MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Did you know that the Dutch Data Protection Authority imposed fines totaling no less than €338.6 million in 2024? This is a huge increase compared to previous years and proves that the regulator is taking stricter action than ever. For many entrepreneurs, a security incident is a major source of stress. The moment personal data is exposed, you immediately need clear legal advice regarding a data breach to get the situation under control right away.
It is perfectly understandable that you dread the administrative burden or fear lasting reputational damage with your customers. The rules surrounding the GDPR are often complex, and the fear of a hefty fine is real when the definition of a breach is unclear. In this article, you will learn exactly how to recognize a data breach, when the strict 72-hour notification obligation comes into effect, and how to effectively limit legal damage to your business. We offer you a concrete action plan for compliance with the law, so that you maintain control and can continue doing business with peace of mind.
Key Points
- Discover why a data breach goes much further than just a hack and learn to recognize everyday incidents such as lost USB sticks in time.
- Obtain clarity regarding the strict 72-hour reporting obligation to the Dutch Data Protection Authority and the specific criteria for an official report.
- Understand the real legal risks, including administrative fines and civil damage claims, to proactively protect your business.
- Receive a practical step-by-step plan for immediate action in the event of an incident, so that you maintain control and immediately stop further dissemination of data.
- Learn how timely legal advice on a data breach helps you fully comply with privacy legislation and professionally streamline communication with regulators.
What is a data breach and why is expert legal advice necessary?
Many entrepreneurs immediately think of Russian hackers or complex ransomware attacks that cripple an entire company when it comes to a data breach. However, the reality is often much more mundane. An employee leaving a USB stick on the train or an invoice accidentally emailed to the wrong customer; these are situations that occur daily. To understand your obligations, the question of what exactly constitutes a data breach according to the law is essential. According to the General Data Protection Regulation (GDPR), a data breach occurs whenever there is a security breach that leads to the destruction, loss, alteration, or unauthorized disclosure of personal data.
Not every security incident automatically constitutes a data breach that you are required to report officially. A computer virus that encrypts files without accessing any data is a technical incident. However, as soon as there is a real possibility that customer data has been viewed or copied by unauthorized persons, the legal status changes immediately. This is where professional legal advice regarding data breaches into play. A lawyer helps you objectively determine whether the threshold for the reporting obligation has been exceeded. This prevents you from causing unnecessary panic among customers or, worse, failing to make a legitimate report.
The role of personal data in your business operations
Personal data is the fuel of almost every business. Whether it concerns a simple address list, your staff's social security numbers, or your customers' extensive purchase history, you likely process more sensitive data than you might think at first glance. The GDPR makes no distinction between large multinationals and local SMEs in this regard. Even the loss of a small amount of data can have major legal consequences if that information is traceable to individuals. It is therefore of great importance that you have insight into your data flows before something goes wrong. Do you know exactly who has access to your customer database and where this information is physically stored?
Legal aid versus technical support
When an incident is discovered, the first reaction is often to call the IT administrator. That is a good first step; the leak must be technically closed as quickly as possible. However, the entrepreneur's responsibility does not end there. While the IT specialist focuses on the bits and bytes, a legal expert focuses on limiting your liability and complying with the law. An independent legal assessment is necessary to determine whether you need to notify the Dutch Data Protection Authority (AP). Failure to report a reportable leak can result in fines that seriously impact your profitability. By obtaining timely legal advice on data leaks , you build a case file that demonstrates you take your responsibility as a data processor seriously. This form of legal assistance offers the necessary peace of mind in a hectic situation.
The data breach notification obligation: when must you notify the Dutch Data Protection Authority?
When you discover a security incident, the clock starts ticking immediately. The notorious 72-hour deadline is a source of great stress for many entrepreneurs. Within these three days, you must not only determine what has happened but also decide whether to file an official report with the Dutch Data Protection Authority (AP). Obtaining legal advice regarding data breaches helps you make the right choices during this short time. Speed is essential, but a hasty report without the proper context can raise unnecessary questions from the regulator.
Incidentally, you are not obliged to report every incident. The law states that a report is only necessary when the leak is likely to pose a risk to the rights and freedoms of the data subjects. Examples include risks of identity fraud, financial damage, or reputational loss for your customers. Furthermore, if the risk is assessed as 'high', you are required to inform the affected parties directly. Determining this risk level is a matter of specific legal assessment; what is a minor incident for one organization may be a reportable leak for another.
Even if you decide not to report after a thorough analysis, you are not out of the woods yet. The GDPR requires every organization to maintain an internal data breach register. In this register, you log every incident, including the facts, the consequences, and the reason why you decided not to report to the Dutch Data Protection Authority (AP). This register serves as your evidence in the event of an audit. Do you want to be certain that your internal procedures comply with the law? Our experts offer practical legal assistance in setting up your privacy policy.
Determining the severity of the leak
The severity of an incident depends on the nature of the data. Does it involve medical data, national identification numbers, or passwords? Then the risk is quickly high. A crucial factor is encryption. If the lost data was encrypted using modern technology and the key has not fallen into the hands of unauthorized persons, you often do not need to report the leak. A practical step-by-step plan for a data breach helps you systematically weigh these technical and legal factors.
Communication with your customers and business relations
Transparency is often the best strategy to maintain your customers' trust. In an official notification to data subjects, you must clearly explain what happened, which data was leaked, and what measures they can take themselves. An honest approach often prevents greater reputational damage later on. For broader context regarding your general obligations, you can consult our guide on GDPR compliance for SMEs . This ensures that you comply with the rules not only in the event of incidents, but on a structural basis.

Risks and consequences of improper handling of data breaches
When a data breach is not handled according to the rules, the financial risks are substantial. Many entrepreneurs hear stories about multi-million euro fines and believe that this will not affect their business. However, the figures tell a different story. In 2024, the Dutch Data Protection Authority issued fines totaling no less than €338.6 million, a gigantic increase compared to the previous year. Although the highest amounts are often imposed on large organizations, SMEs are also increasingly facing stricter enforcement. The lack of expert legal advice regarding a data breach at the critical moment can lead to fines that could have been avoided through timely and correct reporting.
In addition to the regulator, you also have to deal with the affected parties themselves. Customers or employees can claim compensation through the civil courts if their privacy has been violated. This concerns not only direct financial damage, but increasingly also non-material damages. Moreover, your insurance company may decide not to pay out on claims. This occurs when it becomes apparent that you have shown gross negligence, for example due to the lack of basic security or an up-to-date incident protocol. Incorrect handling thus directly jeopardizes the continuity of your business.
Reputational damage is perhaps the most difficult consequence to repair. In a market where trust is the foundation of every business relationship, news of careless data handling can lead to contract termination. Nowadays, clients place high demands on their suppliers' privacy safeguards. If you cannot demonstrate that you respond adequately to incidents, you will quickly miss out on new tenders. By having your affairs in order beforehand, you significantly limit these risks. See how we can support you with expert legal assistance to strengthen your legal position.
Enforcement in practice for SMEs
In the event of an incident, the Dutch Data Protection Authority scrutinizes your efforts. There is a fundamental difference between human error, such as a letter being sent incorrectly, and culpable negligence where security updates have been ignored for months. The regulator expects you to have taken 'appropriate technical and organizational measures'. A sound data breach protocol within your legal advice data breach process not only reduces the risk of errors but also serves as proof of your good faith, which can significantly mitigate any potential fine.
Contractual consequences of collaborations
Data breaches can have far-reaching consequences for your ongoing collaborations. Many business contracts contain clauses giving the client the right to terminate the agreement immediately in the event of a serious privacy incident. In addition, there is the issue of liability within the chain. If a sub-processor you have engaged causes a leak, in many cases you remain the primary point of contact for the damages. It is therefore crucial to make watertight agreements. Read more about drafting a data processing agreement to effectively mitigate these risks with your partners.
