MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
The Dutch Data Protection Authority has made the data breach notification form more user-friendly — including intermediate saving and follow-up questions based on previous answers — but correctly reporting a data breach remains complex. You must assess whether a report is required, whether you also need to inform the data subjects, and record the breach in your data breach register.
The AP has modified the data breach notification form to make reporting easier. Welcome, but technical and legal assistance remains important: a report must be submitted correctly.
The obligation to report data breaches
In the event of a serious data breach, you must report it immediately to the AP. This concerns not only the unintentional release of personal data, but also unauthorized modification, access, or destruction thereof. In addition, other obligations apply: limiting the damage, sometimes informing the data subjects, and recording the data breach in the mandatory data breach register — even if it does not need to be reported to the AP.
Proper handling is crucial, otherwise fines threaten. For example, Booking.com received a fine of 475,000 euros for a data breach reported too late.
Substantive changes to the reporting form
- Not only when, but also how the infringement was discovered.
- More selection options regarding the nature of the incident that preceded the data breach.
- The notifier must now explain their risk assessment; merely making an assessment is no longer sufficient.
- You can enter the FG registration number and describe the encryption/hashing if data has been rendered unintelligible or inaccessible.
Improved usability
Follow-up questions are now asked based on previous answers, so that you do not have to answer irrelevant questions. The form can be saved midway and resumed later (this does not replace the pro forma notification: a saved session is not sent to the DPA but is stored locally). Bulk notifications — in the event of a data breach that recurs in quick succession — have also become simpler.
However, downsides remain: it is not indicated which information is required to proceed, and the explanation fields offer little space.
Frequently Asked Questions
Do I have to report every data breach to the DPA?
Not every data breach, but data breaches posing a risk to data subjects, in principle within 72 hours. You must also record data breaches that are not subject to mandatory reporting in your data breach register.
When do I also need to inform those involved?
In the event of a data breach posing a high risk to the data subjects, you must inform them without delay, in addition to reporting it to the Dutch Data Protection Authority (AP).
What is the data breach register?
A mandatory internal register in which you record all data breaches, including those not reported to the AP. It enables the AP to verify compliance.
Help with reporting a data breach
The decision of whether and how to report remains difficult. The privacy experts at MKB Juristen make that assessment with you and guide you through the reporting process. View our expertise in privacy and data protection or contact us.