
Cordemeyer & Slager
INPLP member firm · HL Amsterdam, Netherlands
Cordemeyer & Slager Advocaten B.V. ( a company with limited liability) is a specialised law firm for the IT branch and dealing with issues in the field of I(C)T-law, employment law, Privacy and company law (including M&A), internet Law, tendering and litigation. Most of Cordemeyer & Slagers’s clientele are IT companies. We are also consulted by users in that market who need advice relating to information and computer contracts. Members of our firm serve as arbitrators and mediators in accordance with the Stichting Geschillenoplossing Organisatie en Automatisering or SGOA (Foundation for the Settlement of Automation Disputes). We are LawyersforIT, and like to help and understand IT Companies Wilsonsplein 15, 2011 VG Haarlem - NL P.O. Box 3223, 2001 DE Haarlem - NL T: +31 (0)23 534 01 00 F: +31 (0)23 534 45 50 M: +31653146592 I: www.cordemeyerslager.nl Bob Cordemeyer, the founder of Cordemeyer & Slager / Advocaten has broad experience as IT law attorney-at-law. He advises and assists clients in all kinds of complex national and cross-border IT contracts and is an experienced litigator in IT disputes on failed automation projects and has a considerable track record for amicable settlement of disputes through negotiating or mediation. He is as mediator and arbitrator associated with the SGOA (the Foundation for the Resolution of Automation Disputes). He is a privacy specialist and advises his clients on GDPR issues. Bob is a member of VIRA (Netherlands Association of Information Technology Lawyers), of NVvIR(Netherlands Association for Information Technology and Law) and of PON (Platform Outsourcing Netherlands). He represents the law firm in the international network IGAL (International Grouping of Accountants and Lawyers) and represents the Netherlands in CPC (Cloud Privacy Check). Hanneke Slager mainly practises law in the IT sector and advises and assists her clients in all kinds of complex national and cross-border IT contracts. These contacts concern outsourcing, implementation, turn key, agile and waterfall, licences, hosting, cloud services, open source, sales of hardware, management and maintenance, managed services, etc. Hanneke also assists her clients in trying to prevent or solve IT disputes – where requested through conflict prevention, mediation, (international) arbitration and other forms of ADR (Alternative Dispute Resolution). Hanneke graduated at Groningen University, where she specialized in private law and socio-economic law. She was admitted to the bar in 1989 and became a partner at Cordemeyer & Slager / Advocaten in that same year. She successfully completed the mediation training programme. She frequently speaks at seminars and conferences in the Netherlands and abroad and she is a lecturer at the Juridische Academie. She lectures IT law in the Grotius post-academic specialist programme. Hanneke has been a member of the SGOA (Governing Board of the Foundation for the Resolution of Automation Disputes) since 2002, and its chairman since January 2009. Since 2012 she has been a member of the Supervisory Board of the NL Net Foundation. From 2005 to 2012 she was a member of the SIDN (Supervisory Board of the Foundation for Internet Domain Registrations in the Netherlands). Hanneke is a member of VIRA (Netherlands Association of Information Technology Lawyers), of NVvIR (Netherlands Association for Information Technology and Law) and of PON (Platform Outsourcing Netherlands). Hanneke is the author of various articles in a wide range of magazines and professional journals, particularly on the subject of IT law. She is the co-author of series on Recht en Praktijk (169), ‘Van geschil tot oplossing’, chapter 4: ‘Het arbitraal kort geding: opbergen of oppoetsen’ (February 2009). She is main-author of ‘Wegwijzer Automatisering en recht’ (1990) and co-author and final editor of ‘Werken met Source Code Escrow’ (1989).
