Specialized legal assistance for entrepreneurs, organizations, and directors.
View all areas of expertiseLegal assistance with conflicts, claims, negotiations, and proceedings.
View legal assistanceLegal assistance with outstanding invoices, disputed claims, and collection proceedings.
View collectionMeet MKB Juristen, our founders, and the way we organize legal assistance for entrepreneurs.
About SME LawyersIn the event of a data breach, every hour counts. Our lawyers and in-house counsel help you keep the notification obligation, communication with the Dutch Data Protection Authority, and the risk of fines and claims manageable. From international corporations to the baker on the corner.
Despite effective prevention, a data breach can occur within an organization. A data breach occurs when a third party gains unauthorized or unintended access to personal data. Additionally, a data breach can occur when personal data is altered, lost, or destroyed without consent. If a data breach occurs within an organization, immediate action must be taken. Our privacy specialists will assess the situation and, if necessary, assist with filing a report with the Dutch Data Protection Authority (AP).
Do you have questions regarding data breaches? Please contact us.
A data breach is a security breach involving personal data. The General Data Protection Regulation (GDPR) defines this in Article 4, paragraph 12, as a breach that results in the destruction, loss, alteration, or unauthorized disclosure of, or unauthorized access to, personal data. Therefore, not every security incident constitutes a data breach: legally, we only refer to it as a data breach when personal data is actually involved.
In practice, data breaches vary widely. Examples include a ransomware attack in which a customer database is encrypted, an email containing personal data sent to the wrong recipient, a stolen or lost laptop or USB stick, a hack of a web application, or mail containing financial data ending up at the wrong address. Whether it concerns an international corporation or the baker on the corner with a loyalty card: as soon as personal data falls into the wrong hands, the same legal obligations apply.
Pursuant to Article 33 of the GDPR, a data breach must be reported to the Data Protection Authority without undue delay and, where possible, within 72 hours of discovery. This is only required if the data breach is likely to pose a risk to the rights and freedoms of the data subjects. If it is not possible to report within 72 hours, the delay must be substantiated with reasons.
The notification includes, among other things, the nature of the data breach, the categories and number of individuals involved, the likely consequences, and the measures taken or proposed. The burden of proof to demonstrate that a data breach poses no risk lies with the controller. Our lawyers and in-house counsel help to make this assessment quickly and carefully, ensuring that you do not report unnecessarily, but also do not overlook any reportable breach.
In addition to notification to the supervisory authority, Article 34 of the GDPR requires you to inform the data subjects themselves when the data breach is likely to pose a high risk to their rights and freedoms. This sets a higher bar than for notification to the Dutch Data Protection Authority. Notification of data subjects may be omitted if, for example, the data was properly encrypted, if measures have been taken subsequently that eliminated the high risk, or if individual notification would require a disproportionate effort.
In addition, Article 33, paragraph 5, of the GDPR requires you to document all data breaches internally in a register, including those you do not report. This allows you to demonstrate to the Dutch Data Protection Authority that you take your obligations seriously.
In the event of a data breach, every hour counts. We follow a fixed step-by-step plan that we go through with you:
Our legal experts also handle communication with the regulator, clients, and potentially the press, to limit reputational damage.
Many organizations outsource the processing of personal data, for example to a hosting provider, a software supplier, or a payroll administrator. Pursuant to Article 28 of the GDPR, the agreements between the controller and the processor must be laid down in a data processing agreement. This agreement should also state that the processor reports a data breach to the controller without delay, so that the latter can comply with its own reporting obligation in a timely manner.
If things go wrong at your supplier, you, as the data controller, often remain the primary point of contact for the supervisory authority. We review your data processing agreements, place liability where it belongs, and assist with recourse against a negligent processor.
The Dutch Data Protection Authority can impose a fine of up to 10 million euros or 2% of the worldwide annual turnover for violating the notification obligation or for inadequate security. For more serious violations, such as the unlawful processing of personal data, this rises to 20 million euros or 4% of the annual turnover (Article 83 GDPR). In Dutch practice, the fines imposed range from tens of thousands to hundreds of thousands of euros.
In addition, data subjects may claim compensation for material and immaterial damage caused by a data breach pursuant to Article 82 of the GDPR. This risk of claims, alongside enforcement by the supervisory authority, makes a well-considered approach essential. Our lawyers assist both organizations facing a fine or claim and small business owners who wish to prevent such a situation from ever arising.
The best notification is the one that is never needed. Article 32 of the GDPR requires you to take appropriate technical and organizational measures to protect personal data, such as encryption, access control, and employee awareness. Our privacy lawyers help you get your security and internal procedures in order so that you can act quickly and correctly in the event of an incident.
Good prevention is closely linked to other components of your privacy policy. Therefore, please also review our pages on the privacy audit, the DPIA , and the Data Protection Officer (DPO).
Do I have to report every data breach to the Dutch Data Protection Authority?
No. You only report if the data breach is likely to pose a risk to the rights and freedoms of the data subjects. However, you must record all data breaches in your internal register.
Within what timeframe must I report a data breach?
Without undue delay and, where possible, within 72 hours of discovery (Article 33 GDPR). If this is not possible, you must justify the delay.
What if the data breach originates at my supplier?
As the controller, you remain responsible to the supervisory authority. However, the processor must report the breach to you without delay; you stipulate this in the processor agreement (Article 28 GDPR).
Can I be fined if I do not report?
Yes. Failure to report or reporting too late can result in a fine of up to 10 million euros or 2% of worldwide annual turnover (Article 83 GDPR).
Data breaches are a specialty within our broader expertise in Privacy and Data Protection. In mixed teams of lawyers and in-house counsel, we assist organizations ranging from international corporations to the baker around the corner, both with an acute data breach and with structurally bringing your privacy policy up to standard.
In specialized legal cases, it is not just about the legal rule. It is also about evidence, timing, negotiating position, and the business implications of every step.
We guide you every step of the way, from the first incident to the conclusion regarding the regulator and the parties involved.
A misjudged or unreported data breach can lead to hefty fines, damage claims from data subjects, and lasting reputational damage. The burden of proof that a breach poses no risk lies with you as the data controller. A well-considered, swift approach limits these risks.
We act quickly: containment, risk assessment, reporting where necessary, and informing stakeholders in case of high risk. We then help improve security and internal procedures to prevent recurrence. This is done in mixed teams of lawyers and in-house counsel, tailored to your organization.
In the event of a data breach, we go through a fixed step-by-step plan together with you.
We will briefly discuss the situation, the available documents, and your primary interests.
We assess your legal position, supporting documents, deadlines, and possible next steps.
You will receive concrete advice on the best course of action: responding, negotiating, settling, or litigating.
We assist with correspondence, negotiation, litigation strategy, or further legal assistance.
We combine legal analysis with practical experience in cases for entrepreneurs, directors, and organizations.
Our team is engaged to provide legal and strategic support in the field of privacy and data protection. We offer this support to a wide variety of clients, ranging from companies to non-profit organizations. Our practice group's excellent knowledge of privacy law and data protection results in sound and pragmatic advice. In addition to outlining the legal framework, our lawyers and legal experts specialize in implementing this advice within the organization.
The questions we receive most frequently regarding the reporting obligation and the consequences of a data breach.
Legal advice is wise as soon as pressure arises, deadlines are running, an opposing party takes a position, or when the financial or strategic interests are significant.
Yes. We assess your legal position, advise on strategy, and can assist with correspondence, negotiation, defense, or further legal steps.
Specialist advice is provided on an hourly basis in principle. Where possible, we provide clarity in advance regarding the expected approach, costs, and next steps.
Yes. You can request a free consultation. We will briefly discuss your situation and indicate which course of action is likely the sensible one.
Contact us immediately in the event of a data breach or ask for advice regarding your reporting obligations and security. Our lawyers and in-house counsel will assist you quickly and clearly.
Also view the other sections within this area of law.
Leave your details. We will contact you to briefly discuss your situation.
Want to know more about our services?
Then contact our specialists.