Starting 1 September 2026, organisations fined for GDPR violations in the Netherlands will no longer be able to keep their name out of the headlines. A new legal provision, Article 21b, will require the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) to publish sanctions together with the name of the organisation being penalised. What was once a discretionary practice becomes a legal obligation, and that shift carries real consequences for how businesses, associations, and event organisers handle personal data.
What Article 21b Actually Changes
Under the current system, the Dutch DPA has flexibility in how it discloses enforcement actions. Fines and corrective measures are sometimes published, sometimes summarised without naming the violator, and sometimes left out of public communications entirely. Article 21b removes that discretion. Once the rule takes effect, the AP will be obligated to name the sanctioned party whenever it issues a GDPR penalty.
This is a meaningful departure from how privacy enforcement has typically worked in the Netherlands. Fines have always been a financial risk, but from September 2026 they also become a guaranteed reputational event. A published sanction with a company's name attached is searchable, shareable, and permanent in a way that a quiet financial penalty never was. For organisations that rely on public trust, customer relationships, or partnerships with larger institutions, that visibility can matter as much as the fine itself.
It is worth noting that this development is specific to the Netherlands and to GDPR enforcement mechanics rather than a change to the substance of the regulation. The rules about what counts as a violation, lawful bases for processing data, or breach notification timelines are not changing. What is changing is transparency around who gets caught and penalised, and how visible that becomes to the public, to competitors, and to potential customers doing due diligence.
Why Event Organisers Should Pay Attention Now
The source reporting on this change specifically calls out event organisers as a group that should get its house in order before the rule takes effect. That makes sense: events routinely collect attendee data through registration forms, ticketing platforms, sponsor lead-capture tools, and marketing lists. Each of these touchpoints is a potential source of GDPR exposure, whether through inadequate consent language, unclear data retention policies, or third-party vendors handling data without proper agreements in place.
Until now, an organiser that fell short of GDPR requirements might absorb a fine quietly. After September 2026, that same organiser's name will be attached publicly to the violation, visible to future attendees, exhibitors, and sponsors evaluating whether to work with them again. For an industry built on repeat business and reputation, that is a different kind of risk calculus.
Practical housekeeping before the deadline includes reviewing registration and ticketing forms for clear consent language, auditing what data is collected and why, confirming that data processing agreements with ticketing platforms and marketing tools are current, and checking that data retention periods are actually being followed rather than just documented. None of this requires a legal overhaul, but it does require someone to actually check rather than assume compliance is in place.
A Pattern of Deadlines Across Data Protection Regimes
The Netherlands is not alone in tightening enforcement visibility around a specific date. Regulators in other jurisdictions have set similar compliance deadlines that organisations are working against. Zimbabwe's telecoms regulator, for instance, has confirmed it will begin actively policing data protection law from September 2026, a timeline that lands in the same month as the Dutch change. Switzerland took a similar step years earlier, when its revised Federal Act on Data Protection took effect for companies in September 2023, giving businesses a hard date to work toward rather than an open-ended expectation of compliance.
The common thread is that regulators increasingly favor concrete deadlines and public accountability over quiet, case-by-case enforcement. Organisations that wait until a rule is already in force tend to have less room to fix problems before they become public record.
What This Means For You
If you run an organisation that processes personal data in the Netherlands, whether that's an event company, a small business, or a nonprofit, the practical effect of Article 21b is straightforward: any future GDPR fine will carry your name in public records. That doesn't change your underlying legal obligations, but it raises the stakes for getting compliance right the first time. Reputational damage from a named fine can outlast the financial penalty itself, particularly for organisations whose customers or partners can easily search for public enforcement records before signing a contract.
For individuals whose data is collected by these organisations, the change is arguably a net positive. Greater transparency around who has been sanctioned gives consumers and event attendees more information when deciding which companies to trust with their personal details.
Key Takeaways
Before 1 September 2026 arrives, organisations operating in the Netherlands, especially those handling attendee, customer, or member data through registration and ticketing systems, should review consent language on all data collection forms, confirm data processing agreements with third-party vendors are up to date, verify that data retention practices match written policies, and address any known compliance gaps now rather than after a sanction becomes public. Acting early is the difference between quietly fixing a problem and having it permanently attached to your organisation's name in public enforcement records.




