Specialized legal assistance for entrepreneurs, organizations, and directors.
View all areas of expertiseLegal assistance with conflicts, claims, negotiations, and proceedings.
View legal assistanceLegal assistance with outstanding invoices, disputed claims, and collection proceedings.
View collectionMeet MKB Juristen, our founders, and the way we organize legal assistance for entrepreneurs.
About SME LawyersPrivacy and data protection law dictates how you handle personal data — from legal bases and processor agreements to data breaches and enforcement by the Dutch Data Protection Authority. Our lawyers and in-house counsel assist both international corporations and the local entrepreneur: practical and legally sharp.
Privacy and data protection law dictates how you handle personal data — from legal bases and processor agreements to data breaches and enforcement by the Dutch Data Protection Authority. Our lawyers and in-house counsel assist both international corporations and the local entrepreneur: practical and legally sharp.
Are you sure that the cookies on your website comply with the law? Our lawyers and (corporate) legal experts map out all your cookies and ensure a comprehensive cookie banner and cookie statement – for corporations and small business owners.
View pageIn the event of a data breach, every hour counts. Our lawyers and in-house counsel help you keep the notification obligation, communication with the Dutch Data Protection Authority, and the risk of fines and claims manageable. From international corporations to the baker on the corner.
View pageTechnological innovations and data offer unprecedented opportunities. The more data, the better, as data increases the value of the organization. Due to strict privacy regulations, legal risks have increased enormously, which can have serious consequences for the continuity of the organization. A large amount of data can also lead to increased liability. Our Privacy Team helps the organization navigate the complex data protection regulations.
View pageFrom international e-commerce giants to the baker with an order page: we make your webshop privacy-proof, from privacy statements and cookies to data processing agreements and data breaches.
View pageAre you required to appoint a Data Protection Officer, and how do you structure that role independently? Our lawyers and in-house counsel assess your situation, act as an external DPO if desired, and support your internal DPO – from international corporations to the baker around the corner.
View pageDoes your organization demonstrably comply with the GDPR? With a privacy audit, our lawyers and in-house counsel map out your processing activities, risks, and shortcomings – from international corporations to the baker on the corner – and deliver a report with clear priorities.
View pageOur lawyers and in-house counsel fulfill the external Security Officer role and translate Article 32 GDPR and NIS2 into verifiable security policies, from international corporations to the baker on the corner.
View pageHealthcare organizations process special categories of personal data and, in addition to the GDPR, must comply with healthcare-specific laws such as the WGBO and the Wabvpz. Our lawyers and in-house counsel help you demonstrably get this in order.
View pagePrivacy and data protection law governs how organizations may handle personal data: when you may collect, use, share, and must protect data. The core consists of the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG). When properly regulated, it prevents fines, data breaches, and reputational damage; if things go wrong, it provides avenues to limit the damage.
Our lawyers and in-house counsel assist both international corporations and the baker on the corner — from drafting a data processing agreement to managing a data breach or an investigation by the Dutch Data Protection Authority.
The GDPR applies to every organization that processes personal data, regardless of size — including sole proprietorships and family businesses. Every processing activity requires a valid legal basis (Article 6 of the General Data Protection Regulation): consent, necessity for a contract, a legal obligation, a vital interest, a public task, or a legitimate interest. A stricter regime applies to special categories of personal data, such as health or criminal data (Articles 9 and 10 of the GDPR). We assess which legal basis you can rely on and help document it with proper documentation.
If you engage an external party to process personal data on your behalf—such as your accounting firm, hosting provider, CRM or email supplier—you are required to conclude a data processing agreement (Article 28 of the General Data Protection Regulation). In this agreement, you specify, among other things, the purpose and nature of the processing, the security measures, the use of sub-processors, audit and confidentiality agreements, and the return or deletion of data after completion. The controller remains ultimately responsible. We draft your data processing agreement or review the agreement presented to you by your supplier.
In the event of a data breach — ranging from a stolen laptop to a misaddressed email — you must, in principle, report it to the Dutch Data Protection Authority within 72 hours of discovery (Article 33 of the General Data Protection Regulation). If the breach poses a high risk to data subjects, you must also inform them (Article 34 of the GDPR). You must record every data breach, even one that is not subject to mandatory reporting, in an internal data breach register. We assess with you whether reporting is necessary, draft the report, and manage the communication with data subjects.
Three obligations are systematically overlooked in SMEs. The processing register records all your processing activities, purposes, retention periods, and security measures (Article 30 of the General Data Protection Regulation). For high-risk processing activities, a Data Protection Impact Assessment (DPIA) is mandatory (Article 35 GDPR). Furthermore, if you process special categories of data on a large scale or monitor systematically, you may sometimes need to appoint a Data Protection Officer (Article 37 GDPR). We map out what is mandatory for you and set it up pragmatically.
Customers, website visitors, and employees have rights: access, rectification, erasure ('right to be forgotten'), restriction, data portability, and objection (Articles 15 to 21 of the General Data Protection Regulation). You must clearly inform them in advance via a privacy statement (Article 13 and Article 14 GDPR). We draft your privacy statement and internal privacy policy and help you handle requests from data subjects correctly and on time.
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) can enforce the law severely. For less serious violations, a maximum of €10 million or 2% of the worldwide annual turnover applies; for serious violations, €20 million or 4% (Article 83 of the General Data Protection Regulation). In addition, data subjects may claim damages (Article 82 GDPR). We assist you in investigations or enforcement proceedings by the AP and in privacy disputes, ensuring that your defense and case file are in order.
Privacy rarely stands alone. If it concerns software, SaaS, cloud services, or broader digital law, please also visit our Intellectual Property & IP Law; if publication, portrait rights, or online expressions are involved, you will find more information on Media Law. This page focuses on the protection of personal data itself: legal bases, data processing agreements, data breaches, and enforcement.
From bringing your GDPR documents into order to guiding you through a data breach or an investigation by the Data Protection Authority — our lawyers and legal experts support you in every area of privacy law.
Often, something is already at play before it becomes legally urgent. The sooner you involve us, the more options you retain. If you recognize any of these situations, seeking advice is advisable.
In privacy law, your starting position determines the outcome. Before reporting a data breach or filing a defense with the Dutch Data Protection Authority, we map out your processing activities, legal bases, and documentation. This allows us to choose the route—advice, ensuring documentation is in order, reporting, or filing a defense—that best serves your interests, rather than taking the first step that comes to mind.
From question to solution in four steps.
We discuss your organization, your processing activities, and your question, and review existing agreements and documents.
We assess your situation against the GDPR and the UAVG and map out the legal bases, obligations, and risks.
We choose the route — advice, putting documents in order, reporting, or defense — and the involvement of a lawyer or legal expert.
We execute: from drafting a data processing agreement to assistance with the Dutch Data Protection Authority.
In a legal dispute, it is not just about being right. It is also about evidence, timing, negotiating position, and the business consequences of every step.
Our specialists combine legal analysis with experience in cases for entrepreneurs, directors, and organizations.
Our team is engaged to provide legal and strategic support in the field of privacy and data protection. We offer this support to a wide variety of clients, ranging from companies to non-profit organizations. Our practice group's excellent knowledge of privacy law and data protection results in sound and pragmatic advice. In addition to outlining the legal framework, our lawyers and legal experts specialize in implementing this advice within the organization.
The questions entrepreneurs ask us most often about the GDPR.
Yes. The General Data Protection Regulation makes no distinction based on company size. Even a sole proprietorship, freelancer, or family business must handle personal data carefully, have a legal basis (Article 6 GDPR), and report data breaches. Especially in the SME sector, a solid foundation prevents major problems.
As soon as an external party processes personal data on your behalf, such as your accounting firm, hosting provider, or CRM supplier, you are required to enter into a data processing agreement (Article 28 GDPR). This agreement sets out the arrangements regarding purpose, security, sub-processors, and confidentiality. As the data controller, you remain ultimately responsible.
In principle, within 72 hours of discovery to the Data Protection Authority (Article 33 GDPR). If the breach poses a high risk to the data subjects, you must also inform them (Article 34 GDPR). Furthermore, you must record every data breach in an internal data breach register, even if notification is not required.
The DPA can impose fines of up to €10 million or 2% of global annual turnover for less serious infringements, and up to €20 million or 4% for serious infringements (Article 83 GDPR). In addition, data subjects may claim damages (Article 82 GDPR).
That depends on your situation. For advice, drafting a data processing agreement or privacy statement, and managing a data breach, an in-house counsel is often sufficient. If proceedings before the court become necessary, a lawyer is mandatory. We have both in-house and will determine the best option together with you.
The controller determines the purpose and means of processing and remains ultimately responsible. The processor processes data on the instructions and under the direction of the controller. You record the mutual agreements in a data processing agreement (Article 28 GDPR).
Leave your details. We will contact you to briefly discuss your situation.
Want to know more about our services?
Then contact our specialists.