← Regulators
GDPR EU 2016/679 Netherlands

Who is the AP: the Netherlands' data protection authority and algorithm watchdog

The Autoriteit Persoonsgegevens is the Netherlands' GDPR supervisory authority — the regulator that fined Uber €290 million and Clearview AI €30.5 million, and, unusually, also the country's coordinating supervisor for algorithms and AI. What it does, how it is run, and who chairs it through the 2026 leadership change — every fact sourced.

Most data protection authorities do one job: enforce the GDPR. The Netherlands’ Autoriteit Persoonsgegevens (AP) does that — it is the regulator behind the €290 million Uber transfer fine and the €30.5 million Clearview AI penalty — but it has also been handed a second, unusual mandate that most of its EU peers do not have: it is the Dutch coordinating supervisor for algorithms and AI. This is a profile of what the AP is, what it does, and who runs it through a chair handover happening in 2026. Every fact is sourced.

Quick facts

  • Full name: Autoriteit Persoonsgegevens (AP) — the Dutch Data Protection Authority
  • Role: the Netherlands’ GDPR supervisory authority — “the independent supervisor” that checks whether organisations process personal data lawfully (AP Jaarverslag 2025); a member of the EDPB
  • Legal status: an independent administrative authority with a legal personality of its own, managed by a board, organised into six directorates (AP — Organisation)
  • Legal basis: the GDPR and its Dutch implementation act, the UAVG (Uitvoeringswet AVG); the body took its current name Autoriteit Persoonsgegevens on 1 January 2016, succeeding the College bescherming persoonsgegevens (CBP), when Dutch law also gave it the power to impose fines
  • Second mandate: the national coordinating supervisor for algorithms and AI (a dedicated directorate set up in 2023), publishing the half-yearly Rapportage AI- & Algoritmerisico’s Nederland (RAN) (AP Jaarverslag 2025)
  • Board: Aleid Wolfsen (chair), Monique Verdier (deputy chair) and Katja Mur (board member) (AP Jaarverslag 2025)
  • Incoming chair: Geert Potjewijd, who becomes chair from 1 August 2026 for a five-year term, succeeding Wolfsen (AP)
  • Seat: The Hague (‘s-Gravenhage) (AP Jaarverslag 2025)
  • Website: autoriteitpersoonsgegevens.nl

What the AP is — and what it is not

The AP is the Netherlands’ data protection authority (DPA — the independent national regulator that supervises and enforces data-protection law) and the country’s GDPR supervisory authority. In its own words it is “the independent supervisor” that checks whether organisations handle personal data in line with the GDPR (AP Jaarverslag 2025), and it is one of the 27 national authorities on the EDPB. Legally it is an independent administrative authority with its own legal personality, run by a board and split into six directorates (AP — Organisation).

What makes it stand out from most peers is its second hat. Since 2023 the AP has been the Netherlands’ coordinating supervisor for algorithms and AI — a national role, distinct from classic GDPR work, in which it maps how algorithms and AI are used across the public and private sectors and publishes a recurring risk report. That is why the AP shows up in the AI conversation more than a typical DPA.

But the distinction matters: the AP’s enforcement powers run through the GDPR, not (yet) through the AI Act. Its algorithm work is supervision, mapping and guidance; when it actually fines someone, the legal basis is data-protection law. Like every DPA, its “AI” cases are GDPR cases that happen to involve AI.

What the AP actually does

Its core job is the standard GDPR toolkit — handling complaints, taking in data-breach notifications, running investigations, issuing corrective orders and fines. Two features make it notable:

  1. It enforces hard against cross-border data flows. The AP’s headline fines are about data leaving the EU without protection — most prominently the Uber case below.
  2. It coordinates algorithm and AI oversight nationally. Through its dedicated directorate it publishes the half-yearly Rapportage AI- & Algoritmerisico’s Nederland (RAN) and works on practical guidance — for example on AI literacy and on getting automated decision-making right (AP Jaarverslag 2025).

On scale: in 2025 the AP received 7,465 complaints (up from 7,119 in 2024), and — counting complaints and other signals together — 13,517 in total, alongside tens of thousands of data-breach notifications (AP Jaarverslag 2025).

The AP’s enforcement record

The AP is one of the more active fining authorities in the EU. Its two most internationally cited cases:

  • Uber — €290 million (2024). For transferring sensitive data on European drivers to the United States without a valid transfer mechanism. The case is one of the largest fines in EU history; details, articles and status are in the Big Tech GDPR fines registry.
  • Clearview AI — €30.5 million (2024). Part of a Europe-wide pushback against the US facial-recognition company; the cross-regulator picture is in the Clearview AI fines registry.

It also issues a steady stream of mid-size domestic fines — for example a €2.7 million penalty on Experian for unlawful processing in its credit-data business (AP Jaarverslag 2025).

The board — how the AP is run, and the 2026 handover

The AP is run by a board, not a single director. As recorded in its 2025 annual report, the board is Aleid Wolfsen (chair), Monique Verdier (deputy chair) and Katja Mur (board member) (AP Jaarverslag 2025).

That top is changing. The AP has announced that from 1 August 2026, Geert Potjewijd will be the new chair, succeeding Aleid Wolfsen, who held the position for the past 10 years; the appointment is for a five-year term (AP). Potjewijd joins from the law firm De Brauw Blackstone Westbroek, where he co-led the data-protection and cyber-security practice. As of mid-2026, Wolfsen remains the sitting chair — Potjewijd does not take over until 1 August — so any current-leadership reference should name Wolfsen, with Potjewijd as the incoming chair.

What this means for you

  • If you process personal data and reach Dutch users: the AP is your supervisory authority. If your business is established in the Netherlands and you operate across the EU, it can also be your lead authority under the one-stop-shop (the mechanism explained on the DPC profile) — which is exactly why Uber answers to the AP.
  • If you send data outside the EU: this is the AP’s sharpest enforcement edge. The Uber fine was for transfers to the US without a working mechanism — the same trap a smaller company falls into with US cloud, analytics or CRM tools.
  • If you build or deploy algorithms or AI in the Netherlands: the AP watches this space specifically, through its algorithm-coordination role and the RAN risk reports — but it will act against you under the GDPR (lawful basis, transparency, automated-decision rules), so that is the standard to design to.
  • If you are a journalist or researcher: “the Dutch privacy regulator” = the Autoriteit Persoonsgegevens, an independent administrative authority seated in The Hague, the GDPR supervisory authority for the Netherlands and the national coordinating supervisor for algorithms and AI. Current chair: Aleid Wolfsen; from 1 August 2026, Geert Potjewijd.

TL;DR

The AP (Autoriteit Persoonsgegevens) is the Netherlands’ GDPR supervisory authority — an independent administrative authority seated in The Hague, run by a board, and a member of the EDPB. It is unusual in also being the national coordinating supervisor for algorithms and AI, publishing the half-yearly RAN risk report, though its enforcement still runs through the GDPR. It is a hard enforcer of cross-border transfer rules — the €290 million Uber fine and €30.5 million Clearview AI penalty are both AP decisions. Its board is Aleid Wolfsen (chair), Monique Verdier (deputy chair) and Katja Mur; from 1 August 2026 Geert Potjewijd becomes chair for a five-year term, succeeding Wolfsen after ten years.

Sources