A practical step-by-step plan for entrepreneurs in the event of a (suspected) data breach
As soon as you suspect that something is wrong with the security of your personal data, a structured approach is your best defense. Panic often leads to hasty decisions that can legally worsen the situation. By following the step-by-step plan below, you remain in control and comply with your legal duty of care.
- Step 1: Detection and isolation. The first goal is to stop the breach. Disconnect infected systems from the network or immediately block access for unauthorized users. Prevent further dissemination of data without destroying evidence that may be needed for investigation later.
- Step 2: Analysis and classification. Determine exactly which data is involved. Is it a technical incident or a data breach? This is the time to immediately legal advice regarding the data breach . A lawyer will objectively assess whether a reporting obligation applies based on the nature and extent of the leaked data.
- Step 3: Notification and communication. If there is a notification obligation, you must inform the Dutch Data Protection Authority within 72 hours of discovery. If the risk to data subjects is high, you must notify them immediately with a clear explanation and advice on the measures to be taken.
- Step 4: Evaluation and prevention. After the incident, you must determine where things went wrong. Was it human error or a technical failure by a supplier? Adjust your internal processes and check whether your contracts with partners still offer sufficient protection.
- Step 5: Documentation. Record the entire process in your internal data breach register. Even if you decided not to report, the justification for this must be in your records for future audits.
Legal checks on your foundation
A data breach is often a painful reminder of gaps in your contracts. Many entrepreneurs rely on external IT suppliers for their data but have not properly arranged for liability in the event of incidents. With our ContractCheck™ , we take a critical look at your existing agreements. We check whether you can shift risks to the party responsible and whether your general terms and conditions contain sufficient privacy clauses. An up-to-date register of processing activities is indispensable in this regard; it forms the legal foundation you can fall back on in the event of an incident.
Setting up an internal data breach protocol
When push comes to shove, there should be no ambiguity about who does what. An effective internal protocol designates a responsible person to take charge of incidents. It is advisable to include a lawyer as a permanent point of contact in this protocol, so that you can immediately seek legal advice regarding a data breach. Do not forget the human factor, either. By regularly training your staff to recognize phishing and handle customer data securely, you significantly reduce the risk of human error. Is your contractual protection not yet in order? Have your contracts professionally drafted or reviewed via our contract service.
How the legal experts at MKB Juristen support you with privacy incidents
A security incident is always inconvenient and often brings with it a great deal of uncertainty. At MKB Juristen, we understand that at such times you need immediate and down-to-earth legal advice regarding data breaches. We act as your external legal department standing by your side; not with complicated jargon, but with practical solutions that fit the daily reality of your business. Our approach is aimed at restoring calm within your organization, while simultaneously minimizing your legal risks.
We support you throughout the entire incident process. This begins with the crucial question of whether an incident actually constitutes a reportable data breach. Should a notification to the Dutch Data Protection Authority (AP) be necessary, our legal experts will assist you in carefully formulating this notification. A well-substantiated notification can make the difference in how the regulator views your organization. Additionally, we advise you on communication with your customers or employees, ensuring you are transparent without creating unnecessary legal vulnerabilities.
Our services do not stop at putting out fires. We also assist you in drafting necessary customized documentation. This includes a watertight data breach protocol and an up-to-date privacy statement that meets the latest requirements. By proactively screening your contracts, we ensure that your agreements with IT suppliers and other partners optimally protect your interests in the event of future incidents.
Immediate legal assistance for incidents
When the clock strikes 72, there is no time for long waiting times. We act quickly to assist you within the statutory deadlines. Our legal experts also provide support when you are held liable by third parties for damages resulting from a leak. We assess the claim, verify your contractual position, and conduct the defense on your behalf. For urgent support, you can immediately make use of our legal assistance for entrepreneurs.
Building a privacy-proof future
The digital world is changing rapidly; therefore, a one-off check of your privacy policy is never sufficient. We believe in a structural approach where your legal foundation grows with your business. For start-up entrepreneurs or companies looking to strengthen their foundation, our legal starter package an excellent way to immediately comply with all obligations. Do you currently have doubts about a situation within your company? Feel free to contact us without obligation for an initial assessment; we are happy to help you get back on track with clear legal advice regarding data breaches.
Protect your business against the consequences of a data breach
A security incident is a stressful moment for any entrepreneur, but it does not have to mean the end of your good reputation. By remaining vigilant regarding the 72-hour notification obligation and accurately maintaining your internal data breach register, you meet the key requirements of the GDPR. It is essential not only to take technical action but also to strengthen your contractual basis. As we saw earlier, good preparation with the right privacy clauses helps keep eventual damages and liability manageable.
The moment you are faced with an incident, adequate legal advice regarding a data breach the key to limiting fines and unnecessary claims. Since 2009, MKB Juristen has been the trusted partner for entrepreneurs seeking legal certainty. Our specialists in privacy law offer pragmatic solutions without complex jargon, so you know exactly where you stand and what steps to take.
Do not wait until an incident gets out of hand. Contact MKB Juristen immediately for advice regarding a data breach and ensure a solid legal foundation for your business operations. We stand by your side to tackle this challenge in a pragmatic manner.
Frequently asked questions about data breaches and legal obligations
Is legal advice mandatory for small business owners in the event of a data breach?
Legal advice is not legally required, but it is strongly recommended to avoid fines and reputational damage. An expert helps you objectively determine whether an incident is reportable under the GDPR. This prevents you from causing unnecessary panic among customers or overlooking a mandatory notification to the supervisory authority, which can have major financial consequences.
What should I do if I accidentally sent an email to the wrong person?
Legally speaking, this constitutes a data breach as soon as the recipient is unauthorized to view the personal data contained in the email. Ask the recipient to immediately delete the email and confirm this in writing. You must always record this incident in your internal data breach register. Whether you also need to report it to the Dutch Data Protection Authority depends on the sensitivity of the enclosed information.
How high are the fines for failing to report a data breach in the SME sector?
Fines can amount to €20 million or 4% of global annual turnover. In 2024, the Dutch Data Protection Authority issued fines totaling no less than €338.6 million, demonstrating that enforcement has become stricter. Although SME entrepreneurs receive the maximum fine less frequently, the amounts are still high enough to immediately jeopardize the continuity of a small business.
Do I also have to report a data breach if all data was encrypted?
In most cases, you do not need to report a breach if the data is unreadable to unauthorized persons due to strong encryption. This only applies if the encryption key itself has not been stolen or compromised. In case of doubt, it is advisable to seek specific legal advice regarding data breaches to legally assess the effectiveness of your security and avoid unnecessary risks with the regulator.
When is a data breach serious enough to inform customers?
You must inform customers when a data breach is likely to pose a high risk to their rights and freedoms. Consider situations where sensitive data such as social security numbers, passwords, or financial data have been exposed. The goal is to enable affected parties to take measures themselves, such as changing their login credentials or being extra vigilant against phishing attempts and identity fraud.
Who is liable if my IT supplier causes a data breach?
As the data controller, you remain the primary legal point of contact for the supervisory authority and your customers, even if the fault lies with your IT supplier. You are responsible for reporting to the Dutch Data Protection Authority. However, you can often recover the damages suffered from the supplier. This depends entirely on the agreements you have laid down in the data processing agreement or your general terms and conditions.
How long do I have to officially report a data breach?
You have a maximum of 72 hours to report a data breach after becoming aware of it. This timeframe is strict and applies during weekends and public holidays as well. If you report later, you must provide a very good reason for the delay. It is therefore crucial to act immediately upon suspicion and not wait for the full technical investigation.
Can I add new information to a data breach notification later?
Yes, you can supplement a report later if new facts come to light during your investigation. In the initial report, you indicate that it is a preliminary report. This is common practice, as you often cannot yet assess all the details of the breach or the full impact on the data within the first 72 hours. With timely legal advice on data breaches, you structure these follow-up steps professionally.