GDPR Fines Going Public: What It Means for Your Business

Privacy law is evolving fast. The Dutch Data Protection Authority (AP) already imposes sanctions on organisations that breach GDPR, and a political proposal now wants to go further: making fines mandatory public. For freelancers and small businesses, this is the moment to take GDPR compliance seriously. Here is what is happening, what you are required to do under current rules, and how to reduce your risk.

Not legal advice. Consult a legal specialist for your specific situation.

What does GDPR require from freelancers and SMEs?

According to the Dutch Data Protection Authority, the General Data Protection Regulation applies to every organisation that processes personal data, including the solo web designer, the small accountant, or the five-person marketing agency. The AP states that there are no exemptions based on size or legal form.

The three core obligations:

Obligation What it means
Legal basis GDPR requires a valid legal ground for every processing activity (consent, contract, legal obligation, etc.)
Transparency Data subjects must know what you do with their data, via a privacy statement
Security You must take appropriate technical and organisational measures to prevent data breaches

For example: if you work as an IT consultant and store client contacts, project notes and time records in an online platform, all of that data falls under GDPR. Process it without a legal basis or retention policy, and you risk enforcement action.

For time tracking and client data in particular, think carefully about retention periods. Read more in GDPR & Time Tracking: Legal Basis, Location Data.

How does the AP enforce GDPR today?

GDPR shield protecting personal data

The Dutch Data Protection Authority is the legally authorised supervisory body in the Netherlands. It can issue warnings, impose penalty orders or levy administrative fines.

Currently, a fine is only published after it becomes formally irrevocable. As long as an organisation objects or appeals, the case remains internal. This protects businesses from reputational damage before a decision is final, but it also limits the deterrent effect.

That is precisely the gap a political proposal by NSC aims to close: publishing AP fines earlier in the process. The stated goals are:

  1. Increase the AP's visibility
  2. Create a stronger deterrent against violations
  3. Allow organisations to learn from each other's mistakes

Note: this is a political proposal, not enacted legislation. Status may change. Monitor progress via official parliamentary documents.

Get your privacy administration in order today with PrikKlokPlus features, from time tracking to CRM.

What does mandatory publication mean for your reputation?

If this proposal becomes law, the stakes change significantly: a GDPR violation will no longer be just a financial risk. It will be a reputational one, visible to clients, partners and competitors.

For SMEs and freelancers, that is especially sensitive. Your client relationships are your most valuable asset. One published fine, however small, can erode trust built over years.

That makes it worthwhile to act now:

  • Publish an up-to-date privacy statement on your website
  • Document the legal basis for each processing activity
  • Maintain a processing register (the AP states this is mandatory for 250+ employees; recommended for smaller organisations)
  • Report data breaches to the AP within 72 hours when individuals are at risk

Learn how to manage client data securely in CRM Data Security: What Supply Chain Risks Teach You.

AI tools and additional obligations from 2026

There is another layer to consider. From 2026, the EU AI Act introduces additional obligations for websites that integrate third-party AI tools. The responsibility for transparency lies with the website operator, even if you simply add a chat widget or analytics tool from an external provider.

The EU AI Act provides for significant fines in cases of serious violations. This affects businesses that have expanded their website or client communications with AI-powered tools.

What you can do now:

The combination of GDPR, mandatory fine publication and the AI Act makes privacy a strategic issue, not just a legal checklist.

Conclusion

GDPR already applies, enforcement already exists, and the reputational stakes are about to rise. For freelancers and SMEs the message is clear: do not wait for new legislation. Establish your legal basis, keep your privacy statement current and make sure client data is stored securely. Sort this out now and you will be better positioned, even if fines become public.


Frequently asked questions

Does GDPR apply to me as a sole trader? Yes. The AP states that GDPR makes no distinction based on business structure or size. The moment you process personal data, even just a client list with names and email addresses, you are a data controller and all GDPR obligations apply.

When does the AP publish a fine? Currently, publication only occurs once a fine is formally irrevocable. While you object or appeal, the case remains internal. The NSC proposal aims to change this, but it is not yet law.

Do I need a processing register as a small business? The AP states that a processing register is formally only mandatory for organisations with 250 or more employees, unless the processing carries risks or occurs regularly. In practice, keeping a concise register is sensible for everyone. It helps you demonstrate that you handle personal data responsibly.

What should I do in the event of a data breach? According to the AP, you are required to report any breach posing a risk to individuals to the Dutch DPA within 72 hours. More information at autoriteitpersoonsgegevens.nl.

Do AI tools bring additional obligations? Yes. From 2026, the EU AI Act introduces additional transparency requirements for websites using third-party AI tools. The responsibility lies with you as the website operator, even for straightforward integrations.


Take the first step today

Manage your client data, time tracking and project administration securely and in line with GDPR.

Try PrikKlokPlus free today →