Articles about Privacy
Practical legal information for entrepreneurs. Read what to look out for, which steps are sensible, and when legal advice is necessary.
5 documents to make your organization GDPR-compliant
Privacy
7 December 2023
To be GDPR-compliant, virtually every organization needs a number of documents: a data processing agreement, a privacy and cookie statement, privacy regulations, a data breach protocol, and a consent form for visual material. These documents show...
Right to compensation after a data breach
Privacy
November 23, 2023
Victims of a data breach are entitled to compensation — not only from the hacker, but often also from the negligent organization that failed to adequately protect the data. The amounts are typically...
Lease cars and GDPR: a guide to more data privacy
Privacy
July 10, 2023
Modern lease cars store personal data — such as call, navigation, and app data — that falls under the GDPR. Especially when returning or transferring a lease car, it is crucial that...
Five years of GDPR: a look back at fines and compliance
Privacy
July 3, 2023
Five years after the introduction of the GDPR (May 25, 2018), it is clear: the Netherlands issues relatively few fines, but when one is imposed, it is substantial — and the...
Everything you need to know about the sub-processor agreement
Blog
May 30, 2023
A sub-processor agreement is the GDPR-mandated agreement between a processor and a third party engaged by the processor (the sub-processor), stating how the latter may process the personal data. For example, if your processor engages a...
Privacy requirements when using cloud services
Privacy
March 9, 2023
Storing personal data in the cloud is permitted, but as an organization, you remain responsible for its secure storage — even if you outsource it to a cloud service. That means: bring...
GDPR fines in 2022: the heaviest fines of last year
Privacy
February 13, 2023
In 2022, the Dutch Data Protection Authority (AP) also handed out substantial GDPR fines, the heaviest being the fine of 3.7 million euros for the Tax and Customs Administration due to the illegal “blacklist” FSV. The...
Detailed explanation of the DPIA or the GEB
Privacy
January 31, 2023
A DPIA (Data Protection Impact Assessment), also known as GEB, is a mandatory risk assessment that you carry out in advance when data processing is likely to pose a high privacy risk. With a DPIA, you bring...
Know the client and focus on an appropriate CDD policy
Privacy
January 17, 2023
Customer Due Diligence (CDD) is the client investigation used to determine who you are doing business with and what integrity risks are associated with it. A good CDD policy helps you comply with the rules against...
6 examples of damages under the GDPR
Privacy
December 22, 2022
In the event of a breach of the GDPR, an aggrieved party can not only count on enforcement by the Dutch Data Protection Authority, but also claim damages themselves (Article 82 GDPR) — including for non-material...