The Dutch data protection authority just spent two years proving a point: a pre-ticked consent box is never valid consent, no matter how small the checkbox looks. In 2024 it fined AS Watson €600,000 over Kruidvat.nl's tracking cookies. On appeal, that fine dropped to €50,000, but the underlying finding stood, and the Autoriteit Persoonsgegevens (AP) has since warned more than 200 Dutch websites that their banners have the same problem.
If your site serves EU visitors and your cookie banner defaults to "accept," pre-selects any non-essential category, or buries the reject option behind extra clicks, you are running the exact configuration the AP just spent two years penalizing. This is not a hypothetical risk. It is an active, sweep-style enforcement program with a fine schedule already attached to it.
Key Takeaways
- AS Watson's fine for Kruidvat.nl's pre-ticked cookie box dropped from €600,000 to €50,000 on appeal, but the AP's finding that pre-ticked boxes are invalid consent was upheld, not overturned.
- The AP has issued formal warnings to more than 200 Dutch websites over misleading cookie banners since 2025, with roughly three-quarters correcting their setup and the rest now facing investigation or fines.
- The AP now automatically scans thousands of Dutch websites' cookie banners on an ongoing basis and has set a public target of reviewing 500 sites a year, meaning banner-default violations are being detected systematically, not by complaint.
What the AP actually found wrong with Kruidvat's banner
The Kruidvat.nl case traces back to an AP investigation opened in late 2019. Inspectors found that the site's cookie banner had a box for tracking cookies that was pre-ticked by default, and that visitors who wanted to refuse had to navigate a deliberately longer path than visitors who simply clicked "accept" autoriteitpersoonsgegevens.nl. Because Kruidvat sells items like pregnancy tests and contraceptives, the tracking data at stake included visitors' browsing and purchase behavior tied to health-adjacent products, which raised the sensitivity of what was being collected without a valid legal basis.
The mechanism here matters more than the headline fine. A pre-ticked box shifts the default from "no tracking" to "tracking," which means a visitor who does nothing at all is recorded as having consented. Under the standard the Court of Justice of the EU set in its Planet49 ruling, consent has to be an active, unambiguous choice; a default the user never touched cannot be that choice, regardless of how the checkbox is labeled (SP's breakdown of the Planet49 ruling walks through why this standard applies to any pre-checked box, not just Planet49's specific lottery form). The AP applied that same logic to Kruidvat: the site corrected its banner by October 2020, but the violation period behind it still generated the fine four years later, once the AP's formal decision was issued in July 2024.
Why the fine shrank to €50,000 without the violation disappearing
AS Watson objected to the €600,000 fine, and in May 2025 the AP reduced it to €50,000. It is tempting to read that reduction as the company winning its case. It did not. The AP's own reasoning for the cut cited procedural factors: the unusually long time the AP itself took to move from investigation to enforcement, AS Watson's acknowledgment of the violation, and the comparatively limited severity of this instance relative to other cookie violations the AP has pursued. None of those reasons touch the actual finding, which is that the pre-ticked box was unlawful. The consequence for a business assessing its own risk is that a smaller fine on appeal is not evidence a similar banner would survive scrutiny; it is evidence that the AP's process, not its standard, has room to be argued down.
This procedural-versus-substantive split is not unique to the Netherlands. The same distinction is playing out in Luxembourg's 2026 annulment of Amazon's €746 million GDPR fine, where a court found fault with how the fine was calculated without disturbing the finding that Amazon's practices were unlawful. Regulators are increasingly separating "was this illegal" from "was this specific penalty calculated correctly," and businesses that treat a reduced or annulled fine as vindication are reading only half the ruling. The same manipulation tactics regulators keep penalizing, not just pre-ticked boxes but asymmetric accept/reject button design, show up across nearly every one of these enforcement actions.
The Dutch DPA's 200-site cookie banner warning wave is the bigger signal
Kruidvat is one enforcement action from one investigation. The AP's broader 2026 cookie-banner sweep is the part that should change how any EU-facing site owner prioritizes their compliance backlog. Since 2025, the AP has sent formal warnings to more than 200 Dutch websites, covering online retailers, media outlets, and insurers, after automated scans flagged banners with hidden reject buttons, pre-ticked boxes, or tracking cookies that fired before any consent was given at all, including cases where cookies loaded even after a visitor clicked "reject." Roughly three-quarters of the warned sites corrected their banners within the response window; the remainder now face a formal investigation or fine track Hogan Lovells.
This is not a one-off sweep that clears itself out. The AP has allocated dedicated annual budget through 2026 specifically for cookie and tracking oversight, built an automated tool that continuously scans the cookie banners of thousands of Dutch websites, and set a public target of reviewing 500 sites a year going forward. AP chairman Aleid Wolfsen has described the approach as deliberately two-sided: "We don't just point out to organisations what they're doing wrong, we also help them to do it right" as reported, which signals warnings-first enforcement rather than fines-first, but also confirms that non-response converts a warning into an investigation.
The cookie sweep is also not a standalone initiative sitting apart from the AP's broader agenda. In its published strategic priorities for 2026-2028, the AP names mass surveillance as one of three core focus areas and explicitly places "the legal framework for online data collection (such as cookies)" inside that priority, alongside camera surveillance and location tracking. That framing matters for how seriously a compliance team should take a warning letter: cookie tracking is no longer being treated by the regulator as a narrow technical formality, but as one instance of a category the AP considers capable of eroding personal autonomy at scale.
A single member state running an active, resourced, automated cookie-banner sweep is historically a leading indicator, not an isolated event. Germany, France, and Belgium have each escalated cookie enforcement in stages that started with a warning campaign before moving to fines against non-responders, and the Netherlands' own guidance has previously anticipated this pattern SP's guide to Dutch DPA cookie guidelines. Treating this as a Netherlands-only problem is the mistake most likely to cost a compliance team time later. A banner redesigned around genuine reject-accept parity is the difference between passing an automated scan and generating the next warning letter.
Before your next banner review, check whether reject is genuinely one click away. Secure Privacy's fully customizable banner templates let you configure reject and accept as equal, single-step actions without hand-coding the layout.
Banner-default audit checklist
Run this checklist against your current banner configuration before your next release, not after a regulator flags it.
| Check item | What "compliant" looks like | What the AP has fined for |
|---|---|---|
| Default toggle state | Every non-essential category defaults to off | Pre-ticked boxes for tracking cookies |
| Reject visibility | Reject sits on the first layer, same size and prominence as accept | Reject hidden behind a second layer or smaller/grayed-out button |
| Click parity | Accepting and rejecting take the same number of clicks | Rejecting requires extra steps or a settings dive |
| Script timing | No tracking script, pixel, or cookie fires before a consent signal is recorded | Cookies placed before the visitor made any choice |
| Post-rejection behavior | Cookies already set are cleared or never fire after "reject" is clicked | Tracking cookies continuing to fire after a visitor rejected them |
| Consent record | Every accept/reject decision is timestamped, exportable, and tied to the banner version shown | No usable record to demonstrate what consent was actually given |
| Regional logic | Consent requirements and defaults match the applicable local law (GDPR/ePrivacy in the EU) | Generic banners that don't reflect jurisdiction-specific rules |
The last two rows are where most sites without a dedicated consent management platform quietly fail, because a corrected banner today does not prove what the banner looked like six months ago if a regulator asks. Building a defensible audit trail means every accepted, declined, or partial consent decision is timestamped, exportable, and tied to the exact banner version a visitor saw, so a compliance team can produce evidence rather than reconstructing one from memory after a warning letter arrives.
Common issues and fixes
Sites that fail this kind of scan rarely fail on one dramatic violation; they fail on small defaults nobody revisited after the initial banner setup.
- A marketing team added a new ad pixel and it fires immediately. Fix: route every new script through the same consent-gated deployment process the original banner used, not a direct tag-manager insertion that bypasses it.
- The banner was last configured by a developer who has since left. Fix: assign banner-configuration ownership to a named role (privacy, legal, or marketing ops) with documented change history, so a leaver doesn't leave a compliance gap.
- Reject is technically present but three menu levels deep. Fix: move reject to the first layer of the banner itself; a "manage preferences" link is fine as an additional option, not as the only way to refuse.
- Cookies were "removed" from the banner list but the script that sets them was never deleted. Fix: re-run a full site scan after any banner change, since removing a category from the banner UI does not remove the underlying script.
None of these fixes require a rebuild. They require an automated compliance scan that catches the gap between what your banner claims and what your scripts actually do.
FAQ
Was the Kruidvat cookie fine overturned on appeal?
No. The fine amount was reduced from €600,000 to €50,000 in May 2025, but the AP's finding that Kruidvat.nl's pre-ticked consent box was invalid under GDPR remained in place. The reduction was based on procedural factors, including the length of the AP's own process, not a finding that the banner was compliant.
How many websites has the Dutch DPA warned about cookie banners?
More than 200 Dutch websites have received formal warnings since the AP's cookie-banner sweep intensified, covering retailers, media companies, and insurers. Around three-quarters corrected their banners after the warning; the rest face investigation or fines.
Are pre-ticked cookie consent boxes ever legal under GDPR?
No. The Court of Justice of the EU settled this in the Planet49 ruling: consent must be an active, unambiguous action taken by the user, and a pre-ticked box does not meet that standard regardless of what the checkbox is labeled or how the site's privacy policy describes it.
Does this enforcement only apply to companies based in the Netherlands?
No. The AP's jurisdiction covers any site targeting or tracking visitors in the Netherlands, not just Dutch-incorporated companies. A non-Dutch business with meaningful Dutch traffic and a non-compliant banner is within scope of the same automated scanning program.
What is the fastest way to check if my banner has the same problem as Kruidvat's?
Load your site as a fresh visitor, with no prior cookies, and confirm that no tracking cookie appears in your browser's storage before you click anything. Then click "reject" and reload the page; if any tracking cookie is still present, your banner has the same failure mode the AP has been fining.
What should I do if my site already received an AP warning letter?
Correct the specific defaults the letter identifies, keep a dated record of the change, and treat the correction window as final. Warnings that go unaddressed are the ones converting into formal investigations under the AP's current program.
Whichever stage your banner is at, the fix is rarely a redesign. It's fixing the defaults. Secure Privacy's cookie and consent platform builds reject-as-easy-as-accept banners, blocks scripts until consent is recorded, and logs every decision as an exportable audit trail so the next regulator sweep finds a defensible answer instead of a pre-ticked box.




