Netherlands Netherlands AP GDPR enforcement

Netherlands' New Fraud-Signal Rules Blame AI for a Governance Failure That Predates It

The Dutch DPA's 11 conditions on fraud-tip data are sound GDPR housekeeping, but its blanket steer away from AI conflates automation with the real causes of the FSV scandal.

Dutch DPA's Fraud-Signal Guidance, By the Numbers People of Internet Research · Netherlands 11 Conditions set by AP Formal guidance issued July 7, 202… €3.7M Belastingdienst FSV fine AP's 2022 penalty for the blacklis… 270,000 People on FSV blacklist Included roughly 2,000 minors, per… 1 month Notification window required Agencies must generally tell indiv… peopleofinternet.com
Dutch DPA's Fraud-Signal Guidance, By … People of Internet Research · Netherlands 11 Conditions set by AP €3.7M Belastingdienst FSV fine 270,000 People on FSV blacklist 1 month Notification window required peopleofinternet.com

Key Takeaways

Eleven Conditions, One Blanket Warning

On July 7, 2026, the Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, published formal guidance setting out 11 conditions for how government agencies and regulators may process personal data drawn from unsolicited fraud tips and non-compliance signals. The advisory targets uitvoeringsorganisaties — agencies that distribute benefits, subsidies, loans, or other financial provisions — and toezichthouders, the regulators who field reports of suspected fraud, while explicitly carving out fraud reporting already governed by dedicated legislation such as the Wgs and Wbsrz.

Most of the 11 conditions are conventional GDPR housekeeping: organizations must define in advance why they are processing a signal, collect no more data than necessary, apply extra safeguards to special or criminal-record data, secure it properly, and respect data subject rights. Two conditions are sharper. Agencies must actively assess a signal's reliability rather than assume it "could be useful," and unsubstantiated signals must be deleted rather than retained indefinitely; individuals who are reported must generally be notified within a month. Buried in the list is the line drawing the most attention: the AP explicitly discourages the use of AI, algorithms, and chatbots to assess the authenticity or reliability of incoming signals, citing what it calls considerable privacy and bias risks.

The Scandal Behind the Caution

That warning is not abstract. The Dutch tax authority (Belastingdienst) ran a system called the Fraude Signalering Voorziening (FSV) from roughly 2013 to 2020 — a blacklist that flagged suspected fraud, in part using indicators tied to nationality and apparent foreign origin. The AP fined the Belastingdienst €3.7 million on April 12, 2022 for the resulting GDPR violations: no valid legal basis for the processing, undefined purpose, inaccurate and stale data, weak security, and years of retention without review. Roughly 270,000 people, including 2,000 minors, ended up on the FSV list, and the AP found that between 5,000 and 15,000 suffered concrete financial harm. FSV was a direct contributor to the toeslagenaffaire — the childcare-benefits scandal that wrongly accused tens of thousands of families of fraud and forced the Rutte III cabinet to resign in January 2021.

Given that history, the AP's caution deserves a fair hearing before it gets a rebuttal. Regulators who watched a poorly governed risk-flagging system destroy families' finances and helped topple a government have every reason to be wary of anything that automates the same judgment call — assessing whether a tip about a person is credible — at scale and with less human accountability per decision. A chatbot or scoring model trained to triage thousands of anonymous tips a week could reproduce FSV's failure mode faster and with a thinner paper trail than a system built by hand. That is a legitimate fear, not regulatory reflex.

Where the Guidance Overshoots

But FSV's actual failures were not caused by algorithms per se — they were caused by the absence of purpose limitation, data minimization, retention limits, deletion, and human sign-off, exactly the gaps the AP's other 10 conditions now close. The blacklist did not need machine learning to go wrong; a spreadsheet with no legal basis and no expiry date was sufficient. Conflating that governance failure with "AI, algorithms, and chatbots" as a category treats a badly supervised system and a well-audited one as the same risk, when the conditions that made FSV dangerous are precisely the ones a well-designed, human-in-the-loop triage tool can be built to avoid.

GDPR's own Article 22 and the EU AI Act already offer a more calibrated tool for this than a blanket discouragement: requiring meaningful human review of automated decisions, documented data protection impact assessments, and audit trails for any system touching personal data at this sensitivity. A properly logged triage model — one that flags signals for human review rather than closing cases on its own — can actually leave a clearer record of why a person was investigated than an overworked caseworker's undocumented judgment call, which carries its own biases without leaving a trace to audit. Steering agencies away from automation altogether, without distinguishing decision-support from decision-making, risks pushing fraud-signal triage back toward manual review that is slower, harder to audit, and no less prone to the human biases that also shaped FSV's targeting criteria.

The Compliance Reality

There is also a practical mismatch. Agencies and regulators covered by this guidance receive rising volumes of unsolicited tips — exactly the caseload that motivated interest in automated triage in the first place. Discouraging the tools that help manage that volume, without funding a proportional increase in human reviewers, risks the same outcome the AP is trying to prevent: signals processed too quickly, too superficially, or not reliably reassessed at all, just done by hand instead of by model.

The AP's 11 conditions are a reasonable floor for any organization handling unverified tips about individuals, and other regulators building fraud-signal frameworks should look at the purpose-limitation and deletion requirements as a template. But the guidance would be stronger, and more useful to agencies trying to comply, if the AI-specific advice set conditions for how automated triage tools must be governed — human sign-off, DPIA, audit logging — rather than counseling agencies away from the technology itself. Proportionate regulation targets the oversight gap that produced FSV, not the tool that happens to sit nearest to the next one.

Sources & Citations

  1. AP: 11 voorwaarden bij signalen van fraude
  2. AP: Advies verwerking persoonsgegevens fraudesignalen
  3. NOS: Recordboete voor Belastingdienst wegens zwarte lijst
  4. Accountant.nl: AP stelt nieuwe voorwaarden aan fraudemelding
  5. Accountancy Vanmorgen: AP stelt strengere eisen aan fraudesignalen