Duty to Report Data Breach

On 1 January 2016, the so-called “Data Leaks Reporting Obligation” came into effect. This reporting obligation was already laid down in the Personal Data Protection Act (“Wet bescherming persoonsgegevens – Wbp”). However, since May 28, 2018, the General Data Protection Regulation (“Algemene Verordening Gegevensbescherming – AVG”) has replaced it. This umbrella of European privacy law now regulates the obligation to report data leaks. It ensures that organizations are obliged to report to the Dutch Data Protection Authority (formerly known as the “College bescherming persoonsgegevens” (CBP)) as soon as they have a serious data breach. In some cases, organizations are also required to report the data breach to data subjects whose personal data has been leaked. 

Notice and takedown

General Data Protection Regulation (GDPR)

The background to this duty to report is the right to privacy (or more specifically: the right to respect and protection of privacy and careful handling of personal data).

The right to privacy is elaborated in the General Data Protection Regulation (GDPR – also known as Algemene Verordening Gegevensbescherming (AVG)). This regulation imposes a number of obligations on organizations that process personal data. For example, these “controllers” must take measures to protect personal data against loss and unlawful processing. It is, therefore, necessary to take measures to prevent data leaks.

Duty to Report

If there is a data breach, reporting to the Dutch Data Protection Authority is mandatory under the new rules. That is, however, not necessary for all data leaks. Reporting is only necessary if there is (a significant risk of) serious adverse consequences for the protection of personal data. If the data breach is also likely to have adverse consequences for the privacy of the data subject, this person must also be informed about the data breach.

SHOULD YOU REPORT THE DATA LEAK?

Simply put, you can follow these steps:

1. Is there a security incident?

  1. Yes: Go to step 2.
  2. No: No obligation to report the data breach.

2. Has Personal Data been lost?

  1. Yes: Go to step 4 (there is a data breach).
  2. No: Go to step 3.

3. Can unlawful processing not be excluded?

  1. Yes: Go to step 4 (there is a data breach).
  2. No: No obligation to report the data breach.

4. Does the data breach relate to sensitive data or is there any other (significant) risk of serious adverse consequences for the protection of the processed personal data?

  1. Yes: The Data Breach must be reported to the Dutch Data Protection Authority, Go to step 5.
  2. No: No obligation to report the data breach.

5. Were the leaked personal data not encrypted or not sufficiently encrypted, or are there likely to be adverse consequences for the data subject’s privacy for some other reason?

  1. Yes: The data breach must also be reported to the data subject.
  2. No: The data breach must only be reported to the Dutch Data Protection Authority.

Penalty

Does the data breach notification obligation apply to your organization, but you are not following it and thus breaking the rules? Then the Dutch Data Protection Authority can impose administrative fines. If your organization has not committed the violation intentionally and there is no serious culpable negligence, the Dutch Data Protection Authority will first have to impose a binding instruction before possibly imposing a fine. In addition, the Dutch Data Protection Authority must take into account all circumstances of the case. Consider, for example, the fact that the data has not been viewed by third parties.

handhaving

Processing Agreement

Given the risk of fines, it is advisable to make agreements with parties that process personal data (so-called processors) for your organization about the security measures to be taken. These agreements can be laid down in a processing agreement. In fact, such an agreement is mandatory!

It is also advisable to make agreements about the responsibility for (enabling) compliance with the data breach reporting obligation. Is your organization addressed as responsible for the processing of personal data, but the error lies with your processor? Then it is wise to have made agreements about this in advance in the processing agreement so that you are free from any fines.

More information can be found in the data breach reporting rules of the Dutch Data Protection Authority.

Handelsnaamrecht

Contact

Do you have a dispute with an organization or with the Dutch Data Protection Authority about the (non-) compliance with the obligation to report data breaches? Or do you have another problem with regard to the protection of personal data?

LAWFOX’s lawyers are happy to assist you. We can advise and assist you in any procedure, but we can also help you draw up a processing agreement. We have a team available to assist you with all your questions about the obligation to report data leaks.

Contactform

  • This field is for validation purposes and should be left unchanged.

Advocaten domeinnaam recht

Google reviews LAWFOX

0 / 10 0 reviews