Skip to content
Case Law · District Court Den Haag EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Rb. Den Haag - C/09/689833

District Court Den Haag
Summary

Facts — Kindred Group PLC and Risepoint Limited (the controllers) are companies that provide online gambling products. Several companies within Kindred Group PLC (Risepoint was initially in this group) offered online gambling products before a national law requiring a license entered into force. In response, several lawsuits were filed before courts regarding the validity of the gambling agreements between players and unlicensed online gambling providers. Several data subjects later requested access (Article 15 GDPR, or in the alternative, the right to portability under Article 20 GDPR) to the controller to receive information on specific transaction data and the types of games they participated in. The data subjects did not receive access and brought a claim to the court. The data subjects requested the court to hold both companies liable (jointly or separately) The court initially dismissed the claim based on the code of civil procedure, but allowed the data subjects to amend their arguments regarding the GDPR. Both companies argued that they were not controllers, and that the requests made by the data subjects were abusive. According to the companies, the data subjects requested access for the sole purpose of bringing legal actions against them. Finally, the companies argued that they did not have the obligation to comply with the requests under Article 15(4) GDPR. Holding — The court first clarified that both Kindred Group PLC and Risepoint Limited were controllers. Kindred Group PLC argued that it did not exercise any decisive influence over the purpose and means of processing. The court took into consideration the functional definition of “controller” under Article 4(7) GDPR and CJEU case law, rather than a formal definition. The court found that Kindred Group PLC was a controller for access made between May and October 2024, but not for requests made after October 2024. This is because Kindred had a unified privacy policy for companies under its group, and answered the access request from an email address containing its name. However, after October 2024, Risepoint was no longer a part of the group, and the data from Kindred had been transferred to Risepoint. The court then dismissed the controllers’ arguments, and stated that the access requests were not abusive under Article 12(5) GDPR. Under Article 12(5) GDPR, a controller may refuse a request for access if it is manifestly unfounded or excessive. However, the CJEU has clarified that a data subject does not need to justify an access request, and a controller cannot refuse a request for access on the sole ground that it serves a purpose other than obtaining information about the processing of personal data and verifying its lawfulness. In any case, the court stated that the controller bears the burden in proving that a request is manifestly unfounded or excessive. Similarly, the controllers could not rely on Article 15(4) GDPR to refuse the data subjects’ requests. The court stated that the controllers’ interest in not granting information that data subjects could use against them in court is not recognised under EU law as a basis to refuse access. While the GDPR allows for national law to restrict specific rights under Article 23 GDPR, the court stated that the restriction must be necessary and proportionate. This, however, does not apply for hypothetical situations. The court upheld the data subjects’ claim, and ordered the controllers to provide them with a copy of their transaction data. The court specified that the controllers had the obligation to provide a complete copy, in accordance with CJEU case law.

How it connects

38 of 74 paragraphs apply legislation or carry a topic — see them in the full text ↓

Full text 74 paragraphs

Paragraphs carrying a topic or an applied provision show those connections inline Original at the source →
¶0

27 May 2026 in the case of 1 . [claimant 1] in [place of residence 1] , 2. [claimant 2] in [place of residence 2] , 3. [claimant 3] in [place of residence 3] , 4. [claimant 4] in [place of residence 4] , 5. [claimant 5] in [place of residence 5] , 6. [claimant 6] in [place of residence 6] , 7. [claimant 7] in [place of residence 7] , 8. [claimant 8] in [place of residence 8] , 9. [claimant 9] in [place of residence 8] , 10. [claimant 10] in [place of residence 9] , 11. [claimant 11] in [place of residence 10] , claimants, attorney: mr. B.Z. Loonstein, against

¶1

KINDRED GROUP PLC in Valetta (Malta), attorney: Mr. R.E. van Schaik, 2 RISEPOINT LIMITED in Birkirkara (Malta), attorney: Mr. J.G. Reus defendants. 1 In brief: what is this case about?

¶1.1

In these proceedings, the plaintiffs seek that the court order the defendants, pursuant to the GDPR1, to grant each of them access to transaction data relating to the Unibet online gambling games in which they participated. The defendants refuse the plaintiffs access to this data because they believe that the plaintiffs are abusing their right of access; in any case, the defendants believe that they are entitled to refuse access because the plaintiffs are seeking access for a purpose other than that for which the right of access is intended.

¶1.2

In this judgment, the court partially grants the plaintiffs' claims, because there is no abuse of rights and the defendants cannot invoke the grounds for refusal mentioned in the GDPR.

¶2

The proceedings

¶2.1

These proceedings were initiated by a petition. In short, this petition contained a request for the provision of certain transaction data by Kindred and Risepoint to the plaintiffs, primarily on the basis of the GDPR and the UAVG2 and subsidiarily on the basis of Article 195 in conjunction with Article 194 of the Code of Civil Procedure (Rv); an oral hearing took place on 19 June 2019.

¶2.2

By order of 31 July 20253, the court rejected the plaintiffs' request insofar as it was based on Articles 195 and 194 Rv. The court, applying Article 69 of the Dutch Code of Civil Procedure (the so-called 'track change'), ordered that the proceedings be continued in their current state in accordance with the rules applicable to summons proceedings. The parties were given the opportunity to adapt their arguments to those procedural rules, and they did so. Subsequently, on March 19, 2026, the GDPR case was heard orally.

applies Art. 69
¶2.3

The case file consists of the following documents: - the petition pursuant to Article 15 paragraph 1 of the GDPR dated March 10, 2025, with exhibits 1-17, which is to be regarded as a summons; - the statement of defense of Kindred dated June 6, 2025, with exhibits 1-22, which is to be regarded as a statement of defense; - the statement of defense of Risepoint dated June 10, 2025, with exhibits 1-16, which is to be regarded as a statement of defense; - the plaintiffs' letter of 17 June 2025 with exhibits 18-25; - the letter from Kindred of 17 June 2025 with exhibits 23 and 24; - the pleadings presented by the lawyers during the oral hearing of 19 June 2025; - the court's decision of 31 July 2025; - the plaintiffs' post-track submission of 3 September 2025; - the post-track submission of Kindred of 1 October 2025; - the post-track submission of Risepoint of 1 October 2025 with exhibits 17-20; - the interlocutory judgment of 3 December 2025 scheduling an oral hearing; - the notice from the Registry of 13 March 2026 containing a hearing agenda; - the deed of Risepoint dated March 13, 2026, with further exhibits 26 and 27; - the pleadings presented by the lawyers during the oral hearing on March 19, 2026.

applies Art. 15
¶2.4

After the oral hearing, the date on which this judgment is rendered was determined.

¶3

The Facts Based on the documents and what was discussed during the hearing, the court proceeds from the following facts.

¶3.1

Pursuant to the Gambling Act (Wok), it is prohibited to provide an opportunity to participate in gambling, unless a license for this purpose has been granted by the Gambling Authority pursuant to the Wok. Due to the entry into force of the Remote Gambling Act, it has also been possible since October 1, 2021, to obtain a license for offering gambling online.

¶3.2

The Claimants participated in online gambling on the websites www.unibet.com and www.unibet.eu (hereinafter: the Websites) in the period prior to October 1, 2021.

¶3.3

Kindred heads a group of companies that offers online gambling under the name Unibet (hereinafter: the Kindred Group).

¶3.4

Trannel International Limited (hereinafter: Trannel) was part of the Kindred Group. In the period prior to October 1, 2021, Trannel made it possible for Dutch players to participate in online gambling via the Websites.

¶3.5

Trannel ceased offering online gambling to Dutch players on September 30, 2021, and has not been part of the Kindred Group since October 31, 2024. After its departure from the Kindred Group, Trannel changed its name to Risepoint Limited.

¶3.6

Proceedings have been initiated at various courts in the Netherlands by gambling participants against entities that offered online gambling before October 1, 2021 (i.e., without a license). The District Court of Amsterdam and the District Court of North Holland jointly submitted preliminary questions to the Supreme Court in judgments of June 12, 2024 (ECLI:NL:RBAMS:2024:3469 and ECLI:NL:RBNHO:2024:5808) regarding – in short – the legal validity of gambling agreements between players and online gambling providers that did not hold a license. The answers to the preliminary questions submitted are expected in 2026.

¶3.7

With the exception of Claimant 5 and Claimant 9, the claimants submitted a request for access based on the GDPR via the email address [email address 1] during the period from May through October 2024. In addition, all claimants submitted a request for access in January or February 2025 via the email addresses [email address 1] and [email address 2], except for Claimant

¶4

(who did not submit a new request for access in 2025) and Claimant 7 (who only sent a request for access to [email address 2] in January 2025). These requests from claimants concern access to personal data processed in the context of their participation in online gambling via the Unibet Websites. More specifically, claimants request an overview of the transaction data and the types of games in which they participated. None of the claimants has received the requested data. 4 The dispute

¶4.1

Claimants claim – in summary – that the court, by judgment, insofar as possible provisionally enforceable: I. Order Risepoint and Kindred jointly, or at least each individually, to provide the relevant claimants within fourteen days after the date of this judgment, with regard to the processing of personal data referred to in the body of the introductory pleading and/or the (other) data referred to in the body of this summons, by granting each of the claimants access to the personal data processed concerning them, by providing each of the claimants with a copy of the personal data that constitute a complete picture of all direct or indirect transactions between each of the claimants and the defendants, to be provided electronically in a common format such as XLS(X) or CSV or by means of an Application Programming Interface (hereinafter: API), whereby the information and/or data to be provided to the claimants is intelligible and enables each of them to verify the accuracy of the personal data and the lawfulness of the processing of such data; II. to order Risepoint and Kindred jointly and severally to pay a penalty of € 2,500.00 for each day that they fail to comply with the judgment as referred to under I, II and/or III; III. To order Risepoint and Kindred jointly and severally to pay the costs of these proceedings.

¶4.2

Kindred and Risepoint present their defense and conclude that the plaintiffs are inadmissible in their claims (Risepoint), or at least that those claims (Kindred and Risepoint) should be dismissed, with an order for the plaintiffs to pay the costs of the proceedings declared provisionally enforceable.

¶4.3

The parties' arguments will be discussed in more detail below, insofar as necessary.

¶5

The assessment Jurisdiction and applicable law

¶5.1

Because Kindred and Risepoint are established in Malta, this case has an international character. This means that the court must assess ex officio whether it has jurisdiction and – if so – according to which substantive law the plaintiffs' claims must be assessed.

¶5.2

The plaintiffs' claims are based on the GDPR. As held in consideration 4.3 of the order of 31 July 2025, the Dutch court has jurisdiction to hear these claims pursuant to Article 79(2) of the GDPR.

applies Art. 79(2)
¶5.3

It is not in dispute between the parties that the claims must be assessed on the basis of the GDPR, which has direct effect under both Maltese and Dutch law. However, the parties disagree on the question of whether Kindred and Risepoint can invoke (successfully) the Maltese ‘Subsidiary Legislation 586.09 Restriction of the Data Protection (Obligations and Rights) Regulations’, which restricts certain rights under the GDPR. The court assesses this point of dispute in paragraphs 4.15 et seq.5.4. In short, the plaintiffs claim access to and a copy of the transaction data concerning them, primarily on the basis of Article 15 GDPR (the right of access) and subsidiarily on the basis of Article 20 GDPR (the right to data portability). Article 15 GDPR

¶5.5

According to Article 15(1) GDPR, a data subject whose personal data have been processed has the right to obtain confirmation from the controller as to whether or not personal data concerning him or her are being processed and, if so, to obtain access to those personal data. According to Article 15(3) GDPR, the controller must provide the data subject, at his or her request, with a copy of the personal data being processed. Personal data?

¶5.6

In this case, it is not disputed that Unibet processed personal data within the meaning of (Article 4(1) of) the GDPR in the period up to 1 October 2021 in the context of the plaintiffs' participation in online gambling via the Websites. Nor is it disputed that the transaction data claimed by the plaintiffs can also be classified as personal data. Pursuant to Article 15 of the GDPR, the plaintiffs can therefore, in principle, claim access to and a copy of the transaction data concerning them from the controller(s) within the meaning of Article 4(7) of the GDPR. Who is the controller?

¶5.7

In these proceedings, it is not disputed that Risepoint can be considered a controller within the meaning of Article 4(7) of the GDPR.

¶5.8

Kindred disputes that it can be classified as a controller. According to Kindred, it did not exercise any actual decisive influence on the purpose and the (essential) means of processing the personal data at issue in this case. Period between May and the end of October 2024

¶5.9

The court is of the opinion that Kindred is indeed the controller with regard to access requests made in the period between May and the end of October 2024, but not with regard to access requests made in the period after October 2024. This judgment is based on the following considerations.

¶5.9.1

The court states upfront that the determining factor in the question of whether Kindred was the (whether or not: joint) controller is the situation at the moment the access request was made. This is consistent with the structure of the GDPR, which works with functional rather than formal role concepts; This implies that the assessment of the role an entity plays must be based on an analysis of the factual circumstances of the case.4 The use of the present tense in Article 4(7) of the GDPR5 underscores that controllership must be assessed on the basis of the situation as it exists at the time the data subject makes the information request.

¶5.9.2

According to settled case law of the Court of Justice of the European Union (Court of Justice, abbreviated: CJEU), the functionally understood concept of ‘controller’ must be interpreted broadly.6 Joint controllership does not require that the various undertakings involved in the processing of personal data bear equivalent responsibility for it, nor that they both be involved in the processing at all stages.7

¶5.9.3

In this case, nine claimants submitted access requests to Unibet in the period from May to October 2024 via the email addresses [email address 1] and/or [email address 2]. All claimants submitted a request for access (again) in January or February 2025 via (one of) these email addresses. The question is whether Kindred, together with Risepoint, actually exercised decisive influence during those periods on the purpose and the essential means of processing the claimants' personal data.

¶5.9.4

Claimen have pointed out that Kindred is the head of the Unibet group and that GDPR requests sent to Unibet email addresses ([email address 1] or [email address 3]) were answered from no-reply@kindredgroup.com, stating that ‘we’ needed more time for the data request. Following that answer, access to personal data was also provided to some claimants8 from that mailbox, showing that Kindred had access to that personal data. Access to the requested transaction data was refused, but the reason Kindred gave for this was not that it could not obtain that data, but that it invoked a ground for exception.

¶5.9.5

Kindred confirms that replies were indeed sent from the inbox no-reply@kindredgroup.com, but argues that this occurred for only a short period and that this was an error related to the introduction of a new platform, OneTrust. However, the plaintiffs have substantiated their claim that the privacy statements on all Unibet websites were identical in the period between May and the end of October 2024, which indicates a single central privacy policy.

¶5.9.6

The privacy statement for www.unibet.nl dated August 12, 2022, submitted by Kindred, confirms that a single central privacy policy was indeed maintained for the Unibet brand name. It follows from the privacy statement that the purposes of the processing of personal data within the group were in any case determined at least partially centrally (underlining in quote by the court): “7 When do we share your personal data? However, it may happen that we share your personal data with other companies in the Kindred Group, with third parties providing services to you on our behalf, and with other third parties complying with our legal obligations. Other examples of when we share your personal data are when we are part of a merger or during a sale of the company. Even when your personal data is shared, we ensure that it is only used for the purposes set out in this policy. With other companies within the Kindred Group We may share the personal data we collect with other companies in the Kindred Group for the following purposes:  to provide you with products and services and to inform you of important changes or developments in the functions and operation of these products and services;  to respond to your questions and complaints;  (…)  Updating, consolidating and improving the accuracy of our records  Performing transactional analyses;  (…)  Customer modeling, statistical and trend analysis, with the aim of developing and improving products and services. With third parties We may share personal data with third parties in the following cases:  (…)  With service providers to enable us to deliver our services, such as companies that assist us with technological services, data storage and combination (…)” Kindred has confirmed that there was a Data Protection Officer (DPO) for the entire group, whose primary task was to oversee compliance with the GDPR within the group. 5.9.7. Risepoint confirms that prior to its departure from the Kindred Group, a central privacy policy was maintained within the group, including via the OneTrust platform managed by Kindred. Trannel/Risepoint could not process the personal data in the period up to November 2024 without the intervention of Kindred.

¶5.9.8

As Exhibit 12, the Claimants have submitted an email dated October 22, 2024, from [email address 1] to Claimant 11, in which “Unibet” requested this claimant to resubmit his request via a web form with an address that began with “https://kindred-privacy.my.onetrust.com”. The request thus resubmitted by Claimant 11 was rejected on October 28, 2024, by the “Kindred Privacy Team” of “Kindred Group Plc” (as stated in the footer of the message), from the mailbox “no-reply@kindredgroup.com”.

¶5.9.9

It follows from the foregoing that, in the period between May and the end of October 2024, Kindred exercised actual (co-)decisive influence over the purpose and the essential means of the processing of the personal data at issue in this case, both through its central policy and through the OneTrust platform prescribed and managed by it and the Kindred Privacy Team.

¶5.9.10

If there are multiple controllers, data subjects may request access from any of them pursuant to Article 26(3) of the GDPR. Period after the end of October 2024

applies Art. 26(3)
¶5.10

Claimants 5 and 9 did not send a request for access to [email address 1] in the period between May and the end of October 2024; they only did so at the end of December 2024 and mid-February 2025. By then, the personal data of players who had participated in online gambling of the Kindred Group before October 2021 had already been transferred to Risepoint. The court must therefore assess whether Kindred was still a (joint) controller at the end of December 2024 and in mid-February 2025.

¶5.11

In view of Kindred's substantiated challenge, the court is of the opinion that, with regard to the period after October 2024, the plaintiffs have not sufficiently concretely argued that Kindred can be regarded as a (joint) controller within the meaning of Article 4(7) of the GDPR and/or Article 26 of the GDPR.

¶5.11.1

In the situation up to November 2024, there was a central policy within the group to which Trannel/Risepoint was also subject, but in the period thereafter, Risepoint could independently determine the purpose and means of the processing. The mere fact that Risepoint entered into agreements for the processing of personal data with an entity within the Kindred Group after its withdrawal from the Kindred Group does not mean that Kindred still exercised decisive influence over the purpose and essential means of processing the plaintiffs' personal data. The plaintiffs have not specified what Kindred's decisive influence over the processing of their data consisted of after November 2024.

¶5.11.2

The data processing agreements submitted by Kindred as exhibits 6 and 7 provide no grounds for the notion that Kindred could still exercise decisive influence over the purpose and means of processing personal data for Risepoint. In those agreements, Risepoint is clearly designated as the controller determining the purpose and means of processing; the entity within the Kindred Group (Kserol) may not process personal data other than in accordance with applicable law and the data processing agreement concluded with Risepoint. Article 12 paragraph 5 GDPR / Abuse of rights

¶5.12

Kindred and Risepoint also take the position that, pursuant to Article 12 paragraph 5 GDPR, they are not required to comply with the access requests because the plaintiffs are abusing their right of access. According to them, the plaintiffs submitted the access requests for a purpose other than that for which Article 15 GDPR is intended, namely to obtain information to substantiate a potential claim against Kindred and Risepoint. In this context, Kindred and Risepoint refer to German case law regarding GDPR access requests from gambling providers, arising from cases brought with the sole intent to recover gambling losses.

¶5.13

The plaintiffs dispute that the access requests were submitted solely with a view to potential legal proceedings against the defendants. The plaintiffs also state that they wish to know what the defendants have done with their data, partly because they have been receiving a striking number of gambling advertisements since the dispute began. Furthermore, the plaintiffs dispute that requesting information to investigate whether they have a legal claim against the defendants constitutes an abuse of their GDPR rights.

¶5.14

The court is of the opinion that there is no abuse of rights. This judgment is based on the following considerations.

¶5.14.1

The court finds confirmation in the statements submitted by the defendants from (the firm of) the plaintiffs' counsel and in the identicality of the (model) requests drawn up by the law firm that the requests were submitted, in any event, partly with a view to a possible (test) procedure to be initiated against Kindred and/or Risepoint. The question is whether this constitutes an abuse of rights, or a (different) ground on which the defendants may refuse the plaintiffs' requests for access.

¶5.14.2

Article 12 paragraph 5 of the GDPR lists two reasons why a controller may refuse to comply with a request for access. According to the CJEU, those grounds relate to cases of abuse of rights in which the requests of the data subject are ‘manifestly unfounded’ or ‘excessive’, particularly when those requests are of a repetitive nature.9 The Court of Justice has also ruled that a request for access cannot be rejected solely on the ground that it has a purpose other than to inform oneself of the processing of personal data and to verify its lawfulness, because data subjects are not required to justify a request for access to the data.10

¶5.14.3

Pursuant to Article 12(5) of the GDPR, it is up to the controller to demonstrate the alleged manifestly unfounded or excessive nature of a request.

¶5.14.4

The applicants' requests are not manifestly unfounded,11 but are provisionally eligible for approval (see paragraphs 5.6 and 5.9 above). The court will address the question of whether the requests of the other claimants are excessive below in its consideration of the defendants' reliance on Articles 15(4) and 23(1) of the GDPR. Reliance on Article 15(4) / Article 23(1)(1) of the GDPR?

¶5.15

Furthermore, Kindred and Risepoint take the position that they are not required to comply with the access requests because they are entitled to rely on the exception referred to in Article 15(4) of the GDPR, or on an exception included in the Maltese implementing law pursuant to Article 23(1)(1)(i) of the GDPR. Risepoint states that it has been confronted with more than 8,000 access requests that are not made in the interest of data protection. This has an enormous impact on its business operations and, according to Risepoint, infringes upon its freedom of entrepreneurship. Kindred also considers the requests to be disproportionate. The plaintiffs' lawyer has submitted requests on behalf of 20,000 data subjects; handling a request takes approximately 90 minutes, which amounts to 30,000 man-hours. According to Kindred, this constitutes an extreme infringement of its rights and freedoms, in which it points out once again that the access requests are not being used for their intended purpose, but only to initiate legal proceedings whose viability is uncertain given the preliminary questions pending before the Supreme Court. Moreover, Kindred considers the requests to be excessive, because the plaintiffs are using the right of access with the sole intention of causing it harm or nuisance.

¶5.16

The provisions on which the defendants rely read as follows: Article 15 paragraph 4 GDPR: The right to obtain a copy referred to in paragraph 3 shall not prejudice the rights and freedoms of others. Article 23(1)(i) GDPR: The scope of the obligations and rights referred to in [inter alia Article 15 GDPR, District Court] may be limited by means of a (…) legislative measure of a Member State applicable to the controller or processor, provided that such limitation does not affect the essential content of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to ensure: (…) the protection of the data subject or of the rights and freedoms of others;

¶5.17

Claimen dispute that the defendants are entitled to rely on the exceptions.

¶5.18

The District Court is of the opinion that the defendants cannot refuse the requests for access, neither on the basis of the exception referred to in Article 15(4) GDPR, nor on the basis of an exception included in the Maltese implementing law. This opinion is based on the following considerations.

applies Art. 15(4)
¶5.18.1

The interest on which Kindred and Risepoint essentially rely is the interest in not having to provide access to information that data subjects could use against them in legal proceedings. This is not an interest recognised under Union law as a ground for refusing data subjects access to their personal data.

¶5.18.2

Under Dutch law, this interest in civil law does not, in principle, stand in the way of the obligation to grant access.12 The Maltese exception ground invoked by the defendants also does not imply that they may refuse access to data subjects because the latter might use the information against them in legal proceedings (underlining in quote by the court):13 “While the GDPR allows for certain restrictions to data subject rights under national law, such limitations must be clearly justified. Regulation 4(e) of Subsidiary Legislation 586.09 provides that “[a]ny restriction to the rights of the data subject referred to in Article 23 of the Regulation shall only apply where such restrictions are a necessary measure required: (e) for the establishment, exercise or defence of a legal claim and for legal proceedings which may be instituted under any law”. However, any such restriction must be assessed strictly in light of Regulation 7 of the same legislation, which mandates that any limitation imposed must constitute a necessary and proportionate measure. For a restriction under Regulation 4(e) of Subsidiary Legislation 586.09 to be justified, the controller must demonstrate that it is strictly necessary to defend an actual legal claim or legal proceedings. A restriction cannot be based merely on the possibility that the data subject may initiate legal action following receipt of the information. A hypothetical or speculative rationale does not satisfy the legal threshold. Without clear and substantiated evidence of an existing or imminent legal claim, invoking Regulation 4(e) of Subsidiary Legislation 586.09 constitutes an unlawful interference with the right of access.”

¶5.18.3

The Maltese Data Protection Authority has rejected the defendants' reliance on this exception in similar cases.14 The fact that the defendants have appealed against these decisions does not mean that the court must interpret the Maltese exception differently than the Maltese Data Protection Authority.

¶5.18.4

The GDPR regulation already takes into account that processing access requests generates work for the responsible entrepreneur. Since the individual requests of the plaintiffs are not unusual, unnecessarily extensive, or complex, the balancing of interests referred to in Article 15(4) of the GDPR weighs in their favour over the business interests of the defendants.

applies Art. 15(4)
¶5.18.5

The assertion that the plaintiffs are exercising the right of access with the sole intention of causing damage or nuisance to the defendants is unsubstantiated. Furthermore, no grounds for this assertion can be found in the file. Conclusion: the defendants must provide the plaintiffs with a copy of their transaction data

¶5.19

The foregoing means that Risepoint was not permitted to refuse any of the access requests directed to it, and that Kindred was only permitted to refuse the access requests directed to it by Plaintiff 5 and Plaintiff 9.

¶5.20

Finally, Kindred and Risepoint take the position that they are not obliged to provide the plaintiffs with a complete transaction overview, or at least not an overview containing data other than that provided by the plaintiffs themselves. This defense, too, cannot succeed. According to settled case law of the Court of Justice, the controller must, upon request, provide data subjects with a faithful and understandable reproduction of all data it processes concerning the data subject.15

¶5.21

The court will therefore largely grant the plaintiffs' claims, in the manner formulated below under the heading ‘The decision’.

¶5.22

In view of the manner in which the defendants have conducted themselves towards the plaintiffs since the submission of the requests for access to the transaction summaries, the plaintiffs have an interest in their claim to reinforce the judgment with a penalty payment. The court will therefore also grant this part of the claim, albeit that the court will extend the time limit for compliance to four weeks after the date of this judgment and that it will reduce the amount of the penalty payment to an amount of € 500 per day per plaintiff, with a maximum of € 10,000 per plaintiff. Legal costs

¶5.23

Kindred and Risepoint have been largely unsuccessful and must therefore pay the legal costs (including post-judgment costs). The legal costs of the plaintiffs in this summons procedure (after the change of track) are estimated at: - lawyer's fees € 1,306.00 (2 points × Tariff II at € 653) - post-judgment costs € 189.00 (plus the increase as stated in the decision) total € 1,495.00.

¶5.24

The interest claimed on the legal costs will be awarded in the manner set out in the decision.

