Specialized legal assistance for entrepreneurs, organizations, and directors.
View all areas of expertiseLegal assistance with conflicts, claims, negotiations, and proceedings.
View legal assistanceLegal assistance with outstanding invoices, disputed claims, and collection proceedings.
View collectionMeet MKB Juristen, our founders, and the way we organize legal assistance for entrepreneurs.
About SME LawyersOur lawyers and in-house counsel fulfill the external Security Officer role and translate Article 32 GDPR and NIS2 into verifiable security policies, from international corporations to the baker on the corner.
In an external organization, one of our privacy specialists can fulfill the role of Security Officer. In this role, legal advice is provided regarding the security of information within an organization. Furthermore, a security policy can be drafted. Once the security policy has been developed, we provide support with its implementation.
Questions regarding the security officer? Please contact us.
The Security Officer we provide has one foot in information security and the other in privacy and data protection. This distinction determines where we place the emphasis. While a traditional (Chief) Information Security Officer primarily focuses on technology and system continuity, our Security Officer translates those measures into the legal requirements that the General Data Protection Regulation (GDPR) imposes on the security of personal data. Consequently, security is not an IT matter, but a statutory obligation with legal consequences if things go wrong.
Our mixed teams of lawyers and in-house counsel ensure that the security policy is not only technically sound but also demonstrably compliant with the law. This works just as well for an international corporation with its own IT department as it does for the baker on the corner who wants to protect his customer base and personnel records.
The legal heart of the Security Officer role is Article 32 of the General Data Protection Regulation. That article obliges every controller and processor to implement “appropriate technical and organisational measures” to ensure a level of security commensurate with the risk. The law does not prescribe a fixed checklist, but mentions, among other things, pseudonymisation and encryption of personal data, ensuring the confidentiality, integrity and availability of systems, and regularly testing and evaluating security.
What is “appropriate” depends on the state of the art, the costs, the nature of the processing, and the risk to data subjects. Our Security Officer makes this assessment based on legal justification, documents the choices, and ensures that you can demonstrate the measures taken. After all, that accountability obligation under Article 5(2) of the GDPR is strict: you must not only work securely, you must be able to prove that you are doing so.
In practice, the roles are often confused. The distinction is legally relevant. The Data Protection Officer (DPO) independently monitors compliance with the GDPR and is legally required in a number of cases (Article 37 GDPR). The CISO or Information Security Officer is responsible for implementing the security policy. The Security Officer we assign bridges the gap: they translate privacy requirements into concrete, verifiable security policy and monitor its implementation.
It is important that the DPO holds a supervisory, independent position and therefore may not personally implement the security policy over which he or she exercises oversight. By assigning both roles separately within our organization, you avoid a conflict of interest and maintain a clear legal relationship.
Security is not a standalone subject. Our Security Officer addresses the interconnected obligations. Should things go wrong, the data breach notification obligation applies: a breach involving personal data must in principle be reported to the Data Protection Authority within 72 hours (Article 33 GDPR) and, in cases of high risk, also to the data subjects themselves (Article 34 GDPR). We structure the data breach so that you meet this deadline and document the appropriate considerations in a substantiated manner.
In addition, the Security Officer assesses whether a Data Protection Impact Assessment is required (the DPIA under Article 35 GDPR) and whether the agreements with suppliers and IT service providers meet the requirements for data processing agreements (Article 28 GDPR). In this way, security measures, contracts, and risk analyses align rather than operating at cross purposes.
For an increasing number of organizations, the European NIS2 Directive is coming into focus alongside the GDPR, which is being transposed into Dutch law through the Cybersecurity Act. This regulation imposes a duty of care and an obligation to report incidents on “essential” and “important” entities in sectors including energy, transport, healthcare, digital infrastructure, and government. Directors are held personally responsible for approving and overseeing the security measures.
While the GDPR places the protection of personal data at the center, NIS2 takes a broader view of the continuity and resilience of network and information systems. Our Security Officer brings both regimes together, ensuring you do not do the same work twice and do not overlook any obligations. NIS2 typically does not play a role for the baker on the corner; for the international group in a vital sector, it does all the more.
At MKB Juristen, you work with mixed teams of lawyers and in-house counsel who understand the technology and master the law. We fulfill the Security Officer role externally, on an on-demand basis or for a fixed period, and liaise directly with our Data Protection Officer (DPO) and privacy law specialists where necessary. No isolated advice, but a security policy that is solid, demonstrably complies with the GDPR, and fits your organization, from an international corporation to the baker around the corner.
Do you have questions about the deployment of a Security Officer or about your security obligations under the GDPR? Please feel free to contact us.
In specialized legal cases, it is not just about the legal rule. It is also about evidence, timing, negotiating position, and the business implications of every step.
We fill the Security Officer role externally and handle the associated privacy obligations.
The security of personal data is a legal obligation. If this falls short, the consequences are legal and financial.
We separate the Security Officer and DPO roles, legally substantiate every measure, and demonstrably document everything in accordance with the accountability obligation under Article 5, paragraph 2 of the GDPR.
From intake to assurance in four steps.
We will briefly discuss the situation, the available documents, and your primary interests.
We assess your legal position, supporting documents, deadlines, and possible next steps.
You will receive concrete advice on the best course of action: responding, negotiating, settling, or litigating.
We assist with correspondence, negotiation, litigation strategy, or further legal assistance.
We combine legal analysis with practical experience in cases for entrepreneurs, directors, and organizations.
Our team is engaged to provide legal and strategic support in the field of privacy and data protection. We offer this support to a wide variety of clients, ranging from companies to non-profit organizations. Our practice group's excellent knowledge of privacy law and data protection results in sound and pragmatic advice. In addition to outlining the legal framework, our lawyers and legal experts specialize in implementing this advice within the organization.
The most frequently asked questions about the Security Officer.
Legal advice is wise as soon as pressure arises, deadlines are running, an opposing party takes a position, or when the financial or strategic interests are significant.
Yes. We assess your legal position, advise on strategy, and can assist with correspondence, negotiation, defense, or further legal steps.
Specialist advice is provided on an hourly basis in principle. Where possible, we provide clarity in advance regarding the expected approach, costs, and next steps.
Yes. You can request a free consultation. We will briefly discuss your situation and indicate which course of action is likely the sensible one.
Contact MKB Juristen for an external Security Officer or advice on your security obligations under the GDPR.
Also view the other sections within this area of law.
Leave your details. We will contact you to briefly discuss your situation.
Want to know more about our services?
Then contact our specialists.