Municipal Executive Board of Enschede – Court Ruling (Netherlands, 2026)

Court Ruling
DPA29 July 2026Netherlands
final
Court Ruling

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Municipal Executive Board of Enschede was investigated for tracking pedestrians using Wi-Fi data without proper legal grounds. This ruling emphasizes the need for transparency and consent in data collection practices.

What happened

Enschede collected and processed Wi-Fi MAC addresses from pedestrians to count visitors without a valid legal basis.

Who was affected

Visitors to the city center whose devices were tracked by the Wi-Fi sensors.

What the authority found

The DPA determined that Enschede's data processing violated GDPR because it lacked a legal basis for tracking individuals.

Why this matters

This case highlights the importance of obtaining proper consent and having a legal basis for data collection. Businesses and municipalities should carefully evaluate their data practices to comply with privacy laws.

GDPR Articles Cited

AI-verified

Art. 6(GDPR)
Art. 4(1) GDPR
Art. 5(1)(a) GDPR
View original scraped data
Art. 4(1) GDPR
Art. 5(1)(a) GDPR
Art. 6(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Recital 26 GDPR
Decision AuthorityRvS
Reviewed AuthorityDistrict Court of Overijssel
Source verified 1 August 2026
articles corrected
authority corrected
Full Legal Summary
Detailed

The Municipal Executive Board of Enschede, the controller, decided to conduct continuous pedestrian counts to obtain information about visitor numbers in the city centre. From 25 May 2018, at least ten sensors captured the Media Access Control (hereinafter, MAC) addresses of devices with Wi-Fi enabled. When a sensor detected a MAC address, it was temporarily stored and converted into a pseudonymised MAC address using an algorithm. Since all sensors used the same algorithm, the same device received the same pseudonymised identifier across different locations. The resulting data included the sensor that detected the device and the date and time of detection. After several filters were applied, the data was retained for up to six months and used to estimate the number of unique visitors. The controller discontinued the pedestrian-counting system on 1 May 2020. Following an enforcement request, the Autoriteit Persoonsgegevens, the DPA, investigated the processing. It considered that the combination of pseudonymised MAC addresses and location data related to identifiable natural persons. According to the DPA, the data allowed individuals to be distinguished and could reveal lifestyle and behavioural patterns. It also identified three methods through which the controller could potentially determine the identity of device users. On 11 March 2021, the DPA imposed a fine of €600,000 on the controller for processing personal data without a legal basis between 25 May 2018 and 30 April 2020. It considered the controller responsible for determining the purposes and means of the processing and found that no legal basis under Article 6 GDPR had been established. The controller challenged the decision before the District Court of Overijssel. The Court held that the DPA had not sufficiently proven that the information processed by the controller constituted personal data. In particular, the DPA had relied on assumptions regarding the possibility of identifying device users without s

Outcome

Court Ruling

A ruling by a national court on a data-protection matter.

Related Cases (0)

No other cases found for Municipal Executive Board of Enschede in NL

This is the only recorded case for this entity in this jurisdiction.

Details

Ruling Date

29 July 2026

Authority

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Municipal Executive Board of Enschede - Netherlands (2026). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: