MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
A data breach can cost you dearly. You are obliged to adequately secure personal data, and if things do go wrong, a reporting obligation applies: you must report serious data breaches to the Dutch Data Protection Authority within 72 hours and, if necessary, to the data subjects. Those who fail to do so properly risk heavy fines.
The security obligation
The GDPR requires you to protect personal data with appropriate technical and organizational measures (Article 32 GDPR). If a hacker still manages to obtain data, you are not always at fault — provided your security was in order. However, you still have a reporting obligation.
The data breach notification obligation
In the event of a data breach posing a risk to data subjects, you must report it to the Dutch Data Protection Authority within 72 hours (Article 33 GDPR). If the risk is high, you must also inform the data subjects themselves (Article 34 GDPR). In addition, maintain an internal record of all data breaches.
High penalties for violation
If you fail to perform properly — insufficient security or a vulnerability that was not reported (in a timely manner) — the regulator can take severe enforcement action. Fines can amount to a substantial sum or a percentage of annual turnover. Strict enforcement also takes place in other EU countries, as the rules apply throughout the European Union.
Prevent and be prepared
Ensure good security, a data processing agreement with your suppliers, and a data breach protocol so that you act quickly and correctly in the event of an incident. Good preparation limits damage and the risk of fines.
Frequently Asked Questions
Do I have to report every data breach?
You must report a data breach posing a risk to data subjects to the Dutch Data Protection Authority within 72 hours; in case of high risk, also report it to the data subjects. Keep a record of all breaches internally.
Am I liable if a hacker strikes?
Not automatically, provided your security was in order. However, the reporting obligation always applies, and insufficient security can indeed lead to sanctions.
What risks do I run with an unreported leak?
High fines from the Dutch Data Protection Authority, in addition to reputational damage.
Is your data security in order?
Our legal experts draft your data processing agreement and conduct a privacy scan. View our privacyteam or schedule a free consultation.