RVS - 202401622/1/A3
Facts — The Municipal Executive of Enschede, the controller, decided to conduct continuous pedestrian counts to obtain information about visitor numbers in the city centre. From 25 May 2018, at least ten sensors captured the MAC addresses of devices with Wi-Fi enabled. When a sensor detected a MAC address, it was temporarily stored and converted into a pseudonymised MAC address using an algorithm. Since all sensors used the same algorithm, the same device received the same pseudonymised identifier across different locations. The resulting data included the sensor that detected the device and the date and time of detection. After several filters were applied, the data was retained for up to six months and used to estimate the number of unique visitors. The controller discontinued the pedestrian-counting system on 1 May 2020. Following an enforcement request, the Autoriteit Persoonsgegevens, the DPA, investigated the processing. It considered that the combination of pseudonymised MAC addresses and location data related to identifiable natural persons. According to the DPA, the data allowed individuals to be distinguished and could reveal lifestyle and behavioural patterns. It also identified three methods through which the controller could potentially determine the identity of device users. On 11 March 2021, the DPA imposed a fine of €600,000 on the controller for processing personal data without a legal basis between 25 May 2018 and 30 April 2020. It considered the controller responsible for determining the purposes and means of the processing and found that no legal basis under Article 6 GDPR had been established. The controller challenged the decision before the District Court of Overijssel. The Court held that the DPA had not sufficiently proven that the information processed by the controller constituted personal data. In particular, the DPA had relied on assumptions regarding the possibility of identifying device users without sufficiently investigating whether those identification methods were realistically available. The Court held that, under Recital 26 GDPR, the DPA should have assessed whether the means allegedly available to identify the individuals were reasonably likely to be used, taking into account the costs, time, available technology and technological developments. It therefore annulled the decision on the objection and revoked the original fine. The DPA appealed the judgment before the Council of State. Holding — The High Court dismissed the DPA’s appeal and upheld the annulment of the €600,000 fine. The High Court noted that the DPA did not challenge the Court’s finding that it had failed to sufficiently investigate and substantiate the three methods through which the controller could allegedly identify individual device users. During the appeal hearing, the DPA also acknowledged that the applicable standard of proof had not been met regarding those methods. Instead, the DPA argued that natural persons had already been directly identified because the combination of MAC addresses and location data allowed the controller to distinguish and count unique visitors. According to the DPA, the ability to single out unique visitors was itself sufficient for the information to qualify as personal data under Article 4(1) GDPR, irrespective of whether the controller could determine their civil identity. However, the High Court held that the DPA had not relied on this reasoning in its original decision or in its decision on the controller’s objection. In proceedings concerning an administrative fine, the DPA must conclusively establish and substantiate the alleged infringement before completing the administrative decision-making process. This requirement safeguards legal certainty and allows the alleged infringer to defend itself effectively and in a timely manner. The DPA could not wait until the judicial appeal stage to introduce a new argument explaining why the processing concerned personal data and why a punishable infringement had occurred. The Court had therefore not erred by refusing to assess this new argument. Since the DPA had not otherwise challenged the substance of the Court’s finding that the original infringement had not been sufficiently proven, the annulment of the fine remained in effect. The High Court did not determine whether the pseudonymised MAC addresses and location data were, as such, personal data under the GDPR.
How it connects
Related across sources
Full text
202401622/1/A3. Date of Decision: July 29, 2026 Section ADMINISTRATIVE LAW Decision on the appeal filed by: the Dutch Data Protection Authority (hereinafter: the AP), appellant, against the judgment of the District Court of Overijssel dated February 2, 2024, in Case No. 22/775 in the proceedings between: the Municipal Executive of Enschede and the AP. Course of the Proceedings By decision of March 11, 2021, the AP imposed an administrative fine on the Municipal Executive. By decision of April 6, 2022, the AP declared the objection filed by the Municipal Executive against that decision to be unfounded. In a judgment dated February 2, 2024, the court upheld the appeal filed by the Municipal Executive against that decision, annulled the decision of April 6, 2022, and revoked the decision of March 11, 2021. The AP filed an appeal against this judgment. The Board submitted a written statement. By decision of April 20, 2026, the Section’s Confidentiality Chamber granted a request by the AP to apply Article 8:29 of the General Administrative Law Act to confidential versions of a number of case documents. The Board granted the Section consent to obtain these documents. The AP submitted a supplementary brief. The Section heard the case at a hearing on May 21, 2026, at which the AP, represented by W. van Steenbergen, E. Nijhof, Esq., and V.B. Klos, and the Municipal Executive, represented by M.H. Elferink, Esq., and M.J.M. Kortier, Esq., attorneys in Enschede, and M. Nijkamp, appeared. Considerations Introduction 1. To gain insight into visitor numbers in Enschede’s city center, the Municipal Executive made the decision to conduct a continuous pedestrian count. The investigation conducted by the AP in response to an enforcement request reveals that, as of May 25, 2018, the municipal executive used at least ten sensors in the city center to capture the MAC addresses of devices with Wi-Fi enabled. A MAC address is, in principle, a unique identification number consisting of twelve hexadecimal characters (0–9, A–F) assigned to a device’s network card. As soon as a sensor captured a MAC address, it was temporarily stored in RAM until it was converted via an algorithm into a pseudonymized MAC address (a different combination of twelve hexadecimal characters) and then sent to a central server. All sensors used the same algorithm, meaning that a MAC address captured on different sensors would still be assigned the same pseudonymized MAC address. On the server, the data from all sensors for a single day was stored in a so-called short-term table. This table showed, among other things, which sensor had captured a pseudonymized MAC address and at what time. Before the data was transferred to a long-term table containing six months’ worth of data, filters were applied. MAC addresses listed in an opt-out registry or those involving “spoofing”—the automatic, random alteration of the MAC address—were removed. Additionally, a resident filter was in place, which removed MAC addresses captured during specific nighttime hours. The data in the long-term table formed the basis for the figures received by the municipal executive. These figures provided an estimate of the number of unique visitors in the city center and at specific sensors. MAC addresses captured by multiple sensors were excluded from the counts. Since January 1, 2019, the last three characters of the pseudonymized MAC address were truncated on the server for the purpose of the tables. The municipal executive discontinued this pedestrian count on May 1, 2020. 1.1. The AP imposed a fine of €600,000 on the municipal executive because, from May 25, 2018, through April 30, 2020, the municipal executive processed personal data without a legal basis regarding owners/Users of mobile devices with Wi-Fi enabled in downtown Enschede. Although the (pseudonymized) MAC address and the location data—consisting of information about the recording sensor and the date and time the MAC address was captured— reveal nothing about the identity of a natural person and therefore do not constitute information about an “identified person,” they do constitute information about an “identifiable natural person” as defined in the General Data Protection Regulation (GDPR). By adding location data to a unique number, a person is individualized, and lifestyle and behavioral patterns can be revealed. Based on the combination of these identifiers, the AP concluded that it was reasonably possible for the board to identify the natural person to whom the data pertains. The AP outlined three methods for doing so. Because these methods of identification do not require excessive effort and are not prohibited by law, a natural person is identifiable through the combination of a (pseudonymized) MAC address and location data, meaning that this data constitutes personal data. Truncating the pseudonymized MAC address does not render the data so unrecognizable that it ceases to be personal data. The Board is the controller because it determined the purpose and means of processing personal data. The Board did not cite a legal basis for this processing. Because the college processed the personal data of hundreds of thousands of citizens without a legal basis, in a systematic manner, and for an unnecessarily long period, the AP increased the base amount of the fine by €75,000 to €600,000. The AP sees no grounds for mitigation. Court Ruling 2. The court concluded that the AP had not proven that the municipal executive, using the method it employed, had processed personal data of owners/users of mobile devices with Wi-Fi enabled in downtown Enschede. In reaching this conclusion, the court considered that, in refuting the municipal executive’s objections on several occasions—such as regarding the range of the sensors and remote login to the sensor—the AP repeatedly relied on the (un)plausibility of circumstances rather than on an investigation of the facts. It further noted that, given the three outlined methods by which a natural person could be identified, the AP essentially based its decision-making on the Municipal Executive’s ability to identify natural persons using the (pseudonymized and truncated) MACaddresses by determining, at some point in the early morning when few people are on the street, that a specific, unique User of a mobile device is within the range of a sensor. According to the court, the AP failed to sufficiently investigate whether this would indeed make it possible to determine the identity of a mobile device user with the naked eye. The mere assertion that the authority could reasonably do so does not convince the court. In light of Recital 26 of the GDPR, the AP should have examined whether it is reasonably foreseeable that the aforementioned means would be used to identify a natural person directly or indirectly, taking into account the costs and time required for identification, with due regard to the technology available at the time of processing and technological developments. Simply because the AP failed to prove that the board processed personal data, the AP could not impose an administrative fine. Appeal 3. On appeal, the AP argues that the court erred in failing to rule on its position that natural persons were directly identified based on their (pseudonymized and later truncated) MAC addresses in combination with location data. After all, the sensors installed in the city center used MAC addresses to determine where a single natural person was located within the city center, and it is not in dispute that unique visitors to the city center were counted in this manner. This in itself constitutes the processing of personal data. Since the identification of natural persons already took place during the counting of unique visitors to the city center—and personal data is therefore already involved— the court’s considerations regarding the AP’s investigation into the possibilities it outlined for actually determining the identity of a natural person based on this data are irrelevant, according to the AP. Assessment of the Appeal 3.1. The Section finds that the AP does not contest the court’s judgement that, in short, it failed to properly investigate and substantiate that natural persons are identifiable because the municipal executive could combine the obtained MAC addresses and location data it had obtained and supplement them with data obtained on site. At the hearing before Section, the AP also confirmed that the standard of proof had not been met with regard to the three methods outlined for this purpose. The AP argues, however, that the court failed to assess a position it had put forward on appeal, namely that natural persons were directly identified because the combination of MAC addresses and location data made it possible for the municipal council to count unique visitors in the city center. However, the AP did not adopt this position in its decision-making. According to established case law of the Section, the basic principle in an administrative fine decision is that the administrative body must provide conclusive evidence of a violation upon completion of the administrative decision-making process. This is partly in light of the legal certainty to which the alleged violator is entitled and of his ability to mount a timely and adequate defense against the charge in court. See the judgments of December 30, 2015, ECLI:NL:RVS:2015:4034, at 6.2, and of July 5, 2017, ECLI:NL:RVS:2017:1819, under 5.1. The Section does not see why it was not reasonably possible for the AP to have already taken the position—and provided evidence—during the decision-making process that there was (unlawful processing of) personal data, simply because the board was able to count unique visitors in the city center based on the MAC address and location data, and natural persons would thereby have been directly identified. Since the court is required to review the decision-making process in light of the grounds for appeal raised, and an administrative body cannot, in principle, wait until the appeal stage to argue and substantiate exactly why a punishable violation has occurred, the AP criticizes the court, in light of the considerations set forth above, for wrongfully failing to review the position it put forward on appeal. For this reason, the Section will also not review this position and will disregard it. This means that, since the AP has not otherwise challenged the substance of the court’s judgement, the annulment of the penalty decision stands. 4. Because the court’s judgement regarding [person] is not the basis for the reversal and he himself did not file an appeal, Section sees no reason to discuss the arguments raised by the AP in this regard. Conclusion 5. The appeal is unfounded. The Section affirms the court’s judgment. The AP is not required to reimburse litigation costs. Decision The Administrative Law Section of the Council of State: I. affirms the contested judgment; II. orders the Dutch Personal Data Authority to pay a court fee of €559.00. So decided by N. Verheij, M.A., Chair, and J.Th. Drop, M.A., and J. Luijendijk, M.A., members, in the presence of G.A. van de Sluis, M.A., Clerk. The Chair is unable to sign the judgment signed Van de Sluis Clerk Delivered in open court on July 29, 2026