

You will find everything in our privacy notice.

All news
Regulation July 30, 2026 4 min

Netherlands and Poland: two authorities that raised the bar in 2026

The Dutch AP names transparency, tracking and cookies as priorities; Poland's UODO shifts inspections towards SMEs. Two markets where the external DPO is worth more than before

TL;DR for the DPO

Two historically different authorities converge: the Netherlands focuses on transparency, tracking and cookies; Poland widens inspections to SMEs. The common theme is that the advisory phase is over in both countries.

The three points that matter

  • Netherlands: the AP has increased resources and staff and publishes its supervisory priorities on its website. That is the first place to look to understand where enforcement will concentrate, and it works as a method for any authority: declared priorities are public information that almost nobody reads.
  • Poland: inspections are moving towards SMEs. That is the segment which typically has formal documentation but misaligned processes: notices updated and consents collected, but no checks on suppliers or on the legal basis of flows to third parties.
  • In both countries the impact assessment duty is self-executing: Article 35 requires it BEFORE processing begins where the risk is high. It is not a duty triggered by an inspection, and it is precisely the sequence in time that is most often challenged.

What to do now, in practice

1) For clients present or with users in the Netherlands: the priority check is the cookie banner and tracking before consent, using the checks already described in earlier analyses; 2) for Poland: if the client is an SME, the typical weak point is not the documentation but the supplier chain - Art. 28 agreements, sub-processors, transfers; 3) generally, when entering a new market, the first useful read is the document in which the national authority states its priorities for the year: it is free, public, and tells you where they will look.

Why it matters for those working in Italy

Even staying in Italy, these two cases show a trend that concerns everyone: European authorities are moving from a phase of accompanying organisations to one of sanctioning them, and they are doing so on basic obligations, not sophisticated questions. The cookie banner, the supplier chain and the DPIA done before rather than after are the three things challenged everywhere, under different names.

Official source:Autoriteit Persoonsgegevens - sanctions and supervisory priorities published on the authority's website; Urzad Ochrony Danych Osobowych (UODO) - 2026 inspection orientations

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free