MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Mishandling personal data can cost you dearly. Since the GDPR, strict rules apply to anyone who processes personal data — even offline. Five common mistakes lead to complaints, data breaches, and fines.
1. No valid basis
Processing personal data without a legal basis (Article 6 GDPR) is not permitted. Emailing customers for marketing without consent, or using data for a purpose other than that for which you obtained it, constitutes an immediate violation.
2. Insufficient security
Poorly secured data leads to data breaches. An unsecured file, a stolen laptop, or excessive access within the company can expose personal data, resulting in a reporting obligation and potential fines.
3. Storing for too long or too much
The GDPR requires data minimization and retention periods: collect no more than necessary and retain no longer than necessary. A customer database that is stored indefinitely or fields that you never use pose a risk.
4. No privacy statement or information
You must inform data subjects about what you do with their data. If a clear privacy statement is missing, you fail to comply with the duty to inform and your position is weak in the event of a complaint.
5. Sharing or reselling data without justification
Sharing or reselling personal data to third parties without a legal basis and without a data processing agreement is a common, risky mistake. Even offline—a notepad with names and numbers—falls under the GDPR.
Frequently Asked Questions
Does the GDPR also apply offline?
Yes. A paper file or notebook containing personal data also falls under the GDPR.
What is the most common mistake?
Processing without a legal basis and insufficient security. Both quickly lead to complaints or data breaches.
What am I risking?
Complaints to the Dutch Data Protection Authority, data breaches, and hefty fines, in addition to reputational damage.
Is your data processing in order?
Our legal experts conduct a privacy scan and draft your privacy statement . View our privacyteam or schedule a free consultation.