Skip to content
Case Law · District Court Rotterdam ·ROT 25/7371 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

ING Bank N.V. (the controller) is a bank

In 2022, several data subjects brought a complaint to the DPA regarding the controller’s contactless payments.

District Court Rotterdam
Summary

The data subjects requested the controller to issue debit cards without a chip that would enable contactless payments. The controller stated that this was not possible, however, the contactless payment feature could be disabled on the data subjects’ cards. The data subjects later filed a complaint because the debit cards contained the chips even if the contactless feature was disabled. The DPA dismissed the complaint in 2024, on the grounds that further investigation would be needed to determine whether the controller violated the GDPR or not. The DPA stated that it had limited capacity and such an investigation would place a heavy burden on it. The data subjects appealed this decision to the court, who determined that the DPA had wrongfully failed to hear the data subjects during the objection phase. The DPA issued a new decision in 2025 and concluded that the controller had not violated the GDPR. The data subjects appealed this decision, arguing that the DPA had again not investigated the case sufficiently. In addition, the data subjects argued that the controller processed personal data through the debit card chip without a valid legal basis. This is because the chip allowed payments made with blocked or expired cards, meaning Article 6(1)(b) GDPR did not apply. The controller could also not rely on consent (Article 6(1)(a) GDPR) to process the data. The DPA argued that the GDPR does not require controllers to completely eliminate a risk. In addition, disabling contactless payments or blocking cards were related to the contract between the data subject and the controller; the DPA argued that this did not remove the basis to process personal data. Holding — The court found that the DPA investigated the complaint to an appropriate extent and was not required to conduct a further investigation. According to the court, the data subjects did not provide sufficient evidence that the controller’s statements were incorrect or that the DPA lacked the technical knowledge during its investigations. The court upheld the DPA’s reasoning that Article 32 GDPR does not require a security risk to be completely eliminated, and concluded that the DPA could reasonably decide that there was no violation of the GDPR. Similarly, the court upheld the DPA’s reasoning and concluded that the controller had a valid legal basis to process the data subjects’ personal data. The court saw no need to assess potential violations of other laws (e.g. fraud or forgery) or consumer law issues, on the grounds that the DPA’s investigation is limited to compliance with the GDPR. The DPA is also not required to coordinate or refer the case to other competent authorities. The court dismissed the appeal.

How it connects

13 of 25 paragraphs apply legislation or carry a topic — see them in the full text ↓

Full text 25 paragraphs

Paragraphs carrying a topic or an applied provision show those connections inline Original at the source →
¶0

24 June 2026 in the case between [plaintiff] and [plaintiff], from [place], plaintiffs and the Data Protection Authority, the AP (representatives: Mr. A. Karimi and Mr. J.M.A. Koster). Summary

¶1

This ruling concerns a complaint filed by the plaintiffs with the AP regarding the processing of personal data by ING Bank N.V. (ING) in connection with contactless payments. Following the annulment of an earlier decision by the court, the AP concluded in a new decision on the objection that no violation of the General Data Protection Regulation (GDPR) by ING could be established. The plaintiffs disagree with that conclusion and take the position that the AP should have conducted further investigation, if necessary in conjunction with other supervisory authorities.

¶1.1

In this ruling, the court concludes that the AP investigated the plaintiffs' complaint to an appropriate degree and was not required to conduct further investigation. The plaintiffs are not vindicated, and the appeal is therefore unfounded. Below, the court explains how it arrived at this judgment and what consequences this judgment entails. Course of proceedings

¶2

The plaintiffs hold payment accounts with ING and are in possession of payment cards linked to those accounts. These payment cards contain a Near Field Communication (NFC) chip, enabling contactless payment. The plaintiffs requested ING to issue payment cards without an NFC chip in order to prevent unauthorized payments and the exchange of privacy-sensitive data. In a response, ING stated that issuing debit cards without an NFC chip is not possible, but that the contactless payment function on the plaintiffs' debit cards has been disabled.

¶2.1

In December 2022, the plaintiffs filed a complaint with the Dutch Data Protection Authority (AP) regarding data processing related to contactless payments by ING. According to the plaintiffs, ING is acting in violation of the GDPR because its debit cards contain NFC chips that enable contactless payment, even when this function is disabled. The plaintiffs have supplemented their complaint several times since filing it, most recently in December 2023.

¶2.2

By decision of 14 February 2024 (primary decision), the AP made a decision regarding the plaintiffs' complaint. In that decision, the AP considered that the issuing of debit cards with an NFC chip by ING is not a GDPR issue. With regard to the plaintiffs' position that ING is acting in violation of the GDPR through data processing during contactless payments, the AP has concluded that, based on the complaint, no violation can yet be established or ruled out. Further investigation is required for this. As a supervisory authority, the AP has the task of investigating complaints to the extent appropriate. If the AP cannot immediately determine whether an organization has violated the GDPR, the AP will consider, based on certain criteria, whether to investigate the complaint further. The AP has chosen not to do so because it cannot act sufficiently efficiently and effectively. In order to establish or rule out a violation of the GDPR, the AP would have to investigate whether and which personal data are processed during contactless payments, examine the lawfulness of any processing of personal data, request information from ING for this purpose, and possibly conduct an on-site investigation. This investigation places a heavy burden on the limited capacity and resources at the AP's disposal. Therefore, the AP has decided not to conduct a further investigation. By decision of 29 August 2024 on the plaintiffs' objection, the AP maintained this handling of the complaint.

¶2.3

By ruling of 23 April 2025, the court annulled the decision of 29 August 2024 because the AP wrongly failed to hear the plaintiffs during the objection phase.

¶2.4

With the contested decision of 2 September 2025, the AP took a new decision on the plaintiffs' objection, after first having heard the plaintiffs at the hearing of 12 June 2025. In the contested decision, the AP concludes that it investigated the complaint to an appropriate degree, but that based on the file, no violation of the GDPR by ING can be established.

¶2.5

The plaintiffs lodged an appeal against the contested decision. The AP responded to the appeal with a statement of defence.

¶2.6

The court heard the appeal at a hearing on April 1, 2026. Participating in this hearing were: the plaintiffs and the representatives of the AP. Plaintiffs' position

¶3

The plaintiffs take the position that the AP did not investigate their GDPR complaint to an appropriate degree. Based on what the plaintiffs have argued, it is already evident that a violation of the GDPR has occurred. The AP should have conducted further investigation based on the evidence and arguments put forward by the plaintiffs and should have involved technical expertise in doing so. In addition, the plaintiffs argue that insofar as the complaint concerns violations of laws for which the AP is not competent, it was obliged to seek coordination with other supervisory authorities or to transfer the case. Relevant legislation and regulations

¶4

The legislation and regulations relevant to the assessment of the appeal can be found in the annex to this ruling. Assessment by the court Did the AP investigate the plaintiffs' GDPR complaint to an appropriate degree?

¶5

The plaintiffs put forward a number of arguments in support of their ground of appeal that the AP did not investigate their complaint to an appropriate degree.

¶5.1

In the first place, the plaintiffs argue that they have demonstrated, by means of various tests, that the NFC chip is not secure. For instance, payments can be made with blocked or expired cards, and there is a risk of unintended contactless payment. According to the plaintiffs, the AP failed to recognize this lack of security, with the plaintiffs pointing to insufficient technical expertise at the AP. In addition, the plaintiffs point out that the measures taken by ING, such as retroactive authorization, do not always work, and that this is also evident from actual debits made by the plaintiffs. According to the plaintiffs, the information provided by ING regarding this is fraudulent, with them pointing, among other things, to incorrect payment characteristics and card numbers. According to the plaintiffs, the AP overlooks the fact that the problem lies with the NFC chip itself. The alternative offered by ING, namely switching to another bank free of charge, does not give the plaintiffs genuine freedom of choice and therefore does not eliminate the lack of security.

¶5.2

In addition, the plaintiffs argue that there is no legal basis for the processing of their personal data and that the processing is therefore in violation of Article 6 of the GDPR. According to the plaintiffs, in the case of an active payment relationship, “performance of a contract” is the appropriate legal basis. However, as soon as the card is blocked, expired, or the contactless function is disabled, the contract is, according to the plaintiffs, effectively suspended or terminated. Nor does consent apply as a legal basis in that case, according to the plaintiffs. Consequently, according to the plaintiffs, the legal basis for processing lapses and that processing is unlawful.

¶5.3

In the contested decision, the AP explained that, as a supervisory authority, it has the task of investigating the plaintiffs' complaint to the extent appropriate. The AP points out that it receives a large number of reports and complaints annually. The best approach and the amount of investigation required vary per complaint. If the AP cannot immediately determine whether the organization has violated the GDPR, the AP considers whether to investigate the complaint further. The AP uses the criteria mentioned above for this purpose. By employing this method, the AP provides insight into the manner in which compliance with regulations is monitored in the event of complaints and the manner in which it appropriately determines the scope of the investigation. In this regard, the AP points out that its method was not deemed unreasonable by the Administrative Jurisdiction Division of the Council of State4.

¶5.4

Based on the plaintiffs' notice of objection, all submitted documents, and what was discussed during the earlier appeal proceedings, the AP reassessed the case and reconsidered the primary decision of 14 February 2024. In the contested decision, the AP concludes that it investigated the plaintiffs' GDPR complaint appropriately and that, based on the file and the instances of use of the payment card described by the plaintiffs, no violation of the GDPR can be established.

¶5.5

The court is of the opinion that the AP investigated the complaint appropriately and that it was reasonably entitled to take the position that, based on that investigation, no violation of the GDPR by ING can be established. The court explains this below.

¶5.6

When using the payment cards, the plaintiffs' personal data are processed by ING as the controller. Article 32 of the GDPR requires controllers to tailor technical and organizational measures to the risks with appropriate security levels and to take into account the assessment criteria set out in the first paragraph of that provision. The Dutch Data Protection Authority (AP) assessed ING's compliance with this provision on the basis of the complaint and what the plaintiffs put forward regarding the use of their payment cards, debits (bank statements and timelines), and the technical operation and risks of using NFC chips. In addition, the AP reviewed documents and statements from ING regarding this matter and gave the plaintiffs the opportunity to respond to the information from ING. Based on that information, the AP does not consider it substantiated that there was accidental contactless payment or an error in that regard, and according to the AP, the instances of use of their payment cards cited by the plaintiffs do not lead to the conclusion that ING violated Article 32 of the GDPR.5.7. The court considers that while the plaintiffs did express doubts regarding the findings of the AP and the underlying statements and documents from ING, they have not substantiated that these findings of the AP or statements from ING are incorrect, or are based on false information or insufficient technical knowledge. With regard to the plaintiffs' assertion that the NFC chip still works with blocked or expired cards or for which contactless payment has been disabled, and that this constitutes a risk, the AP explained in the contested decision that the GDPR does not require risks to be completely eliminated5 and that risks can also be mitigated by additional measures (such as retroactive authorization, requiring a PIN code above certain amounts, and compensation in the event of fraud). The AP notes that, more broadly, it is not aware of any signals or complaints regarding problems surrounding payments with NFC chips. The plaintiffs have not contested this explanation, which the court deems plausible, with reasoned arguments. In view of the foregoing, the AP could reasonably take the position that, based on the file, no violation of Article 32 of the GDPR by ING can be established.

¶5.8

It follows from Article 6, paragraph 1, of the GDPR that the processing of personal data is only lawful if and to the extent that there is a valid legal basis for processing. Based on the plaintiffs' complaint and ING's statements, the AP assessed possible legal bases for processing and concluded that ING generally has a legal basis for processing payment data, namely a statutory obligation. In addition, the processing operations may also be necessary for the performance of the contract or necessary for the pursuit of the legitimate interests of ING or of a third party. The AP also explained that explicit consent is not required for making payments, whether contactless or not, and emphasized that ING customers themselves decide whether or not to make a payment using an NFC chip, namely by holding the bank card against the payment terminal. There are sufficient alternatives, and the AP has not found evidence of the situation outlined by the plaintiffs regarding contactless payment against their will. The AP subsequently concluded that, based on the facts and circumstances presented, it could not establish that ING was processing the plaintiffs' personal data without a valid legal basis.

¶5.9

In the appeal, the plaintiffs only contested the contractual basis with reasoned arguments. In this regard, the court can follow the AP's interpretation that disabling contactless payment or blocking the card primarily relates to the contract between the bank and the account holder and does not remove the legal basis for the processing of personal data. In view of the foregoing, the AP could reasonably take the position that, based on the file, no violation of Article 6 of the GDPR by ING could be established.

¶5.10

In view of what the court has considered above, the AP could reasonably take the position that, based on the file, no violation of the GDPR could be established and was entitled to refrain from further investigation. Alleged violations of other laws and civil or consumer law issues

¶6

The court will not address the substance of other violations that ING allegedly committed according to the plaintiffs, such as fraud and forgery. The AP is the privacy supervisory authority in the Netherlands. The AP only investigated compliance with the GDPR. The AP ruled on a GDPR complaint filed by the plaintiffs, and that is therefore the decision being reviewed by the court. For reporting violations of other laws, the plaintiffs can turn to the police/Public Prosecution Service or other supervisory authorities such as DNB and AFM. Contrary to what the plaintiffs claim, the AP is not obliged to seek coordination with other supervisory authorities regarding this matter, or to transfer the complaint to other supervisory authorities.

¶6.1

Whether ING was required to offer the plaintiffs the choice of a debit card unsuitable for contactless payment, and whether failing to do so constitutes tied selling, are, as the AP has indicated, not GDPR issues. The court cannot address this matter substantively either. Conclusion and consequences

¶7

The appeal is unfounded. This means that the AP has investigated the plaintiffs' complaint to an appropriate degree and the AP was not required to conduct further investigation. Therefore, the plaintiffs will not be refunded the court fees. They will also not be reimbursed for their legal costs. Decision The court declares the appeal unfounded. This judgment was rendered by Mr. A.A. Kleinhout, presiding judge, and Mr. J. Fransen and Mr. S.M. Goossens, members, in the presence of A. van Duijn, registrar. Pronounced in public on 24 June 2026. The registrar is unable to sign the judgment registrar presiding judge A copy of this judgment was sent to the parties on: Information regarding appeal A party that disagrees with this judgment may send a notice of appeal to the Administrative Jurisdiction Division of the Council of State explaining why that party disagrees with this judgment. The notice of appeal must be filed within six weeks of the day on which this ruling was sent. If the appellant cannot await the handling of the appeal because the matter is urgent, the appellant may request the preliminary relief judge of the Administrative Jurisdiction Division of the Council of State to grant a preliminary injunction (a temporary measure). Appendix: legislation and regulations relevant to this ruling General Data Protection Regulation Article 5 Principles regarding the processing of personal data 1 Personal data must: a) be processed in a manner that is lawful, fair and transparent with regard to the data subject (“lawfulness, fairness and transparency”); (…) Article 6 Lawfulness of processing 1 Processing is lawful only if and to the extent that at least one of the following conditions is met: (…) b) the processing is necessary for the performance of a contract to which the data subject is a party, or to take measures at the request of the data subject prior to entering into a contract; c) the processing is necessary to comply with a legal obligation to which the controller is subject; (…) f) the processing is necessary for the legitimate interests of the controller or of a third party, except where the interests or fundamental rights and freedoms of the data subject which require protection of personal data outweigh those interests, in particular where the data subject is a child. (…) Article 32 Security of processing 1 Taking into account the state of the art, the costs of implementation, as well as the nature, scope, context and purposes of the processing and the varying likelihood and severity of the risks to the rights and freedoms of individuals, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security commensurate with the risk, which, where appropriate, shall include: a) pseudonymisation and encryption of personal data; b) the ability to guarantee the confidentiality, integrity, availability and resilience of the processing systems and services on a permanent basis; c) the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident; d) a procedure for periodically testing, assessing and evaluating the effectiveness of the technical and organisational measures for the security of the processing. 2 When assessing the appropriate level of security, account shall be taken in particular of the processing risks, especially those resulting from the destruction, loss, alteration or unauthorized disclosure of or unauthorized access to transmitted, stored or otherwise processed data, whether accidentally or unlawfully. (…) Article 57 Tasks 1 Without prejudice to other tasks established under this Regulation, each supervisory authority shall perform the following tasks within its territory: (…) f) it handles complaints from data subjects, or from bodies, organisations or associations in accordance with Article 80, investigates the substance of the complaint to the extent appropriate and informs the complainant within a reasonable period of time of the progress and result of the investigation, in particular if further investigation or coordination with another supervisory authority is necessary; (…) 1 The AP has referred to: https://www.autoriteitpersoonsgegevens.nl/behandeling-van-klachten-door-de-ap 2 District Court of Rotterdam, 23 April 2025, ECLI:NL:RBROT:2025:5290. 3 Article 57, paragraph 1(f) of the GDPR. 4 Administrative Jurisdiction Division of the Council of State (ABRvS) 19 April 2023, ECLI:NL:RVS:2023:1535, paragraphs 5.1 and 5.2 The AP also refers to District Court of Central Netherlands 25 April 2024, ECLI:NL:RBMNE:2024:2531. 5 With reference to Court of Justice of the European Union 14 December 2023, C-340/21, ECLI:EU:C:2023:986. Help with searching An extensive manual is available for searching for judgments, including explanations regarding: Search by date of judgment/publication Search by keywords Search by ECLI or LJN Search by area of law Finding locations for judgments Finding judgments at locations Selection criteria The Judiciary, the Supreme Court of the Netherlands, and the Council of State publish judgments based on selection criteria: Judgments in multi-judge chamber cases Judgments of the Supreme Court and appellate courts Judgments with media attention Judgments in criminal cases European law Guideline judgments Recusal Full selection criteria Weekly overview Select a week and view which judgments have been added to the judgment register in that week. Weekly overview of judgments English Sitemap Privacy Cookies Accessibility Spoofing Vacancies Archive Disclaimer Follow us twitter facebook facebook linkedin youtube Stay up to date rss email