The encyclopedia · Legal & Compliance · Legal decision · 2018–2024
Netflix fined €4.75M for not telling customers what it does with their data
The Dutch data authority fined Netflix — its privacy notices never made clear how customers' personal data was used or shared.
Netflix · 2024-12-18
What happened
On 18 December 2024 the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) fined Netflix €4.75 million for not giving customers enough, or clear enough, information about what it does with their personal data.
Between 2018 and 2020 Netflix was not clear about the purposes of and legal basis for collecting and using data, which data it shared with other parties and why, how long it kept the data, and how the data stayed safe when transferred outside Europe. Customers who asked which data Netflix held about them also did not get enough information back.
The case began with a complaint from the privacy group noyb, which was forwarded to the Dutch regulator because Netflix's main European establishment sits in the Netherlands. The Dutch authority coordinated the investigation and the penalty with other European regulators.
Netflix objected to the fine and said it had modernised its privacy statement and improved how it informs customers.
Why it happened
- Writing a privacy notice that did not say what data was collected, why, or with whom treated the right to information as fine print rather than as something a customer could act on.
- Answering a direct request about stored data with less than the law required priced the gap between what the notice promised and what it actually disclosed.
- A clarity failure that ran for years across the whole European business made the penalty a matter of the information not being good enough, not of a single slip.
The lesson
A data-protection notice is judged by what a customer can learn, not by what it legally discloses. If the purposes, sharing and retention are unclear, the regulator prices the whole gap.
Aftermath
Netflix objected to the penalty and updated its privacy statement and information practices. The investigation, which the Dutch authority began in 2019, ran across Netflix's European base in the Netherlands and was coordinated with other EU data-protection authorities because of the cross-border reach of the services involved.
Sources
- Netflix fined for not properly informing customers — Autoriteit Persoonsgegevens
- Dutch DPA Fines Netflix €4.75 Million for GDPR Violations Over Data Transparency — The Hacker News
spotted an error? The club wants to know.
More like this
Google stacked its ad exchange against rivals — €2.95B EU fine
TikTok let staff in China access EEA user data — €530M GDPR fine
Meta's 2018 breach exposed 29M accounts — a €251M fine six years later
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.