Municipality of Veenendaal – €25,000 Fine (Netherlands, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Municipality of Veenendaal was fined €25,000 for improperly processing data about the Islamic community. This is important because it shows that municipalities need to have a valid reason for collecting sensitive data, especially during times of heightened security concerns. Other local governments should ensure they comply with data protection laws to avoid penalties.
What happened
The Municipality of Veenendaal processed data about the Islamic community using force field analysis without a valid legal basis.
Who was affected
Individuals in the Islamic community in Veenendaal whose personal data was collected and analyzed.
What the authority found
The Dutch data protection authority found that the municipality did not have a valid legal basis for processing sensitive data, violating GDPR requirements.
Why this matters
This ruling serves as a reminder that municipalities must be careful when handling sensitive information. Other local governments should evaluate their data practices to ensure compliance with privacy laws.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic community in its municipality using a force field analysis, for which it employed an external processor. This processing took place at a time of heightened societal concern about Islamic extremism and terrorism. During this period, the Dutch government and the National Coordinator for Security and Counterterrorism stepped up measures against Salafist and ideological threats to the democratic legal order posed by Islamic radicals. One of these measures was a robust local approach to tackling radicalisation and travel to jihadist conflict areas. Municipalities played a central role in these measures but found that they lacked sufficient insight into Islamic communities. This resulted in some municipalities, including the controller, using an external research agency to collect the necessary data. The agency then used the so-called force field analysis method to map out social structures and key figures. This data processing took place without a sufficient legal basis, particularly as the processing focused on religious and political beliefs, and therefore on special category data.
Related Enforcement Actions (0)
No other enforcement actions found for Municipality of Veenendaal in NL
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
3 February 2026
Authority
Autoriteit Persoonsgegevens
Fine Amount
€25,000
Enforcement Tracker ID
ETid-3040
About this data
Cite as: Cookie Fines. Municipality of Veenendaal - Netherlands (2026). Retrieved from cookiefines.eu
Last updated: