MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Personal data of millions of Dutch citizens may have been stolen from an IT service provider for car garages — one of the largest Dutch data breaches ever. The lesson for entrepreneurs: as a data controller, you are personally responsible for informing your customers and reporting the breach to the Dutch Data Protection Authority, and you must not retain personal data longer than necessary.
The leak reportedly involves 7.3 million data points, including name and address details, license plates, phone numbers, dates of birth, and email addresses. Criminals can use this to see who owns expensive cars and where they live; identity fraud, WhatsApp fraud, and spoofing are also lurking.
What happened?
The leak originated at IT company RDC, which helps garages automatically email customers when their vehicle inspection is approaching. How the data was obtained is unclear; according to RDC, there was no hack. The NOS discovered the leak after the data was offered for $35,000 on a hacker forum. Following the report by the NOS, RDC immediately filed a report with the Dutch Data Protection Authority — mandatory for a data breach, even if it is already known through the press. RDC engaged security expert Fox-IT to determine the cause and prevent future leaks.
Affected car companies must take action themselves
All affected car companies have been informed and must also report to the AP themselves — a collective report is not possible. Important: RDC may not inform the affected consumers itself. This is because the car company is the data controller with the customer relationship, whereas RDC only processes the data for the car company via a data processing agreement . The responsibility towards the consumer therefore lies with the car companies.
Car companies would do well to inform their customers. The Dutch Data Protection Authority (AP) has previously indicated that in the event of a high-risk data breach, the controller must inform the data subjects without delay. Whether there is a high risk is a matter of fact: the number of affected individuals, the ease with which they can be identified, the severity of the consequences, and the volume and sensitivity of the data all play a role. In this case, formal notification is recommended.
Do not store data longer than necessary
Remarkably, data has even reportedly been leaked regarding cars that were at a garage more than ten years ago, even though the data was collected in late 2018 / early 2019. Particularly with the GDPR , it has become more important to delete personal data in a timely manner. If a mistake is found, the Dutch Data Protection Authority (AP) can intervene and impose fines.
Frequently Asked Questions
Who must inform customers in the event of a data breach via a supplier?
The controller with the customer relationship — often the company itself, not the ICT supplier (the processor). The latter is usually not allowed to contact the data subjects directly.
Do I always have to report a data breach?
In principle, a data breach must be reported to the Dutch Data Protection Authority (AP), even if it has already appeared in the press. In the event of a high risk, the affected parties must also be informed without delay.
How long am I allowed to retain customer data?
No longer than necessary for the purpose. Retaining personal data for an unnecessarily long period increases the risk in the event of a breach and may be in violation of the GDPR.
Are your privacy and data breaches in order?
The privacy experts at MKB Juristen assist you with data processing agreements, retention periods, and the appropriate response to a data breach. View our expertise in privacy and data protection or schedule a free intake consultation .