Blog

A data leak is something you'd rather avoid

Data breach under the GDPR: notification obligation within 72 hours, register, informing customers, and fines. Step-by-step plan for SME limited liability companies.

Published on July 7, 2026 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

Data breach under the GDPR: unauthorized access, loss, or disclosure of personal data. Examples: hacked database, lost laptop containing customer data, incorrectly sent email. Notification obligation: within 72 hours to the Dutch Data Protection Authority (AP) in case of risk to data subjects. In case of high risk, data subjects must also be informed. Failure to report: fine of up to 2% of global turnover. Below: how to recognize a data breach, the reporting procedure, and how Tessa handles an incident without it getting out of hand.

The short answer

  • What: unauthorized access, loss, or disclosure of personal data.
  • AP reporting obligation: within 72 hours in case of risk to data subjects.
  • Inform stakeholders: mandatory in case of high risk.
  • Documentation: all data breaches in own register, including unreported ones.
  • Sanctions: AP fine of up to 2% of global turnover for failure to report.

What is a data breach?

Data breach detection and response

Under GDPR Art. 4, paragraph 12: a security breach that accidentally or unlawfully results in:

  • Destruction of personal data.
  • Loss.
  • Change.
  • Unauthorized provision.
  • Unauthorized access.

Examples:

  • Cyberattack/database hack.
  • Ransomware infection.
  • Lost or stolen laptop/USB with data.
  • Phishing email to which an employee responded.
  • Misaddressed email containing personal data.
  • Data sent to the wrong recipient.
  • Insider access without legitimate reason.

AP reporting obligation — 72 hours

72-hour data breach notification obligation

For every data breach involving a “risk to the rights and freedoms of data subjects”: report to the Dutch Data Protection Authority within 72 hours of discovery. Content of the report:

  1. Nature of data breach.
  2. Categories and number of people involved.
  3. Categories and amount of personal data.
  4. Possible consequences.
  5. Measures to limit the consequences.
  6. Contact point for more information.

In case of incomplete information: report as much as is known, supplement later. It is better to inform too early and partially than too late.

Inform those involved

In case of high risk to data subjects (e.g. financial damage, risk of identity theft, damage to reputation): also inform data subjects directly. Content:

  • Description of data breach.
  • Possible consequences for them.
  • Measures taken.
  • What they can do themselves (change password, warn financial institutions).

With a large number of affected people: a public announcement is often practical.

When NOT to report?

Failure to report is only permitted if:

  • “No risk to rights and freedoms” — e.g. pseudonym or encrypted data.
  • Encryption so strong that data is practically inaccessible.
  • Measures taken immediately, no actual result.

High threshold — when in doubt: report. You must be able to justify not reporting afterwards.

Documentation and register

Record all data breaches (including unreported ones) in the internal data breach register:

  • Date of discovery.
  • Description of the incident.
  • Data category.
  • Number of affected people.
  • Measures taken.
  • Risk assessment and notification decision.

The AP can request the register from the inspectorate. Mandatory for every company with customer data.

Sanctions

  • Failure to report under reporting obligation: fine of up to 2% of global turnover or €10 million.
  • Insufficient security: fine of up to 4% of global turnover or €20 million.
  • Civil liability: injured parties can claim compensation.
  • Reputational damage: often the biggest impact of major data breaches.

Cyber ​​insurance aspect

A good cyber insurance policy often covers data breach response, including legal guidance, communication, and potential fines. See cyber insurance.

Honest recommendation

GDPR lawyer oversees incident

For SME limited liability companies: draw up an incident response plan in advance — who does what in the event of a data breach. Maintain contact with a GDPR lawyer (€1,500-€5,000 for guidance). In the event of an incident: act quickly — the first 24 hours are crucial for damage mitigation and a proper notification to the Data Protection Authority. Maintain a data breach register, even for minor incidents. Combine with cyber insurance for financial and operational coverage.

For other topics: privacy statement, cyber insurance and UBO declaration.

Frequently Asked Questions

What is a data breach?

Security breach that accidentally or unlawfully leads to the destruction, loss, alteration, unauthorized disclosure, or unauthorized access to personal data. Examples: hack, lost laptop, erroneous email.

How quickly to report to the AP?

Within 72 hours of discovery — in case of risk to the rights and freedoms of the persons concerned. In case of incomplete information: report what is known, supplement later. Some too early and some too late.

When to inform stakeholders?

In case of high risk to those involved (financial damage, identity theft, reputation). Content: description, possible consequences, measures taken, what they can do themselves. In case of a large number: announce publicly.

When NOT to report?

Only if there is no risk to rights and freedoms — e.g. pseudonym or encrypted data without a key. High threshold — if in doubt: report. You must be able to justify failure to report afterwards.

What needs to be in the register?

All data breaches (including unreported ones): date of discovery, description, data category, number of affected parties, measures taken, risk assessment, and reporting decision. Mandatory for every company with customer data.

What are the sanctions?

Failure to report: fine of up to 2% of global turnover or €10 million. Insufficient security: up to 4% or €20 million. Plus civil liability for claims by involved parties and reputational damage.

How to prepare?

Develop an incident response plan in advance — who does what. GDPR legal expert on standby. Data breach register ready. Periodic employee training. Cyber ​​insurance for financial and operational coverage.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

July 24, 2026

Checking contracts: step-by-step plan for SME entrepreneurs

Checking or reviewing a contract before signing: step-by-step plan, red flags, checklist, and when you need a lawyer.

July 24, 2026

Having general terms and conditions drafted for contractors: costs and process

Having general terms and conditions for contractors drafted by a lawyer: what does it cost, how does the process work, and when do you choose custom work over...

July 23, 2026

Having general terms and conditions drafted: costs and process

Having general terms and conditions drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom-made version over a template.

July 23, 2026

Drafting general terms and conditions: what belongs in them

Drafting General Terms and Conditions? Read which components should be included, common mistakes, and when to hire a lawyer.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation