TL;DR for the DPO
Two historically different authorities converge: the Netherlands focuses on transparency, tracking and cookies; Poland widens inspections to SMEs. The common theme is that the advisory phase is over in both countries.
The three points that matter
- Netherlands: the AP has increased resources and staff and publishes its supervisory priorities on its website. That is the first place to look to understand where enforcement will concentrate, and it works as a method for any authority: declared priorities are public information that almost nobody reads.
- Poland: inspections are moving towards SMEs. That is the segment which typically has formal documentation but misaligned processes: notices updated and consents collected, but no checks on suppliers or on the legal basis of flows to third parties.
- In both countries the impact assessment duty is self-executing: Article 35 requires it BEFORE processing begins where the risk is high. It is not a duty triggered by an inspection, and it is precisely the sequence in time that is most often challenged.
What to do now, in practice
1) For clients present or with users in the Netherlands: the priority check is the cookie banner and tracking before consent, using the checks already described in earlier analyses; 2) for Poland: if the client is an SME, the typical weak point is not the documentation but the supplier chain - Art. 28 agreements, sub-processors, transfers; 3) generally, when entering a new market, the first useful read is the document in which the national authority states its priorities for the year: it is free, public, and tells you where they will look.
Why it matters for those working in Italy
Even staying in Italy, these two cases show a trend that concerns everyone: European authorities are moving from a phase of accompanying organisations to one of sanctioning them, and they are doing so on basic obligations, not sophisticated questions. The cookie banner, the supplier chain and the DPIA done before rather than after are the three things challenged everywhere, under different names.
Official source:Autoriteit Persoonsgegevens - sanctions and supervisory priorities published on the authority's website; Urzad Ochrony Danych Osobowych (UODO) - 2026 inspection orientationsLooking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free