Privacy

This is what you need to know about the major data breach at car companies

Personal data of millions of Dutch people may have been stolen from a company that offers ICT services to car garages. There are reportedly 7.3 million stolen data points, although there is still uncertainty about this. Among the stolen data are...

Published on April 1, 2021 by MKBjuristen.nl
Schedule a free intake. Call 085 25000 44

Personal data of millions of Dutch citizens may have been stolen from a company that offers IT services to car garages. There are reportedly 7.3 million stolen data points, although the exact number remains unclear. The stolen data includes name and address details, license plates, telephone numbers, dates of birth, and email addresses. Based on this information, criminals could, for example, see who owns expensive cars and where these people live, but identity fraud, WhatsApp fraud, and spoofing are also lurking around the corner. It is believed to be one of the largest Dutch data breaches ever.

Data processor files notification immediately

The leak originated at the IT company RDC. This company offers garages the option to automatically email customers when it is time for their vehicle inspection. It is not yet clear how the data was stolen, but according to RDC, there was no hack involved. It was the NOS that uncovered the data leak after the data was offered for $35,000 on a hacker forum. After the NOS informed the company, it immediately filed a report with the Dutch Data Protection Authority. Such a formal notification is mandatory in the event of a data leak, even when the information is already publicly known through the press.

In the meantime, it appears that RDC is taking the leak seriously. For instance, it has brought in Fox-IT, a network security expert, to investigate how the data was leaked. Additionally, it is tasked with helping to prevent future leaks.

Affected car companies must take action themselves

All affected car companies have been notified. They are also required to report to the Dutch Data Protection Authority. A collective notification is not permitted. Furthermore, RDC is not allowed to notify affected consumers itself. This is because the car company is the data controller and has a contractual relationship with the consumer. In this context, RDC is a third party authorized to process this data for the car company via a data processing agreement , but with respect to the consumer, the responsibility lies with the car companies.

Car companies would indeed be wise to inform their customers. The Dutch Data Protection Authority has previously indicated that when a breach poses a high risk, the controller must notify the data subjects without delay. Whether or not a high risk exists is a matter of fact. This takes into account, among other things, the number of affected individuals, the ease with which individuals can be identified, the severity of the consequences, and the scope and sensitivity of the leaked personal data. In this specific situation, it is indeed advisable to formally notify customers of the data breach. RDC has reportedly already prepared a message for the car companies in their digital environment. Naturally, controllers may also use a different message.

Responsibility for data breaches

Although the investigation is still in full swing, there is something we can already question. For instance, data regarding cars that visited a garage more than ten years ago has reportedly been leaked. This is despite the fact that the data was collected in late 2018 and early 2019. Nevertheless, with the arrival of the GDPR has become even more important to delete personal data in a timely manner. If it ultimately turns out that mistakes were made, which is not yet clear, the Data Protection Authority can intervene and impose fines.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

We help entrepreneurs with contracts, conflicts, and specialized legal questions. During a free intake, we briefly discuss which approach suits your situation.

contracts Drafting, reviewing, and amending
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

June 3, 2026

Mobile phones in the workplace: what is reasonable?

Facebook, WhatsApp, or games like Pokémon Go: distractions at work are only getting bigger. And that is often where mobile phones...

June 3, 2026

Hiring a collection agency: here's how to do it in 5 steps

Hiring a collection agency because a customer isn't paying? Read the step-by-step plan for when it's smart, what it costs, and what you need to do first...

June 3, 2026

Drafting a shareholders' agreement: step-by-step plan and pitfalls

Drafting a shareholders' agreement for your BV? Read the step-by-step plan, which clauses are crucial, and why hiring a lawyer is usually the smartest investment.

June 3, 2026

GDPR compliance for SMEs: a practical guide for entrepreneurs in 2026

Did you know that the number of data breach notifications in Europe has increased by no less than 22% in 2025 to an average of 443 notifications per day?...

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation