Municipal Executive Board of Enschede – Court Ruling (Netherlands, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Municipal Executive Board of Enschede was investigated for tracking pedestrians using Wi-Fi data without proper legal grounds. This ruling emphasizes the need for transparency and consent in data collection practices.
What happened
Enschede collected and processed Wi-Fi MAC addresses from pedestrians to count visitors without a valid legal basis.
Who was affected
Visitors to the city center whose devices were tracked by the Wi-Fi sensors.
What the authority found
The DPA determined that Enschede's data processing violated GDPR because it lacked a legal basis for tracking individuals.
Why this matters
This case highlights the importance of obtaining proper consent and having a legal basis for data collection. Businesses and municipalities should carefully evaluate their data practices to comply with privacy laws.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
The Municipal Executive Board of Enschede, the controller, decided to conduct continuous pedestrian counts to obtain information about visitor numbers in the city centre. From 25 May 2018, at least ten sensors captured the Media Access Control (hereinafter, MAC) addresses of devices with Wi-Fi enabled. When a sensor detected a MAC address, it was temporarily stored and converted into a pseudonymised MAC address using an algorithm. Since all sensors used the same algorithm, the same device received the same pseudonymised identifier across different locations. The resulting data included the sensor that detected the device and the date and time of detection. After several filters were applied, the data was retained for up to six months and used to estimate the number of unique visitors. The controller discontinued the pedestrian-counting system on 1 May 2020. Following an enforcement request, the Autoriteit Persoonsgegevens, the DPA, investigated the processing. It considered that the combination of pseudonymised MAC addresses and location data related to identifiable natural persons. According to the DPA, the data allowed individuals to be distinguished and could reveal lifestyle and behavioural patterns. It also identified three methods through which the controller could potentially determine the identity of device users. On 11 March 2021, the DPA imposed a fine of €600,000 on the controller for processing personal data without a legal basis between 25 May 2018 and 30 April 2020. It considered the controller responsible for determining the purposes and means of the processing and found that no legal basis under Article 6 GDPR had been established. The controller challenged the decision before the District Court of Overijssel. The Court held that the DPA had not sufficiently proven that the information processed by the controller constituted personal data. In particular, the DPA had relied on assumptions regarding the possibility of identifying device users without s
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (0)
No other cases found for Municipal Executive Board of Enschede in NL
This is the only recorded case for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Municipal Executive Board of Enschede - Netherlands (2026). Retrieved from cookiefines.eu
Last updated: