From 1 January 2016, organisations and companies are required to report serious data breaches to the Personal Data Authority.
What is a data breach?
We speak of a data breach when there is a breach of personal data security (Article 13 of the Personal Data Protection Act).
A data breach involves personal data at an organisation being accessed, released, destroyed or altered unintentionally or unlawfully. For example, through a stolen or lost laptop containing personal data or a hack into an organisation's data files.
How do I determine whether a data breach needs to be reported?
The Personal Data Authority has drawn up policy rules (PDF) on the data breach notification obligation. These policy rules are intended to help you determine whether there is a data breach that needs to be reported to the Personal Data Authority and possibly to the data subjects.
Where do I report a data breach?
If there is a data breach, you report it to the Authority for Personal Data through the data breach hotline.
More information
On the website of the Personal Data Authority you will find extensive information on the mandatory data breach notification
Watch the data breach debate with Udo Oelen (Dutch Data Protection Authority) and Mirjam Bink (ONL) during TekTok late night
Presentation by Lisette Meij of ICT Recht on the new privacy legislation during the SIDN Relation Day.