Privacy

The GGD data leak once again proves the importance of good security

A major data leak in the GGD coronavirus systems, in which employees traded personal data such as BSNs and addresses, showed how important proper security of personal data is — and how strictly the Dutch Data Protection Authority (AP) monitors medical data....

Published on 15 February 2021 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

A major data breach in the GGD coronavirus systems, in which employees traded personal data such as BSNs and addresses, demonstrated how important proper security of personal data is — and how strictly the Dutch Data Protection Authority (AP) monitors medical data. Restricting access, logging and monitoring everything, and acting quickly and reporting after a data breach are not a luxury, but an obligation.

Investigations revealed that personal data from the GGD (Municipal Health Service) coronavirus systems had been leaked and traded; call center employees were suspected of offering that data. The case underscores that proper security of personal data is always necessary, as is acting quickly after a data breach.

Excessive access to sensitive data

The leaked data originated from two databases — CoronIT and HPzone Light — to which a large number of GGD employees and call center staff had access, including information about test appointments, test results, and source and contact tracing. Such data can be misused for identity fraud, stalking, and phishing.

Call center employees with low hourly wages and high work pressure constitute an attractive target for criminals who actively approach them. Moreover, much work was done from home, with less supervision, which made the transfer of data easier. Because medical data is involved — among the most sensitive personal data there is — the healthcare sector is already a favorite target anyway.

Security measures that may not have been sufficient

Measures had indeed been taken: employees were required to submit a Certificate of Conduct (VOG), sign a confidentiality agreement , and random checks were conducted. Following the media coverage, the GGD announced it would scale up controls and begin permanently monitoring the systems. A major sore point: data was easy to export, and there was no logging of who accessed which data.

The AP investigates and enforces strictly

The umbrella organization officially reported the data breach — rightly so, as organizations are required to report data breaches to the Dutch Data Protection Authority (AP). The AP demanded clarification. That the AP takes the security of medical data extremely seriously was already evident: the HagaZiekenhuis previously received a fine of €460,000 after multiple employees had unauthorizedly accessed Samantha de Jong's medical file, because the hospital did not adequately monitor log files and lacked two-factor authentication. Significantly: at the Haga, log files *did* exist, whereas in the case of the GGD leak, it was not even logged who accessed which data. You can read more about such fines here.

What does this mean for your organization?

If negligence is found, not only does a fine loom: injured parties can also file a claim for damages. The security of personal data must therefore be a top priority for every organization. Otherwise, public outrage, negative media attention, fines, and damage claims are lurking. Ensure that you comply with GDPR requirements .

Frequently Asked Questions

Do I need to report a data breach to the Dutch Data Protection Authority?

In principle, yes. Organizations are required to report data breaches to the Dutch Data Protection Authority (and to the data subjects in the case of serious risks). Acting quickly and correctly after a breach is essential.

What security does the AP expect regarding medical data?

High standards: restricting access to those who truly need it, logging and verifying access, and strong authentication such as two-factor authentication. The absence of these weighs heavily.

Can I be held liable for a data breach?

In the event of negligence, you risk both a fine from the AP and damage claims from injured parties. Good technical and organizational measures limit that risk.

Have your data security tested

A data breach can affect any organization, and the consequences are significant. The privacy experts at MKB Juristen help you comply with the GDPR and get your security in order. View our expertise in privacy and data protection or schedule a call.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

July 24, 2026

Checking contracts: step-by-step plan for SME entrepreneurs

Checking or reviewing a contract before signing: step-by-step plan, red flags, checklist, and when you need a lawyer.

July 24, 2026

Having general terms and conditions drafted for contractors: costs and process

Having general terms and conditions for contractors drafted by a lawyer: what does it cost, how does the process work, and when do you choose custom work over...

July 23, 2026

Having general terms and conditions drafted: costs and process

Having general terms and conditions drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom-made version over a template.

July 23, 2026

Drafting general terms and conditions: what belongs in them

Drafting General Terms and Conditions? Read which components should be included, common mistakes, and when to hire a lawyer.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation