Kindred Group PLC – Court Ruling (Netherlands, 2026)

Court Ruling
DPA RbDenHaag27 May 2026Netherlands
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A Dutch court ruled that Kindred Group PLC and Risepoint Limited did not provide requested access to personal data from users. This decision underscores the obligation of companies to comply with data access requests under GDPR. Small businesses should be aware of their responsibilities regarding user data access.

What happened

Kindred Group and Risepoint failed to grant data subjects access to their personal transaction data as required by GDPR.

Who was affected

Users of Kindred Group's online gambling products were affected by the companies' refusal to provide data access.

What the authority found

The court confirmed that both companies were responsible for complying with data access requests under GDPR.

Why this matters

This ruling reinforces the importance of transparency and user rights in data handling. Companies must be prepared to fulfill access requests to avoid legal challenges.

GDPR Articles Cited

AI-verified

Art. 15(GDPR)
Art. 23(GDPR)
Art. 4(7) GDPR
Art. 12(5) GDPR
Art. 15(4) GDPR
View original scraped data
Art. 4(7) GDPR
Art. 12(5) GDPR
Art. 15(GDPR)
Art. 15(4) GDPR
Art. 23(GDPR)

Original data from scraper before AI verification against source document.

Decision AuthorityRbDenHaag

Entities Involved

Kindred Group PLC0(controller)
Risepoint Limited0(controller)
Source verified 1 July 2026
entity split needed
Full Legal Summary
Detailed

Kindred Group PLC and Risepoint Limited (the controllers) are companies that provide online gambling products. Several companies within Kindred Group PLC (Risepoint was initially in this group) offered online gambling products before a national law requiring a license entered into force. In response, several lawsuits were filed before courts regarding the validity of the gambling agreements between players and unlicensed online gambling providers. Several data subjects later requested access (Article 15 GDPR, or in the alternative, the right to portability under Article 20 GDPR) to the controller to receive information on specific transaction data and the types of games they participated in. The data subjects did not receive access and brought a claim to the court. The data subjects requested the court to hold both companies liable (jointly or separately) The court initially dismissed the claim based on the code of civil procedure, but allowed the data subjects to amend their arguments regarding the GDPR. Both companies argued that they were not controllers, and that the requests made by the data subjects were abusive. According to the companies, the data subjects requested access for the sole purpose of bringing legal actions against them. Finally, the companies argued that they did not have the obligation to comply with the requests under Article 15(4) GDPR. The court first clarified that both Kindred Group PLC and Risepoint Limited were controllers. Kindred Group PLC argued that it did not exercise any decisive influence over the purpose and means of processing. The court took into consideration the functional definition of “controller” under Article 4(7) GDPR and CJEU case law, rather than a formal definition.See cases C-40/17 (Fashion ID), margin 65; C-210/16 (Wirtschaftsakademie Schleswig-Holstein), margins 26 and 27 The court found that Kindred Group PLC was a controller for access made between May and October 2024, but not for requests made after October

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Related Cases (0)

No other cases found for Kindred Group PLC in NL

This is the only recorded case for this entity in this jurisdiction.

Details

Ruling Date

27 May 2026

Authority

DPA RbDenHaag

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Kindred Group PLC - Netherlands (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: