Privacy and data protection

Data leaks

Act quickly and correctly in the event of a data breach

In the event of a data breach, every hour counts. Our lawyers and in-house counsel help you keep the notification obligation, communication with the Dutch Data Protection Authority, and the risk of fines and claims manageable. From international corporations to the baker on the corner.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner

What we do

Despite effective prevention, a data breach can occur within an organization. A data breach occurs when a third party gains unauthorized or unintended access to personal data. Additionally, a data breach can occur when personal data is altered, lost, or destroyed without consent. If a data breach occurs within an organization, immediate action must be taken. Our privacy specialists will assess the situation and, if necessary, assist with filing a report with the Dutch Data Protection Authority (AP).

Do you have questions regarding data breaches? Please contact us.

What exactly is a data breach?

A data breach is a security breach involving personal data. The General Data Protection Regulation (GDPR) defines this in Article 4, paragraph 12, as a breach that results in the destruction, loss, alteration, or unauthorized disclosure of, or unauthorized access to, personal data. Therefore, not every security incident constitutes a data breach: legally, we only refer to it as a data breach when personal data is actually involved.

In practice, data breaches vary widely. Examples include a ransomware attack in which a customer database is encrypted, an email containing personal data sent to the wrong recipient, a stolen or lost laptop or USB stick, a hack of a web application, or mail containing financial data ending up at the wrong address. Whether it concerns an international corporation or the baker on the corner with a loyalty card: as soon as personal data falls into the wrong hands, the same legal obligations apply.

The notification obligation to the Dutch Data Protection Authority (Article 33 GDPR)

Pursuant to Article 33 of the GDPR, a data breach must be reported to the Data Protection Authority without undue delay and, where possible, within 72 hours of discovery. This is only required if the data breach is likely to pose a risk to the rights and freedoms of the data subjects. If it is not possible to report within 72 hours, the delay must be substantiated with reasons.

The notification includes, among other things, the nature of the data breach, the categories and number of individuals involved, the likely consequences, and the measures taken or proposed. The burden of proof to demonstrate that a data breach poses no risk lies with the controller. Our lawyers and in-house counsel help to make this assessment quickly and carefully, ensuring that you do not report unnecessarily, but also do not overlook any reportable breach.

When must you inform the data subjects? (Article 34 GDPR)

In addition to notification to the supervisory authority, Article 34 of the GDPR requires you to inform the data subjects themselves when the data breach is likely to pose a high risk to their rights and freedoms. This sets a higher bar than for notification to the Dutch Data Protection Authority. Notification of data subjects may be omitted if, for example, the data was properly encrypted, if measures have been taken subsequently that eliminated the high risk, or if individual notification would require a disproportionate effort.

In addition, Article 33, paragraph 5, of the GDPR requires you to document all data breaches internally in a register, including those you do not report. This allows you to demonstrate to the Dutch Data Protection Authority that you take your obligations seriously.

Step-by-step plan: what to do in the event of a data breach

In the event of a data breach, every hour counts. We follow a fixed step-by-step plan that we go through with you:

  1. Contain and investigate: stop the breach, determine which personal data has been affected and how many data subjects are involved.
  2. Assess risk: weigh the probability and severity of the consequences for those involved.
  3. Report to the AP: if subject to notification, within 72 hours and with the correct information.
  4. Inform stakeholders: in case of high risk, in clear and simple language.
  5. Take and document measures: restore security, prevent recurrence, and record everything in the data breach register.

Our legal experts also handle communication with the regulator, clients, and potentially the press, to limit reputational damage.

The role of the processor and the processor agreement (Article 28 GDPR)

Many organizations outsource the processing of personal data, for example to a hosting provider, a software supplier, or a payroll administrator. Pursuant to Article 28 of the GDPR, the agreements between the controller and the processor must be laid down in a data processing agreement. This agreement should also state that the processor reports a data breach to the controller without delay, so that the latter can comply with its own reporting obligation in a timely manner.

If things go wrong at your supplier, you, as the data controller, often remain the primary point of contact for the supervisory authority. We review your data processing agreements, place liability where it belongs, and assist with recourse against a negligent processor.

Fines, enforcement and compensation (Articles 82 and 83 GDPR)

The Dutch Data Protection Authority can impose a fine of up to 10 million euros or 2% of the worldwide annual turnover for violating the notification obligation or for inadequate security. For more serious violations, such as the unlawful processing of personal data, this rises to 20 million euros or 4% of the annual turnover (Article 83 GDPR). In Dutch practice, the fines imposed range from tens of thousands to hundreds of thousands of euros.

In addition, data subjects may claim compensation for material and immaterial damage caused by a data breach pursuant to Article 82 of the GDPR. This risk of claims, alongside enforcement by the supervisory authority, makes a well-considered approach essential. Our lawyers assist both organizations facing a fine or claim and small business owners who wish to prevent such a situation from ever arising.

Preventing data breaches: security in order (Article 32 GDPR)

The best notification is the one that is never needed. Article 32 of the GDPR requires you to take appropriate technical and organizational measures to protect personal data, such as encryption, access control, and employee awareness. Our privacy lawyers help you get your security and internal procedures in order so that you can act quickly and correctly in the event of an incident.

Good prevention is closely linked to other components of your privacy policy. Therefore, please also review our pages on the privacy audit, the DPIA , and the Data Protection Officer (DPO).

Frequently asked questions about data breaches

Do I have to report every data breach to the Dutch Data Protection Authority?
No. You only report if the data breach is likely to pose a risk to the rights and freedoms of the data subjects. However, you must record all data breaches in your internal register.

Within what timeframe must I report a data breach?
Without undue delay and, where possible, within 72 hours of discovery (Article 33 GDPR). If this is not possible, you must justify the delay.

What if the data breach originates at my supplier?
As the controller, you remain responsible to the supervisory authority. However, the processor must report the breach to you without delay; you stipulate this in the processor agreement (Article 28 GDPR).

Can I be fined if I do not report?
Yes. Failure to report or reporting too late can result in a fine of up to 10 million euros or 2% of worldwide annual turnover (Article 83 GDPR).

Part of Privacy and data protection

Data breaches are a specialty within our broader expertise in Privacy and Data Protection. In mixed teams of lawyers and in-house counsel, we assist organizations ranging from international corporations to the baker around the corner, both with an acute data breach and with structurally bringing your privacy policy up to standard.

Mr. Jaime Boogaers
Mr. Jaime Boogaers
Corporate Law · Lawyer

In specialized legal cases, it is not just about the legal rule. It is also about evidence, timing, negotiating position, and the business implications of every step.

How we help you with data breaches

We guide you every step of the way, from the first incident to the conclusion regarding the regulator and the parties involved.

  • Assessing whether a data breach is subject to mandatory reporting
  • Notification to the Dutch Data Protection Authority within 72 hours
  • Informing stakeholders in case of high risk
  • Drafting and reviewing the data breach register
  • Defense against fines and damage claims
  • Processor agreements and supplier liability

The risks of a data breach

A misjudged or unreported data breach can lead to hefty fines, damage claims from data subjects, and lasting reputational damage. The burden of proof that a breach poses no risk lies with you as the data controller. A well-considered, swift approach limits these risks.

  • Fine of up to 10 million euros or 2% of global annual turnover
  • Compensation to data subjects (Article 82 GDPR)
  • Reputational damage and loss of customer trust
  • Enforcement by the Dutch Data Protection Authority

Our approach

We act quickly: containment, risk assessment, reporting where necessary, and informing stakeholders in case of high risk. We then help improve security and internal procedures to prevent recurrence. This is done in mixed teams of lawyers and in-house counsel, tailored to your organization.

Step-by-step plan for a data breach

In the event of a data breach, we go through a fixed step-by-step plan together with you.

01

Intake and initial assessment

We will briefly discuss the situation, the available documents, and your primary interests.

02

Analysis of position and risks

We assess your legal position, supporting documents, deadlines, and possible next steps.

03

Strategic advice

You will receive concrete advice on the best course of action: responding, negotiating, settling, or litigating.

04

Execution

We assist with correspondence, negotiation, litigation strategy, or further legal assistance.

Specialists for entrepreneurs

We combine legal analysis with practical experience in cases for entrepreneurs, directors, and organizations.

Our team is engaged to provide legal and strategic support in the field of privacy and data protection. We offer this support to a wide variety of clients, ranging from companies to non-profit organizations. Our practice group's excellent knowledge of privacy law and data protection results in sound and pragmatic advice. In addition to outlining the legal framework, our lawyers and legal experts specialize in implementing this advice within the organization.

Frequently asked questions about data breaches

The questions we receive most frequently regarding the reporting obligation and the consequences of a data breach.

When is legal advice advisable?

Legal advice is wise as soon as pressure arises, deadlines are running, an opposing party takes a position, or when the financial or strategic interests are significant.

Can MKB Juristen also help if there is already a conflict?

Yes. We assess your legal position, advise on strategy, and can assist with correspondence, negotiation, defense, or further legal steps.

How much does specialist legal advice cost?

Specialist advice is provided on an hourly basis in principle. Where possible, we provide clarity in advance regarding the expected approach, costs, and next steps.

Can I have a no-obligation consultation first?

Yes. You can request a free consultation. We will briefly discuss your situation and indicate which course of action is likely the sensible one.

A data breach? Engage our privacy lawyers immediately

Contact us immediately in the event of a data breach or ask for advice regarding your reporting obligations and security. Our lawyers and in-house counsel will assist you quickly and clearly.

Contact us

Contact us

Leave your details. We will contact you to briefly discuss your situation.

Contact us

Jaime Boogaers

Want to know more about our services?
Then contact our specialists.

Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation