Privacy and data protection

Security Officer

Security that demonstrably complies with the GDPR

Our lawyers and in-house counsel fulfill the external Security Officer role and translate Article 32 GDPR and NIS2 into verifiable security policies, from international corporations to the baker on the corner.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner

What we do

In an external organization, one of our privacy specialists can fulfill the role of Security Officer. In this role, legal advice is provided regarding the security of information within an organization. Furthermore, a security policy can be drafted. Once the security policy has been developed, we provide support with its implementation.

Questions regarding the security officer? Please contact us.

Security Officer within Privacy and Data Protection

The Security Officer we provide has one foot in information security and the other in privacy and data protection. This distinction determines where we place the emphasis. While a traditional (Chief) Information Security Officer primarily focuses on technology and system continuity, our Security Officer translates those measures into the legal requirements that the General Data Protection Regulation (GDPR) imposes on the security of personal data. Consequently, security is not an IT matter, but a statutory obligation with legal consequences if things go wrong.

Our mixed teams of lawyers and in-house counsel ensure that the security policy is not only technically sound but also demonstrably compliant with the law. This works just as well for an international corporation with its own IT department as it does for the baker on the corner who wants to protect his customer base and personnel records.

Appropriate technical and organisational measures (Article 32 GDPR)

The legal heart of the Security Officer role is Article 32 of the General Data Protection Regulation. That article obliges every controller and processor to implement “appropriate technical and organisational measures” to ensure a level of security commensurate with the risk. The law does not prescribe a fixed checklist, but mentions, among other things, pseudonymisation and encryption of personal data, ensuring the confidentiality, integrity and availability of systems, and regularly testing and evaluating security.

What is “appropriate” depends on the state of the art, the costs, the nature of the processing, and the risk to data subjects. Our Security Officer makes this assessment based on legal justification, documents the choices, and ensures that you can demonstrate the measures taken. After all, that accountability obligation under Article 5(2) of the GDPR is strict: you must not only work securely, you must be able to prove that you are doing so.

Security Officer, Data Protection Officer, or CISO: who does what?

In practice, the roles are often confused. The distinction is legally relevant. The Data Protection Officer (DPO) independently monitors compliance with the GDPR and is legally required in a number of cases (Article 37 GDPR). The CISO or Information Security Officer is responsible for implementing the security policy. The Security Officer we assign bridges the gap: they translate privacy requirements into concrete, verifiable security policy and monitor its implementation.

It is important that the DPO holds a supervisory, independent position and therefore may not personally implement the security policy over which he or she exercises oversight. By assigning both roles separately within our organization, you avoid a conflict of interest and maintain a clear legal relationship.

Data breaches, DPIA and processor agreements

Security is not a standalone subject. Our Security Officer addresses the interconnected obligations. Should things go wrong, the data breach notification obligation applies: a breach involving personal data must in principle be reported to the Data Protection Authority within 72 hours (Article 33 GDPR) and, in cases of high risk, also to the data subjects themselves (Article 34 GDPR). We structure the data breach so that you meet this deadline and document the appropriate considerations in a substantiated manner.

In addition, the Security Officer assesses whether a Data Protection Impact Assessment is required (the DPIA under Article 35 GDPR) and whether the agreements with suppliers and IT service providers meet the requirements for data processing agreements (Article 28 GDPR). In this way, security measures, contracts, and risk analyses align rather than operating at cross purposes.

NIS2 and the Cybersecurity Act

For an increasing number of organizations, the European NIS2 Directive is coming into focus alongside the GDPR, which is being transposed into Dutch law through the Cybersecurity Act. This regulation imposes a duty of care and an obligation to report incidents on “essential” and “important” entities in sectors including energy, transport, healthcare, digital infrastructure, and government. Directors are held personally responsible for approving and overseeing the security measures.

While the GDPR places the protection of personal data at the center, NIS2 takes a broader view of the continuity and resilience of network and information systems. Our Security Officer brings both regimes together, ensuring you do not do the same work twice and do not overlook any obligations. NIS2 typically does not play a role for the baker on the corner; for the international group in a vital sector, it does all the more.

Why SME Lawyers

At MKB Juristen, you work with mixed teams of lawyers and in-house counsel who understand the technology and master the law. We fulfill the Security Officer role externally, on an on-demand basis or for a fixed period, and liaise directly with our Data Protection Officer (DPO) and privacy law specialists where necessary. No isolated advice, but a security policy that is solid, demonstrably complies with the GDPR, and fits your organization, from an international corporation to the baker around the corner.

Do you have questions about the deployment of a Security Officer or about your security obligations under the GDPR? Please feel free to contact us.

Mr. Jaime Boogaers
Mr. Jaime Boogaers
Corporate Law · Lawyer

In specialized legal cases, it is not just about the legal rule. It is also about evidence, timing, negotiating position, and the business implications of every step.

What we do for you

We fill the Security Officer role externally and handle the associated privacy obligations.

  • Filling the external Security Officer role; one of our privacy specialists fulfills the position on an on-call basis or for a fixed period.
  • Drafting and implementing security policy; We draft the policy and guide the rollout in your organization.
  • Assessment against Article 32 GDPR; We assess whether your technical and organisational measures are appropriate and demonstrable.
  • Establishing a data breach process; A functioning notification process within 72 hours in accordance with Articles 33 and 34 of the GDPR.
  • DPIA and processor agreements; Assessment pursuant to Articles 35 and 28 of the GDPR.
  • NIS2 and Cybersecurity Act; Mapping the duty of care and reporting for essential and important entities.

Risks associated with inadequate security

The security of personal data is a legal obligation. If this falls short, the consequences are legal and financial.

  • No adequate security; Without measures in accordance with Article 32 of the GDPR, you risk enforcement by the Dutch Data Protection Authority and fines.
  • Data breach reported too late; Missing the 72-hour time limit under Article 33 of the GDPR constitutes an independent infringement.
  • Confusion of roles between DPO and Security Officer; A DPO who implements their own security policy loses their independent oversight position.
  • NIS2 obligations missed; Directors are personally responsible for approving and supervising the measures.

Our approach

We separate the Security Officer and DPO roles, legally substantiate every measure, and demonstrably document everything in accordance with the accountability obligation under Article 5, paragraph 2 of the GDPR.

This is how we work

From intake to assurance in four steps.

01

Intake and initial assessment

We will briefly discuss the situation, the available documents, and your primary interests.

02

Analysis of position and risks

We assess your legal position, supporting documents, deadlines, and possible next steps.

03

Strategic advice

You will receive concrete advice on the best course of action: responding, negotiating, settling, or litigating.

04

Execution

We assist with correspondence, negotiation, litigation strategy, or further legal assistance.

Specialists for entrepreneurs

We combine legal analysis with practical experience in cases for entrepreneurs, directors, and organizations.

Our team is engaged to provide legal and strategic support in the field of privacy and data protection. We offer this support to a wide variety of clients, ranging from companies to non-profit organizations. Our practice group's excellent knowledge of privacy law and data protection results in sound and pragmatic advice. In addition to outlining the legal framework, our lawyers and legal experts specialize in implementing this advice within the organization.

Frequently Asked Questions

The most frequently asked questions about the Security Officer.

When is legal advice advisable?

Legal advice is wise as soon as pressure arises, deadlines are running, an opposing party takes a position, or when the financial or strategic interests are significant.

Can MKB Juristen also help if there is already a conflict?

Yes. We assess your legal position, advise on strategy, and can assist with correspondence, negotiation, defense, or further legal steps.

How much does specialist legal advice cost?

Specialist advice is provided on an hourly basis in principle. Where possible, we provide clarity in advance regarding the expected approach, costs, and next steps.

Can I have a no-obligation consultation first?

Yes. You can request a free consultation. We will briefly discuss your situation and indicate which course of action is likely the sensible one.

Need a Security Officer?

Contact MKB Juristen for an external Security Officer or advice on your security obligations under the GDPR.

Contact us

Contact us

Leave your details. We will contact you to briefly discuss your situation.

Contact us

Jaime Boogaers

Want to know more about our services?
Then contact our specialists.

Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation