GDPR
Netherlands GDPR Complaints Surge in 2025: What It Means
By Steven | TrustYourWebsite2 min read
Source: Security.NL
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) reportedly received more than 13,000 privacy complaints and signals in 2025, up from 7,100 the year before. According to Security.NL, which reported on the AP's 2025 annual report, this sharp rise shows that more people in the Netherlands are aware of their rights under the GDPR (AVG) and know how to report concerns.
A Major Data Breach Drove Many Complaints
According to Security.NL, a significant share of the complaints related to a data breach at Clinical Diagnostics, in which sensitive data belonging to more than 900,000 people was stolen. People who filed complaints reportedly said they received little information about what had happened and felt their concerns were not taken seriously. Some women reported feeling unsafe because their home addresses had been leaked.
Following the breach, the AP reportedly started a supervisory process involving Clinical Diagnostics and Bevolkingsonderzoek Nederland, focused on ensuring that victims were properly informed. The fact sheet notes that the outcome of this process has not been stated.
Thousands of Complaints Still Waiting
According to Security.NL, of the more than 13,000 complaints and signals received in 2025, more than 11,000 were handled. Around two thousand complaints are still waiting to be processed. The AP has reportedly acknowledged that waiting times are increasing, which it describes as an important concern.
To handle complaints more efficiently, the AP reportedly began making faster telephone contact with people and organisations to resolve issues directly. The authority also says it is increasingly using on-site supervisory visits to address situations affecting large numbers of people in one go.
What does this mean for your website?
If your business collects personal data, such as customer names, email addresses or health information, you are required under the GDPR (AVG) to handle that data responsibly and to inform people clearly if something goes wrong. The growing number of complaints shows that people are increasingly willing to report concerns to the AP, so it is worth checking that your privacy practices are in order. You can use our GDPR compliance checklist and privacy policy guide as a starting point.
Check your website now
Free website scan covering GDPR, copyright, accessibility, security, and more.
Start free checkRelated articles
GDPR
Digital Omnibus Report: noyb Analysis & EDPB Opinion
noyb published version 3 of its Digital Omnibus analysis report on 24 February 2026, adding commentary on the joint EDPB/EDPS opinion on the data part of the Digital Omnibus published on 11 February…
2 min read
GDPR
GDPR Access Requests: 83.5% Failed, Says noyb
noyb analysis of 121 access requests filed since 2018 found that 83.5% were not answered in line with the law, with only 16.5% receiving a satisfactory reply.
2 min read
GDPR
Dutch AP Warns: Orgs Fail to Limit Data Breach Impact
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) published a position paper stating that many organisations fail to take measures to limit the impact of data breaches, ahead of a…
2 min read