Back to Feed
GDPRJul 31, 2026

RVS - 202401622/1/A3

Netherlands Council of State upholds annulment of €600,000 GDPR fine due to insufficient DPA proof that pseudonymised

Summary

The Dutch Council of State (RVS) upheld the annulment of a €600,000 fine imposed by the Dutch Data Protection Authority (DPA) on Enschede's Municipal Executive for processing pseudonymised MAC addresses and location data from Wi-Fi sensors without legal basis. The court found the DPA failed to sufficiently prove that the data constituted personal data under GDPR Article 4(1), as the DPA did not adequately investigate whether the three proposed re-identification methods were realistically available. The DPA attempted to introduce new arguments on appeal but was barred from doing so, as regulatory authorities must conclusively substantiate violations during the administrative decision-making process, not at the judicial stage.

Full text

Help RVS - 202401622/1/A3: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 10:49, 31 July 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators230 edits Tag: Decisions [1.0] (No difference) Latest revision as of 10:49, 31 July 2026 RVS - 202401622/1/A3 Court: RVS (Netherlands) Jurisdiction: Netherlands Relevant Law: Article 4(1) GDPR Article 5(1)(a) GDPR Article 6 GDPR Recital 26 GDPR Decided: 29.07.2026 Published: 29.07.2026 Parties: Municipal Executive Board of Enschede National Case Number/Name: 202401622/1/A3 European Case Law Identifier: ECLI:NL:RVS:2026:4403 Appeal from: District Court of OverijsselNo. 22/775 Appeal to: Unknown Original Language(s): Dutch; Flemish Original Source: Rechtspraak.nl (in Dutch; Flemish) Initial Contributor: bms The Council of State upheld the annulment of a €600,000 fine because the DPA had not proven during the administrative proceedings that pseudonymised MAC and location data constituted personal data. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Municipal Executive of Enschede, the controller, decided to conduct continuous pedestrian counts to obtain information about visitor numbers in the city centre. From 25 May 2018, at least ten sensors captured the MAC addresses of devices with Wi-Fi enabled. When a sensor detected a MAC address, it was temporarily stored and converted into a pseudonymised MAC address using an algorithm. Since all sensors used the same algorithm, the same device received the same pseudonymised identifier across different locations. The resulting data included the sensor that detected the device and the date and time of detection. After several filters were applied, the data was retained for up to six months and used to estimate the number of unique visitors. The controller discontinued the pedestrian-counting system on 1 May 2020. Following an enforcement request, the Autoriteit Persoonsgegevens, the DPA, investigated the processing. It considered that the combination of pseudonymised MAC addresses and location data related to identifiable natural persons. According to the DPA, the data allowed individuals to be distinguished and could reveal lifestyle and behavioural patterns. It also identified three methods through which the controller could potentially determine the identity of device users. On 11 March 2021, the DPA imposed a fine of €600,000 on the controller for processing personal data without a legal basis between 25 May 2018 and 30 April 2020. It considered the controller responsible for determining the purposes and means of the processing and found that no legal basis under Article 6 GDPR had been established. The controller challenged the decision before the District Court of Overijssel. The Court held that the DPA had not sufficiently proven that the information processed by the controller constituted personal data. In particular, the DPA had relied on assumptions regarding the possibility of identifying device users without sufficiently investigating whether those identification methods were realistically available. The Court held that, under Recital 26 GDPR, the DPA should have assessed whether the means allegedly available to identify the individuals were reasonably likely to be used, taking into account the costs, time, available technology and technological developments. It therefore annulled the decision on the objection and revoked the original fine. The DPA appealed the judgment before the Council of State. Holding The High Court dismissed the DPA’s appeal and upheld the annulment of the €600,000 fine. The High Court noted that the DPA did not challenge the Court’s finding that it had failed to sufficiently investigate and substantiate the three methods through which the controller could allegedly identify individual device users. During the appeal hearing, the DPA also acknowledged that the applicable standard of proof had not been met regarding those methods. Instead, the DPA argued that natural persons had already been directly identified because the combination of MAC addresses and location data allowed the controller to distinguish and count unique visitors. According to the DPA, the ability to single out unique visitors was itself sufficient for the information to qualify as personal data under Article 4(1) GDPR, irrespective of whether the controller could determine their civil identity. However, the High Court held that the DPA had not relied on this reasoning in its original decision or in its decision on the controller’s objection. In proceedings concerning an administrative fine, the DPA must conclusively establish and substantiate the alleged infringement before completing the administrative decision-making process. This requirement safeguards legal certainty and allows the alleged infringer to defend itself effectively and in a timely manner. The DPA could not wait until the judicial appeal stage to introduce a new argument explaining why the processing concerned personal data and why a punishable infringement had occurred. The Court had therefore not erred by refusing to assess this new argument. Since the DPA had not otherwise challenged the substance of the Court’s finding that the original infringement had not been sufficiently proven, the annulment of the fine remained in effect. The High Court did not determine whether the pseudonymised MAC addresses and location data were, as such, personal data under the GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Dutch; Flemish original. Please refer to the Dutch; Flemish original for more details. 202401622/1/A3. Date of Decision: July 29, 2026 Section ADMINISTRATIVE LAW Decision on the appeal filed by: the Dutch Data Protection Authority (hereinafter: the AP), appellant, against the judgment of the District Court of Overijssel dated February 2, 2024, in Case No. 22/775 in the proceedings between: the Municipal Executive of Enschede and the AP. Course of the Proceedings By decision of March 11, 2021, the AP imposed an administrative fine on the Municipal Executive. By decision of April 6, 2022, the AP declared the objection filed by the Municipal Executive against that decision to be unfounded. In a judgment dated February 2, 2024, the court upheld the appeal filed by the Municipal Executive against that decision, annulled the decision of April 6, 2022, and revoked the decision of March 11, 2021. The AP filed an appeal against this judgment. The Board submitted a written statement. By decision of April 20, 2026, the Section’s Confidentiality Chamber granted a request by the AP to apply Article 8:29 of the General Administrative Law Act to confidential versions of a number of case documents. The Board granted the Section consent to obtain these documents. The AP submitted a supplementary brief. The Section heard the case at a hearing on May 21, 2026, at which the AP, represented by W. van Steenbergen, E. Nijhof, Esq., and V.B. Klos, and the Municipal Executive, represented by M.H. Elferink, Esq., and M.J.M. Kortier, Esq., attorneys in Enschede, and M. Nijkamp, appeared. Considerations Introduction 1. To gain insight into visitor numbers in Enschede’s city center, the Municipal Executive made the decision to conduct a continuous pedestrian count. The investigation conducted by the AP in response to an enforcement request reveals that, as of May 25, 2018, the municipal executive used at least ten sensors in the city center to capture the MAC addresses of devices with Wi-Fi enabled. A MAC address is, in principle, a unique identification number consisting of twelve hexadecimal characters (0–9, A–F) assigned to a device’s network card. As soon as a sensor

Entities

Dutch Data Protection Authority (Autoriteit Persoonsgegevens) (vendor)Wi-Fi MAC address pedestrian counting system (product)