¶6

The decision The court 6.1. orders Kindred to grant all claimants except Claimant 5 and Claimant 9 access to the personal data processed about them within four weeks of the date of this judgment, by providing each of the claimants with a copy of the personal data that constitute a complete picture of all direct or indirect transactions between the relevant claimant and Kindred, its legal predecessors and/or partners under the Unibet label; 6.2. orders Risepoint to grant each of the claimants access to the personal data processed about them within four weeks of the date of this judgment, by providing each of them with a copy of the personal data that constitute a complete picture of all direct or indirect transactions between the relevant claimant and Risepoint, its legal predecessors and/or partners under the Unibet label; 6.3. orders that the defendants must provide the data referred to above under 6.1 and 6.2 electronically in a common file format (such as XLS(X) or CSV) or by means of an Application Programming Interface, in such a manner that the information and data to be provided to the claimants are intelligible and that each of the claimants can verify, on the basis thereof, the accuracy of the personal data and the lawfulness of the processing of those data; 6.4. orders Kindred and Risepoint jointly and severally to pay a penalty of € 500 per claimant for each day that they fail to comply with the judgments referred to under 6.1, 6.2 and 6.3, with a maximum of € 10,000 per claimant; 6.5. orders Kindred and Risepoint jointly and severally to pay the legal costs, assessed on the part of the claimants at € 1,495, to be paid within fourteen days after notification thereof. If Risepoint and Kindred fail to comply with the judgments in a timely manner and the judgment is subsequently served, they shall pay an additional € 98 in ancillary costs, plus the costs of service; 6.6. orders Kindred and Risepoint jointly and severally to pay statutory interest as referred to in Article 6:119 of the Dutch Civil Code on the legal costs if these are not paid within fourteen days after notification; 6.7. declares this judgment provisionally enforceable; 6.8. dismisses any further or other claims. This judgment was rendered by Mr. C.J-A. Signed and pronounced in public on 27 May 2026. 1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), OJ EU 2016, L 119/1. 2 Implementing Act General Data Protection Regulation. 3 Delivered under case number: C/09/681584 / HA RK 25-133. 4 European Data Protection Board (EDPB), Guidelines 07/2020 on the concepts of “controller” and “processor” in the GDPR, Version 2.0 (7 July 2021), paragraph 12 and §2.1.2. 5 Article 4(7) of the GDPR states that the controller is the person who “alone or jointly determines the purposes and means of the processing of personal data”. 6 CJEU 29 July 2019, case no. C-40/17, ECLI:EU:C:2019:629 (Fashion ID), §65; CJEU 5 June 2018, C-210/16, EU:C:2018:388, §26 and 27 (Wirtschaftsakademie Schleswig-Holstein).

¶7

CJEU 10 July 2018, C-25/17, ECLI:EU:C:2018:551 (Jehovan Todistajat).

¶8

Claimants 1, 2, 8 and 11.

¶9

CJEU 26 October 2023, C-307/22, ECLI:EU:C:2023:811 (FT/DW), §52 and §80 sub 1.

¶10

CJEU 26 October 2023, C-307/22, ECLI:EU:C:2023:811 (FT/DW), §43.

¶11

With the exception of those of Claimant 5 and Claimant 9 insofar as they are addressed to Kindred.

¶12

Cf. Supreme Court 11 February 1994, ECLI:NL:HR:1994:ZC1265, legal ground 3.2; Supreme Court 28 September 2001, ECLI:NL:HR: 2001:ZC3656, legal ground. 3.5; Supreme Court 12 July 2013, ECLI:NL:HR:2013:BZ3640, legal ground 3.9; Parliamentary Papers II 2019-2020, 35 498, no. 3, pp. 16 and 23. 13 https://idpc.org.mt/for-organisations/restrictions/.

¶14

See also District Court of Amsterdam ECLI:NL:RBAMS:2025:4663, legal ground 4.7.

¶15

CJEU 26 October 2023, C-307/22, ECLI:EU:C:2023:811 (FT/DW), §72-75; CJEU 4 May 2023, C-487/21, ECLI:EU:C:2023:369 (Österreichische Datenschutzbehörde and CRIF), §32. Search assistance An extensive manual is available for searching for judgments, including explanations regarding: Search by date of judgment/publication Search by keywords Search by ECLI or LJN Search by area of law Finding locations for judgments Finding judgments at locations Selection criteria The Judiciary, the Supreme Court of the Netherlands, and the Council of State publish judgments based on selection criteria: Judgments in multi-judge chamber cases Judgments of the Supreme Court and appellate courts Judgments with media attention Judgments in criminal cases European law Guideline judgments Recusal Full selection criteria Weekly overview Select a week and view which judgments have been added to the judgment register in that week. Weekly overview of rulings English Sitemap Privacy Cookies Accessibility Spoofing Vacancies Archive Disclaimer Follow us twitter facebook facebook linkedin youtube Stay up to date rss email

Similar Content