The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) has told government agencies and regulators exactly how they may — and may not — act on unsolicited tips about fraud. In formal advice published July 7, 2026, the AP set out 11 conditions that benefits agencies, tax authorities, and supervisory bodies must meet before processing personal data drawn from fraud or non-compliance signals: a predefined purpose for each use, strict data minimization, and — critically — a documented assessment of how reliable a tip actually is before anyone acts on it.
Why the AP Is Doing This Now
This is not abstract rulemaking. It is a regulator responding to the most consequential data-protection failure in modern Dutch governance. From 2013 to 2020, the Dutch Tax and Customs Administration ran the Fraud Signalling Facility (FSV), an internal blacklist that logged more than 540,000 signals on roughly 270,000 people, frequently without any legal basis for doing so, according to the AP's own investigation as reported by Clifford Chance. The AP fined the tax authority €3.7 million in April 2022 for the FSV's unlawful processing — on top of a separate €2.75 million fine the year before over discriminatory algorithmic profiling in childcare-benefit fraud detection, a scandal that forced the entire Dutch cabinet to resign in January 2021.
That history matters for how this guidance should be read. The AP is not inventing a hypothetical risk. It is codifying the lessons of a case where unverified, poorly governed fraud signals were fed into a supervisory system, treated as more reliable than they were, and ended up wrecking thousands of families' finances — many because a caseworker's suspicion, not evidence, triggered a benefits clawback. The steelman case for this guidance is strong: when a fraud signal can trigger a criminal referral, a benefits suspension, or a tax audit, the state has an obligation to know where that signal came from and whether it deserves the weight being placed on it. Purpose limitation and reliability vetting are not bureaucratic friction for its own sake — they are the specific safeguards the FSV case proved were missing.
What the 11 Conditions Actually Require
According to detailed Dutch coverage of the advice from Accountancy Vanmorgen, the conditions include: agencies must substantiate, per processing activity, that using personal data is both necessary and effective — a general policy justification is not enough; a covenant or cooperation agreement between agencies does not by itself create a lawful basis; signals that cannot be verified as reliable must be deleted rather than retained "just in case"; and data subjects generally must be notified within one month that they were the subject of a signal, with narrow exceptions for active investigations. The advice also singles out special-category and criminal data — the kind fraud tips routinely contain — for extra scrutiny given the risk of stigmatization.
Most notably, the AP explicitly discourages the use of AI, algorithms, and chatbots to assess whether a fraud signal is authentic or reliable. Given that algorithmic risk-scoring is exactly what produced the childcare-benefits disaster, the instinct is understandable. But it is also where this otherwise well-targeted guidance risks overshooting.
The Case for Caution on the AI Language
A blanket steer away from automated tools, rather than a requirement for human sign-off, audit trails, and explainability on any tool that is used, risks freezing agencies into slower, more expensive manual triage without actually fixing the underlying problem the FSV exposed — which was inadequate governance and accountability, not automation per se. A well-audited system that flags inconsistencies for human review, with logged reasoning and a right to contest, could plausibly do more to catch unreliable signals than an overworked caseworker skimming a queue. The AP's own generative-AI guidance elsewhere draws exactly that human-in-the-loop distinction rather than a categorical ban; applying a blunter standard here, to fraud signals specifically, creates an inconsistency agencies will have to navigate case by case.
The better reading of the guidance — and the one agencies should adopt — is that the AP is not banning automation outright but signaling deep skepticism toward using it as a substitute for documented human judgment on reliability. That is defensible. Codifying it as a near-prohibition, rather than a proportionate governance requirement, is not, and invites exactly the kind of vague, catch-all compliance answer the AP says it wants agencies to stop giving.
The Broader Signal
What makes this advice a useful model, despite that flaw, is its specificity. It doesn't ban fraud tip-offs, doesn't impose a new licensing regime, and doesn't create a private right of action. It tells public bodies, in concrete terms, what "lawful basis" and "necessity" mean in a context — anonymous tips — where those tests are easy to wave away. That is proportionate regulation responding to a documented failure, not regulation in search of a problem. Other GDPR regulators overseeing similar fraud-detection systems, particularly in benefits and tax administration, would do well to study both halves of this advice: the sound reliability-vetting core, and the overcorrection on automated tools worth pressure-testing before it hardens into de facto policy.