The Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, published advice on July 17, 2026 setting out 11 conditions that government implementing bodies and supervisory authorities must meet before registering, retaining or acting on unsolicited fraud tips. The guidance, titled Advies verwerking persoonsgegevens fraudesignalen, is aimed squarely at agencies distributing benefits, subsidies, credits and other financial support, plus regulators who receive anonymous reports about possible fraud or non-compliance — but the AP says the reasoning extends to any organization, including accountants, that investigates clients on the strength of a tip.
The case for fraud-tip processing
The strongest argument for letting agencies act quickly on fraud signals is straightforward: welfare fraud, subsidy abuse and tax evasion cost the public money, and anonymous tip lines are often the only practical way to surface sophisticated schemes before they compound. Demanding full verification before an agency may even log a tip risks making tip lines useless — which mainly benefits people actually committing fraud. Regulators and benefits administrators have a legitimate, arguably urgent, interest in triaging signals fast, and Dutch supervisory bodies have relied on citizen and third-party reporting for decades as a low-cost enforcement multiplier.
Why the AP intervened anyway
That argument runs into a documented failure mode: the Belastingdienst's Fraude Signalering Voorziening (FSV). Dutch tax authorities operated an internal fraud blacklist from 2013 until March 2020 — with predecessor systems dating to 2001 — that ultimately held records on roughly 270,000 people, including some 2,000 minors, according to NOS. The AP's investigation found the list had no legal basis, contained inaccurate entries, was inadequately secured, and — most damaging — that caseworkers were instructed to weigh nationality and physical appearance in fraud-risk scoring. The AP fined the Ministry of Finance €3.7 million in April 2022, a penalty Taxence described as a record at the time. FSV entries followed people for years, affecting benefit and tax decisions, without the individuals ever being told they were on the list.
The new advisory is best read as the AP converting that post-mortem into a checklist regulators can apply before the next FSV happens, rather than after.
What the 11 conditions actually require
According to Accountancy Vanmorgen, the conditions include: agencies must document, in advance, why processing a given category of fraud signal is necessary — "the mere assumption that a signal could be useful for supervision or enforcement is insufficient"; a cooperation agreement (convenant) between agencies cannot by itself serve as a legal basis for sharing personal data; signal reliability must be assessed on an ongoing basis, and tips traceable to personal grudges or mistaken identity must be deleted rather than retained "just in case"; data tied to suspected criminal conduct gets extra safeguards as special-category data; agencies must use the word "fraud" precisely rather than applying it to unproven allegations, to avoid stigmatizing people who turn out to be innocent; and — notably — the AP explicitly advises against using "AI, algorithms and chatbots" to assess the reliability of incoming signals. Individuals who are the subject of a report must generally be informed within one month, unless notification would seriously impede an active investigation.
None of this is new law. It is the AP's application of existing GDPR necessity, purpose-limitation and transparency principles to a specific, recurring government activity — which is exactly why agencies should treat it as a preview of what the AP will consider defensible the next time it opens an investigation.
The proportionate reading
Most of the checklist is difficult to object to on innovation grounds. Requiring a documented legal basis before repurposing a tip, deleting tips traceable to personal disputes, and notifying people within a month are low-cost procedural steps that plainly would have prevented the worst FSV harms — the six-year retention of unverified, ethnically-skewed entries with zero transparency to the people affected. Agencies that adopt this checklist now are, in effect, buying insurance against a multi-million-euro fine later.
The one condition worth pushing back on is the blanket steer away from AI and algorithmic triage. Manual review scales poorly against the volume of tips a national tax or benefits agency receives, and a well-audited model with a documented decision log and mandatory human sign-off can be more consistent — and more auditable after the fact — than a caseworker's informal judgment, which is precisely what went wrong inside FSV. The AP's own investigation found the underlying failure was undocumented criteria and unaccountable discretion, not automation per se. A rule requiring meaningful human review, logged reasoning and regular accuracy audits for any AI-assisted triage would target that failure directly, without pushing agencies toward slower, equally unaccountable manual processes that happen to lack a machine-learning label attached to them.
Still, as regulatory guidance goes, this is a narrow, evidence-driven response to a fine the AP itself already litigated — not speculative pre-emptive regulation. That distinguishes it from broader data-processing restrictions elsewhere in Europe, and it is the kind of enforcement clarity that gives compliance teams something concrete to build against.