The Dutch Council of State (Raad van State) ruled on July 29, 2026 that a lower court was right to annul the €600,000 fine the Autoriteit Persoonsgegevens (AP) imposed on the municipality of Enschede for tracking pedestrians' wifi signals. It is a resounding loss for the AP — but a narrower one than the headlines suggest, and it says less about the legality of wifi-tracking than about the evidentiary discipline regulators owe the people they punish.
What Enschede actually did
Starting in 2018, Enschede installed sensors across its shopping streets to measure foot traffic. The boxes captured MAC addresses broadcast by nearby phones with wifi enabled, assigned each device a pseudonymous code, and used the codes to count unique visitors and map movement patterns through roughly 2020. In March 2021 the AP fined the municipality €600,000 — its first-ever GDPR fine against a Dutch government body — arguing that combining device codes with location data amounted to processing personal data without a legal basis.
The AP's case — and its real weakness
The AP's underlying instinct was not unreasonable. Regulators are right to worry that a device code plus a timestamped location trail can, in the wrong hands, become a movement diary. The agency's then-deputy chair Monique Verdier framed the stakes bluntly: "Nobody should be able to track what shops, doctors, churches or mosques we visit" (Pinsent Masons). The AP's theory of harm was that Enschede's sensors could, in principle, be cross-referenced with CCTV footage during quiet periods to re-identify specific people — exactly the kind of pseudonymisation-isn't-anonymisation argument that has real teeth under GDPR.
The problem was proof, not theory. When Rechtbank Overijssel first annulled the fine on February 2, 2024 (ECLI:NL:RBOVE:2024:594), it found that the AP had not actually investigated how much time, money, and specialised skill re-identification would take — it had asserted the possibility rather than demonstrated it. Dutch administrative law puts the burden of proof for a violation squarely on the enforcer at the moment it issues the penalty, precisely so the accused can mount a timely defence against a concrete case, not a hypothetical one.
Two courts, one answer: prove it
The Council of State's July 29, 2026 ruling did not reopen that factual question — it confirmed the district court got the standard right. The AP tried a different tack on appeal, arguing that the mere act of counting unique visitors was itself a form of identification. The Council of State refused to consider it, because that argument was never part of the original 2021 fining decision. Regulators cannot retroactively substitute a stronger legal theory for one that failed on its own terms; the case a defendant answers has to be the case actually charged.
"The AP's argument — raised only during appeal — that MAC addresses combined with location data constituted personal identification, was inadmissible since it wasn't part of the original decision-making process." — summary of the Council of State's reasoning, via Dutch Brief
That makes this a procedural defeat, not a substantive vindication of wifi-tracking. The court explicitly left open whether Enschede's system did, in fact, process personal data — it only held that the AP failed to establish that it did, with the evidence the AP actually put on the table in 2021.
Why this matters beyond one Dutch city
Municipalities across Europe are deploying similar sensor networks for crowd management, traffic planning, and retail-footfall analytics — often pitched as privacy-friendly because the raw MAC address is hashed or truncated before storage. This ruling doesn't hand them a green light. It tells regulators, correctly, that "this data could theoretically be re-identified" is not a substitute for showing that re-identification was reasonably likely given the actual cost, effort, and available auxiliary data at the time of the alleged violation — the standard GDPR's identifiability test (recital 26) already demands, and which the AP simply didn't apply with enough rigor here.
The better lesson
The pro-innovation reading of this case isn't "wifi-tracking is fine now." It's that enforcement built on a plausible-sounding privacy story, rather than an investigated one, invites exactly the kind of multi-year reversal Enschede just won — five years of litigation over a fine the AP's own evidentiary file couldn't support. That serves nobody: not the municipality that spent years and legal fees fighting an unproven charge, not the public interest in genuinely accountable public-sector data use, and not the AP's own credibility as an enforcer. If Dutch and EU regulators want cities to take wifi-based and similar pseudonymous sensing seriously as a privacy question — which they should — the fix is sharper guidance on what counts as reasonably likely re-identification, backed by actual investigation, not broader fines built on weaker proof.