MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
A major data breach in the GGD coronavirus systems, in which employees traded personal data such as BSNs and addresses, demonstrated how important proper security of personal data is — and how strictly the Dutch Data Protection Authority (AP) monitors medical data. Restricting access, logging and monitoring everything, and acting quickly and reporting after a data breach are not a luxury, but an obligation.
Investigations revealed that personal data from the GGD (Municipal Health Service) coronavirus systems had been leaked and traded; call center employees were suspected of offering that data. The case underscores that proper security of personal data is always necessary, as is acting quickly after a data breach.
Excessive access to sensitive data
The leaked data originated from two databases — CoronIT and HPzone Light — to which a large number of GGD employees and call center staff had access, including information about test appointments, test results, and source and contact tracing. Such data can be misused for identity fraud, stalking, and phishing.
Call center employees with low hourly wages and high work pressure constitute an attractive target for criminals who actively approach them. Moreover, much work was done from home, with less supervision, which made the transfer of data easier. Because medical data is involved — among the most sensitive personal data there is — the healthcare sector is already a favorite target anyway.
Security measures that may not have been sufficient
Measures had indeed been taken: employees were required to submit a Certificate of Conduct (VOG), sign a confidentiality agreement , and random checks were conducted. Following the media coverage, the GGD announced it would scale up controls and begin permanently monitoring the systems. A major sore point: data was easy to export, and there was no logging of who accessed which data.
The AP investigates and enforces strictly
The umbrella organization officially reported the data breach — rightly so, as organizations are required to report data breaches to the Dutch Data Protection Authority (AP). The AP demanded clarification. That the AP takes the security of medical data extremely seriously was already evident: the HagaZiekenhuis previously received a fine of €460,000 after multiple employees had unauthorizedly accessed Samantha de Jong's medical file, because the hospital did not adequately monitor log files and lacked two-factor authentication. Significantly: at the Haga, log files *did* exist, whereas in the case of the GGD leak, it was not even logged who accessed which data. You can read more about such fines here.
What does this mean for your organization?
If negligence is found, not only does a fine loom: injured parties can also file a claim for damages. The security of personal data must therefore be a top priority for every organization. Otherwise, public outrage, negative media attention, fines, and damage claims are lurking. Ensure that you comply with GDPR requirements .
Frequently Asked Questions
Do I need to report a data breach to the Dutch Data Protection Authority?
In principle, yes. Organizations are required to report data breaches to the Dutch Data Protection Authority (and to the data subjects in the case of serious risks). Acting quickly and correctly after a breach is essential.
What security does the AP expect regarding medical data?
High standards: restricting access to those who truly need it, logging and verifying access, and strong authentication such as two-factor authentication. The absence of these weighs heavily.
Can I be held liable for a data breach?
In the event of negligence, you risk both a fine from the AP and damage claims from injured parties. Good technical and organizational measures limit that risk.
Have your data security tested
A data breach can affect any organization, and the consequences are significant. The privacy experts at MKB Juristen help you comply with the GDPR and get your security in order. View our expertise in privacy and data protection or schedule a call.