Enforcement · Autoriteit Persoonsgegevens EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
International Card Services B.V.: Insufficient technical and organisational measures to ensure information security
The Dutch DPA has imposed a fine of EUR 150,000 on International Card Services B.V.
Full text
The Dutch DPA has imposed a fine of EUR 150,000 on International Card Services B.V. (ICS). ICS failed to carry out a data protection impact assessment before starting the digital identification of customers in the Netherlands in 2019. The identity check covered around 1.5 million people and involved sensitive personal data such as pictures of the data subjects.
Industry: Finance, Insurance and Consulting
How it connects
References
Related across sources
VwGH Ro 2025/04/0007-7 VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural The controller was an address publisher and direct advertising company that operated a data application to provide advertisers with personal data for targeted marketing measures.… Jun 24, 2026 Controllers Accountability Personal Data
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design
Opinion 6/2024 draft list of the Latvian SA on pro-cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR) Opinion ·EDPB Apr 18, 2024 DPIA Personal Data Supervision
15625/2026 Cass.Civ. - 15625/2026 Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its… Supreme Court May 21, 2026 Privacy by Design & Default Privacy by Design DPIA
Guidelines 01/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines ·EDPB Mar 9, 2021 Personal Data Privacy by Default Retention Period
Opinion 26/2018 draft list of the competent supervisory authority of Luxembourg regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) 1 Adopted EDPB Plenary meeting, 04/05.12.2018 Opinion 26 /2018 on the draft list of the competent supervisory authority of Luxembourg regarding the processing operations subject… Opinion ·EDPB Dec 4, 2018 DPIA Supervision Supervisory Authorities