Representatives

Bob Cordemeyer
partner

Hanneke Slager
member
Contact
Publications
- Tracking trouble: AS Watson's €600,000 fine and Google’s Privacy Sandbox under scrutinyRecently, two notable cases have emerged demonstrating that the consent requirement for cookies is not always adhered to. The Dutch Data Protection Authority (AP) fined AS Watson B.V., the parent company of the Dutch drugstore chain Kruidvat, €600,000 for placing tracking cookies on Kruidvat.nl without the required consent. At the same time, concerns are being raised about Google’s Privacy Sandbox, which critics claim is also not fully compliant with the consent requirement. In this article, we will discuss these two recent cases. Additionally, we will delve into future regulations regarding cookies and the subsequent consent requirements. We will conclude with some practical tips.3 October 2024
- Europe’s AI Act: a new role for the Dutch Data Protection Authority?"The genie is out of the bottle. We need to move forward on artificial intelligence development but we also need to be mindful of its very real dangers. I fear that AI may replace humans altogether." This quote from Stephen Hawking in 2017 is more relevant today than ever.7 February 2024
- Facebook is in trouble again …… And this time it’s not Max Schrems who’s behind it. On March 15, 2023, the Amsterdam District Court ruled that Facebook Ireland violated the law by unlawfully processing the personal data of Dutch Facebook users. The Schrems rulings had already made it clear that Facebook does not always comply with European privacy rules. With the March 15, 2023 ruling, another case was added. This time, however, it was not Max Schrems who sued Facebook, but a Dutch foundation: the Data Privacy Foundation.5 May 2023
- AP applies incremental penalty authority to the fullestIt is the first time in history that the Dutch Data Protection Authority (DPA) has identified six violations of the GDPR in only one decision. All violations relate to the use and security by the Tax Authorities of its application Fraud Signaling Facility (FSV). An application that included signals about established fraud and signals that could indicate an increased risk of fraud with taxes and benefits.12 July 2022
- Dutch GDPR class action against Oracle and Salesforce declared inadmissibleThe first major GDPR class action under the Dutch Act on Mass Damages Settlement in Class Actions (WAMCA) has been declared inadmissible before a substantive assessment could take place.18 March 2022
- Class actions against big tech in the NetherlandsBig tech is getting sued for billions. What are these claims based on and who is supporting them? A short article on the recent developments of Dutch class actions.5 November 2021
- Data breach reported to late? That’s a €475,000 fine!The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has imposed a €475,000 fine on Booking.com because the company took too long to report a data breach to the DPA.16 May 2021
- Schrems II recommendationsImportant recommendations EDPB (European Data Protection Board) after Schrems II and new standard contractual clauses27 November 2020
- The British Data Protection Authority ICO considers operating systems that are no longer supported inadequate security.If systems such as Windows 7 and Windows Server 2008 R2 SP1 are no longer supported by Microsoft, this may result in inadequate security, which could then be seen as an infringement of article 32 GDPR. Huge GDPR fines may be imposed because of this infringement.17 September 2020
- New Dutch class action legislation makes it possible to claim damages in a collective action to ensure enforcement of the GDPROn 1 January 2020, a new Act allowing representative entities to seek damages in a collective action came into effect in the Netherlands. This Act on redress of mass damages in a collective action (Wet afwikkeling massaschade in collectieve actie (WAMCA), under article article 3:305a Dutch Civil Code) introduces stricter requirements for filing a valid claim vehicle and for the scope of collective actions. It also introduces procedural changes to enhance the efficiency and effectiveness of the proceedings.27 August 2020
- Fine for Dutch tennis association for unlawfully selling personal dataThe Dutch DPA imposed a fine of 525,000 euros for the unlawful sale of personal data by the Dutch national tennis association the KNLTB. In 2018, the KNLTB unlawfully provided personal data of a few hundred thousand of its members to two sponsors against payment.17 March 2020
- € 150.000,- GDPR fine imposed on PWC by Greek Data Protection Authority for being not accountableThe Greek HDPA (Hellenic Data Protection Authority) imposed a fine of € 150.000,- on PWC Greece.6 August 2019
- Fine of € 460.000,- imposed on Dutch Haga Hospital by Dutch Data Protection Officer, the first Dutch fine under GDPR (July 19, 2019)This first fine under the GDPR is imposed on the Dutch Haga Hospital for having an insufficient internal security of patient records as stated by the DPA on July 19, 2019. The DPA started an investigation after it appeared that a large amount (about 200 employees) of hospital staff had unauthorized accessed the medical records of a Dutch celebrity. Personal was leaking medical information to the press as well.25 July 2019
- On 19 February 2019, the Dutch Data Protection Authority has come up with its own policy for determining the levels of administrative finesOn the basis of the guidelines of the article 29 working party of what now is the EDPB (European Data Protection Board) and the stipulations on imposing and setting administrative fines as laid down in the GDPR, the Dutch DPA has now formulated its own policy. This to achieve a consistent approach when administrative fines are imposed. The policy adequately reflects all of the principles listed in the EDPB guidelines, which are intended to come to a common understanding of the assessment criteria laid down in article 83 (2) of the GDPR.2 April 2019
- The Dutch Data Protection Authority (Dutch DPA) clarifies the concept “large scale” for the Data Protection Officer (DPO)Government agencies and public organisations have the obligation to appoint a DPA, regardless the type of data they process.17 December 2018
- Uber fined £385,000 in the UK and €600,000 in the NetherlandsUber US and Uber Netherlands were considered to be joint controllers which made them both separately liable for claims of customers of Uber. Uber was fined after a 'serious breach' allowing hackers to download worldwide 54 million customer data.30 November 2018
Join the network
Applications from qualified privacy practices are reviewed individually by the INPLP board.