Skip to main content
Authority

Autoriteit Persoonsgegevens (AP)

The Autoriteit Persoonsgegevens is the Dutch data protection authority. For a licensed financial institution it matters in three places: personal data processing under the GDPR, the 72-hour breach notification that runs alongside DORA incident reporting, and anti-money-laundering monitoring, where the AP has taken a public position against large-scale transaction surveillance.

Checked by Remmert
6 min read

What is the AP responsible for?

The AP supervises compliance with the GDPR and the Dutch GDPR Implementation Act (UAVG) across every sector, public and private (AP, tasks and powers). Since 2023 it has also housed the Department for the Coordination of Algorithmic Oversight (DCA), which coordinates algorithm and AI risk supervision across Dutch regulators. The DCA's budget grows from 1 million euros a year in 2023 to 3.6 million euros in 2026 (AP, DCA).

Geert Potjewijd took office as chair on 1 August 2026, two weeks before this page was written, succeeding Aleid Wolfsen after exactly ten years (appointment announcement, 13 May 2026). Any AP guidance written before that date predates the current chair.

Last updated: 17 August 2026. First version of this page, written after Regulation (EU) 2026/1744 moved the Annex III high-risk date to 2 December 2027.

Key facts

What does the AP handle, in volume?

Complaints rose sharply. The AP received 13,500 complaints in 2025, a 75% increase on 2024, including 400 complaints tied to a single breach at Clinical Diagnostics affecting 850,000 people (AP, Rapportage klachten 2025, reported 8 June 2026). On breaches, the most recent full-year figure we could confirm is 37,839 notifications in 2024, of which 26,815 were followed up and 28 investigated in detail. Of those, 1,430 were caused by cyberattacks, 9% more than in 2023, at an average cost of 103,976 euros and a median of 30,000 euros (AP, Datalekkenrapportage 2024).

No published sector breakdown separates financial institutions from the total. We do not have that number and will not estimate it.

Which rules does the AP enforce, and where does the AI Act sit?

The AP enforces the GDPR and the UAVG. Its role under the EU AI Act in the Netherlands is not yet settled law. On 20 April 2026 the cabinet published a draft AI Act implementing act (Uitvoeringswet AI-verordening) for consultation, which closed on 1 June 2026. The draft designates ten market surveillance authorities, among them the AP, RDI, AFM and DNB (Rijksoverheid, 20 April 2026).

Under that draft, the AP takes prohibited practices, transparency obligations and high-risk AI in areas such as recruitment and benefits, while the AFM and DNB supervise AI inside their own financial-sector remits. The AP and RDI hold coordinating roles and are to launch a joint AI regulatory sandbox during 2026. As at 17 August 2026 the bill still has to pass both chambers.

For a bank or insurer, the practical reading is this: your AI Act supervisor is likely to be your existing financial supervisor, with the AP setting cross-sector interpretation.

What does the AP publish, and how often?

The AP publishes the AI and Algorithmic Risks Report Netherlands (RAN) twice a year, five editions so far, most recently in July 2025, plus an annual report, annual complaint and data-breach reports, guidance and normuitleg, fine decisions and consultations. The RAN is the publication to watch if you use AI: it sets out Dutch supervisory expectations on algorithms before they become enforcement.

What has the AP published recently?

DatePublication

Which deadlines does the AP own?

2025

  1. 2 February 2025Passed

    AI Act prohibitions and the AI literacy obligation apply

  2. 2 August 2025Passed

    Governance rules and general-purpose AI obligations apply

2026

  1. 2 August 2026Passed

    General application of the AI Act, including transparency obligations

2027

  1. 2 December 2027Upcoming

    Annex III high-risk AI obligations apply

2028

  1. 2 August 2028Upcoming

    High-risk AI embedded in regulated products applies

No fixed date

  1. Consultation closed 1 Jun 2026Recurring

    Dutch AI Act implementing act pending

  2. During 2026Expected

    AP and RDI to launch a joint AI regulatory sandbox

What does the AP's enforcement look like, and where does it touch finance?

The AP's most consequential intervention for financial institutions is not a fine. On 14 July 2023 it wrote to the Ministry of Finance opposing the plan for continuous, centralised monitoring of transactions, a scheme it described as covering roughly 10 billion transactions a year from some 35 million clients. It called the plan a serious interference with the fundamental right to data protection, warned that pseudonymisation does not cure the proportionality problem, and flagged discrimination and exclusion risks (AP letter, 14 July 2023).

That letter is three years old and remains the AP's clearest published position on AML monitoring. It is the reason Dutch banks' joint transaction-monitoring plans have advanced slowly, and it is the tension a Wwft programme has to be designed around: the Wwft asks you to monitor, the GDPR asks you to justify how much.

What changes for a financial institution?

Three obligations sit next to your prudential ones. A personal data breach must be notified to the AP within 72 hours under GDPR Article 33, a clock that runs in parallel with, and on different criteria from, DORA major incident reporting to DNB or the AFM. A data protection impact assessment is required for high-risk processing under Article 35, which covers most large-scale customer profiling and transaction monitoring. And from 2 December 2027, credit scoring of natural persons and life and health insurance pricing become high-risk AI systems, supervised, on the current draft Dutch bill, by your financial supervisor rather than the AP.

What can GenCompl.ai do for you?

We track the AP's publications, the RAN cycle and the Dutch AI Act implementation file, and date each change, because the answer to "who supervises our AI" is currently a moving object in Dutch law. Our position is to show which obligations are in force, which are proposed, and the date each was last checked, rather than presenting a draft bill as settled.

Sources

Regulations

  • EU Artificial Intelligence Act (EU AI Act)

    The EU AI Act is Regulation (EU) 2024/1689. On 2 August 2026 its transparency rules and enforcement machinery took effect, but the high-risk regime for credit scoring and life and health insurance pricing did not: Regulation (EU) 2026/1744 moved it to 2 December 2027. Prohibitions have applied since February 2025.

    NextNew Art. 5 prohibitions; Art. 50(2) marking deadline for pre-existing generative systems

    Checked

  • Digital Operational Resilience Act (DORA)

    DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.

    NextNext register of information cycle, reference date expected 31 December 2026

    Checked

  • Anti-Money Laundering Regulation (AMLR)

    The AMLR is Regulation (EU) 2024/1624. It applies from 10 July 2027 and is directly applicable, so from that date customer due diligence, beneficial ownership, reporting and internal controls come from EU law rather than national statute. Cash payments for goods and services are capped at €10,000. Football clubs and agents follow on 10 July 2029.

    NextAMLR applies (Art. 90) and the AMLD6 transposition deadline. References to Directive (EU) 2015/849 are construed as references to the AMLR and AMLD6, per the correlation table in Annex VI (Art. 89); the repeal itself sits in AMLD6

    Checked