MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Data breach under the GDPR: unauthorized access, loss, or disclosure of personal data. Examples: hacked database, lost laptop containing customer data, incorrectly sent email. Notification obligation: within 72 hours to the Dutch Data Protection Authority (AP) in case of risk to data subjects. In case of high risk, data subjects must also be informed. Failure to report: fine of up to 2% of global turnover. Below: how to recognize a data breach, the reporting procedure, and how Tessa handles an incident without it getting out of hand.
The short answer
- What: unauthorized access, loss, or disclosure of personal data.
- AP reporting obligation: within 72 hours in case of risk to data subjects.
- Inform stakeholders: mandatory in case of high risk.
- Documentation: all data breaches in own register, including unreported ones.
- Sanctions: AP fine of up to 2% of global turnover for failure to report.
What is a data breach?
Under GDPR Art. 4, paragraph 12: a security breach that accidentally or unlawfully results in:
- Destruction of personal data.
- Loss.
- Change.
- Unauthorized provision.
- Unauthorized access.
Examples:
- Cyberattack/database hack.
- Ransomware infection.
- Lost or stolen laptop/USB with data.
- Phishing email to which an employee responded.
- Misaddressed email containing personal data.
- Data sent to the wrong recipient.
- Insider access without legitimate reason.
AP reporting obligation — 72 hours
For every data breach involving a “risk to the rights and freedoms of data subjects”: report to the Dutch Data Protection Authority within 72 hours of discovery. Content of the report:
- Nature of data breach.
- Categories and number of people involved.
- Categories and amount of personal data.
- Possible consequences.
- Measures to limit the consequences.
- Contact point for more information.
In case of incomplete information: report as much as is known, supplement later. It is better to inform too early and partially than too late.
Inform those involved
In case of high risk to data subjects (e.g. financial damage, risk of identity theft, damage to reputation): also inform data subjects directly. Content:
- Description of data breach.
- Possible consequences for them.
- Measures taken.
- What they can do themselves (change password, warn financial institutions).
With a large number of affected people: a public announcement is often practical.
When NOT to report?
Failure to report is only permitted if:
- “No risk to rights and freedoms” — e.g. pseudonym or encrypted data.
- Encryption so strong that data is practically inaccessible.
- Measures taken immediately, no actual result.
High threshold — when in doubt: report. You must be able to justify not reporting afterwards.
Documentation and register
Record all data breaches (including unreported ones) in the internal data breach register:
- Date of discovery.
- Description of the incident.
- Data category.
- Number of affected people.
- Measures taken.
- Risk assessment and notification decision.
The AP can request the register from the inspectorate. Mandatory for every company with customer data.
Sanctions
- Failure to report under reporting obligation: fine of up to 2% of global turnover or €10 million.
- Insufficient security: fine of up to 4% of global turnover or €20 million.
- Civil liability: injured parties can claim compensation.
- Reputational damage: often the biggest impact of major data breaches.
Cyber insurance aspect
A good cyber insurance policy often covers data breach response, including legal guidance, communication, and potential fines. See cyber insurance.
Honest recommendation
For SME limited liability companies: draw up an incident response plan in advance — who does what in the event of a data breach. Maintain contact with a GDPR lawyer (€1,500-€5,000 for guidance). In the event of an incident: act quickly — the first 24 hours are crucial for damage mitigation and a proper notification to the Data Protection Authority. Maintain a data breach register, even for minor incidents. Combine with cyber insurance for financial and operational coverage.
For other topics: privacy statement, cyber insurance and UBO declaration.
Frequently Asked Questions
Security breach that accidentally or unlawfully leads to the destruction, loss, alteration, unauthorized disclosure, or unauthorized access to personal data. Examples: hack, lost laptop, erroneous email.
Within 72 hours of discovery — in case of risk to the rights and freedoms of the persons concerned. In case of incomplete information: report what is known, supplement later. Some too early and some too late.
In case of high risk to those involved (financial damage, identity theft, reputation). Content: description, possible consequences, measures taken, what they can do themselves. In case of a large number: announce publicly.
Only if there is no risk to rights and freedoms — e.g. pseudonym or encrypted data without a key. High threshold — if in doubt: report. You must be able to justify failure to report afterwards.
All data breaches (including unreported ones): date of discovery, description, data category, number of affected parties, measures taken, risk assessment, and reporting decision. Mandatory for every company with customer data.
Failure to report: fine of up to 2% of global turnover or €10 million. Insufficient security: up to 4% or €20 million. Plus civil liability for claims by involved parties and reputational damage.
Develop an incident response plan in advance — who does what. GDPR legal expert on standby. Data breach register ready. Periodic employee training. Cyber insurance for financial and operational coverage.