By Tom Meevis, attorney at Law & More
Cyberattacks such as ransomware, phishing, DDoS attacks and computer intrusion rarely affect only the organisation under attack. Victims of cyberattacks also include customers, employees, patients, suppliers and other supply chain partners who may suffer loss, and their legal position differs from group to group. Anyone seeking to establish, after an attack, which obligations apply and which claims exist is therefore well advised to determine first exactly who has been affected and what damage has arisen.
This article addresses in turn who qualifies as a victim, when a data breach must be notified, on what conditions a right to compensation exists, which parties may be liable, what role the criminal law plays, what a cyber insurance policy typically covers, and which steps should be taken immediately after an attack.
Who are the victims of cyberattacks?
Three groups can be distinguished in a cyberattack.
- The affected organisation itself, which faces system downtime, lost turnover, recovery costs, the cost of forensic investigation and reputational harm.
- Natural persons whose personal data have been exposed, such as customers, employees and patients. They may suffer financial loss, but also non-material damage through loss of control over their data, uncertainty or fear of identity fraud.
- Third parties affected through a contractual or supply chain relationship, for instance because they depend on a supplier whose systems have gone down.
This classification is legally relevant. The basis of any claim, and the party against whom it can be brought, depend on the victim’s position. An affected organisation will generally hold its IT supplier to account under the contract, whereas a data subject can rely directly on the standalone basis for liability that the GDPR provides.
When must a data breach be notified?
Where personal data are involved in a cyberattack, it must be assessed whether there is a personal data breach and whether notification is mandatory. Article 33 GDPR requires a breach to be notified to the supervisory authority without undue delay and, where feasible, within seventy-two hours, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
In addition, Article 34 GDPR may require the organisation to inform the data subjects themselves. That obligation arises where the breach is likely to result in a high risk to their rights and freedoms. Communication may be omitted where appropriate technical measures such as encryption were in place, where subsequent measures ensure the high risk will no longer materialise, or where individual communication would involve disproportionate effort; in that last case a public communication suffices.
For the data subject that communication is more than a formality. It enables them to take their own measures, for instance by changing passwords or watching for suspicious transactions, and in practice it is often the starting point of any claim for compensation.
An organisation must therefore establish not only that an attack has taken place, but also which data were affected, whether data were in fact exfiltrated, and what risks follow from that. An independent forensic investigation is often indispensable for that purpose.
This applies all the more where the attack occurs at a processor rather than at the organisation itself. In the summary proceedings between Blauw Research and Nebu (District Court of Rotterdam, 6 April 2023, ECLI:NL:RBROT:2023:2931) the interim relief judge held that, under the data processing agreement concluded between the parties, the controller was entitled to more information about the attack, its consequences and the measures taken than had initially been provided. The processor was also ordered to have an independent forensic investigation carried out and to report periodically. The judgment shows that a well-drafted data processing agreement is in practice the most important instrument for obtaining information in time after an incident, precisely because the controller needs that information to discharge its own notification duties.
When does a right to compensation arise?
Data subjects may claim compensation from the controller or the processor under Article 82 GDPR. A cyberattack does not, however, automatically give rise to a claim. It must be substantiated:
- that the GDPR has been infringed;
- that damage has actually been suffered; and
- that there is a causal link between that infringement and that damage.
Material damage may consist of financial losses, recovery costs or loss caused by identity fraud. As to non-material damage, the Court of Justice of the European Union held in Österreichische Post (CJEU 4 May 2023, C-300/21) that there is no minimum threshold of seriousness, but that an infringement of the GDPR alone is not sufficient for an award.
Of particular relevance to data breaches following a cyberattack is Natsionalna agentsia za prihodite (CJEU 14 December 2023, C-340/21). There the Court held that the fear of possible future misuse of leaked personal data can in itself constitute non-material damage. The data subject must, however, substantiate that fear and its consequences concretely; merely pointing to the fact that data have been leaked is not enough. In the same judgment the Court confirmed that it is for the controller to prove that the security measures taken were appropriate, and that an attack by a third party does not in itself exempt the controller from liability.
Liability under the GDPR exists alongside the civil law bases of breach of contract and tort. Under Article 6:162(1) of the Dutch Civil Code, a party committing an attributable unlawful act must compensate the damage caused. The relativity requirement of Article 6:163 applies: the norm infringed must serve to protect against the kind of damage the injured party has suffered.
Importantly, Article 82 GDPR exists alongside these bases. A data subject is therefore not obliged to found a claim solely on breach of contract or tort, but can rely directly on the standalone basis for liability that the GDPR provides. For the affected organisation, this combination of bases means that several parties may bring claims at the same time after an attack.
Who can be liable?
The affected organisation may be liable where it fails to perform its contractual obligations or has taken insufficient security measures. An IT service provider or processor may also be held to account. What could be expected of that service provider is determined first and foremost by the contract.
Within a processing relationship the data processing agreement plays a central role. Article 28 GDPR requires the controller and the processor to conclude such an agreement, governing among other things the security measures and the handling of data breaches. Where the attack results from inadequate security at the processor, the controller can hold the processor to account under that agreement for the resulting loss.
That emerges sharply from the case concerning the cyberattack on the municipality of Hof van Twente (District Court of Overijssel, 10 May 2023, ECLI:NL:RBOVE:2023:1731). The parties had agreed functional monitoring, not security monitoring. The court held that the duty of care of an IT administrator does not extend so far that security monitoring forms a tacit part of an assignment for functional monitoring, and dismissed the municipality’s claim. It also weighed that the municipality had itself taken decisions that increased the risk, including its password policy and the opening of an RDP port.
The mirror image is the O’Cliance case (District Court of Amsterdam, 14 November 2018, ECLI:NL:RBAMS:2018:10124). There the supplier had installed a complete IT infrastructure and taken on its management. Following a ransomware attack in which the backups were also encrypted, the court held that the supply of such a total package carried a far-reaching duty of care and that straightforward measures had been omitted. Liability was not awarded in full, however: on account of the customer’s contributory fault, two thirds of the damage remained for the supplier’s account.
How heavily the burden of proof on appropriate security can weigh is illustrated by the case of a car dealer’s hacked email account. In the interim judgment of 5 November 2024 (Court of Appeal of Arnhem-Leeuwarden, ECLI:NL:GHARL:2024:6812) the dealer was given the opportunity to prove that its email account had been appropriately secured within the meaning of the GDPR, after a hacker had used that account to send a false payment instruction to a buyer. In the follow-up judgment of 22 July 2025 (ECLI:NL:GHARL:2025:4556) the court found that this proof had not been delivered, after which the parties were still to address the buyer’s contributory fault. Both judgments therefore concern the same proceedings.
The common thread is that the contractual arrangements, the risks of the processing, the measures actually taken, the warnings given on both sides and the injured party’s own conduct all matter. Alongside civil liability, the Dutch Data Protection Authority may impose administrative fines of up to EUR 20 million or 4 per cent of worldwide annual turnover, whichever is higher. Those fines are independent of whether individual data subjects suffered damage.
The criminal law route
A cyberattack may also constitute a criminal offence, such as computer intrusion, rendering data inaccessible or appropriating non-public data. Article 138ab(1) of the Dutch Criminal Code makes it an offence to intentionally and unlawfully gain access to an automated system.
Victims can report the offence to the police, which has specialised cybercrime teams. Where a suspect is prosecuted, a victim may join the criminal proceedings as an injured party and claim compensation there. This route avoids separate civil proceedings, but the outcome depends on detection, prosecution and evidence, which with internationally operating offenders frequently yields no result. For organisations, reporting is often also a practical necessity, because insurers and supply chain partners ask for it.
What does cyber insurance cover?
A cyber insurance policy may provide cover for, among other things:
- incident response and forensic investigation;
- restoration of systems and data;
- business interruption losses and lost turnover;
- crisis communication;
- liability towards third parties;
- legal costs; and
- in some cases fines, settlement payments or ransom, to the extent insurable under the applicable law.
The precise cover depends on the policy. Pay attention to exclusions, security conditions, notification periods, deductibles and requirements on engaging experts. Article 7:957(1) of the Dutch Civil Code also obliges an insured party to take reasonable measures to prevent or limit loss. Where that duty of salvage is not observed, the insurer may reduce the payout.
The cyber insurer should therefore be informed as quickly as possible. Engaging external experts or paying a ransom without the insurer’s consent may affect cover.
What should you do immediately after a cyberattack?
- Record the incident and all relevant actions carefully.
- Isolate affected systems without losing evidence.
- Engage a forensic expert.
- Assess whether there is a notifiable data breach.
- Assess whether the data subjects must be informed.
- Report the offence to the police.
- Notify the incident to your cyber insurer.
- Preserve logs, backups, emails and other relevant data.
- Map the damage and the potentially liable parties.
- Inform customers, employees and supply chain partners carefully and in good time.
A cyberattack is therefore not merely a technical incident. It is also a data protection, civil law, criminal law and insurance law matter. A rapid and well-documented response not only limits the damage, but is decisive for the notifications, the insurance cover and your evidential position in any proceedings.
In closing
The rights and obligations following a cyberattack are spread across several fields of law, and the outcome of a case depends heavily on the specific facts, the content of the contract and the quality of the records. The case law discussed shows that supplier and customer alike are judged on their own conduct, and that deadlines such as the seventy-two hour notification period leave little room for delay.
Law & More assists organisations and data subjects with the legal handling of cyber incidents: from assessing notification duties and reviewing data processing agreements to establishing liability, insurance issues and recovering losses. Are you dealing with a cyberattack or a data breach, or would you like your contracts reviewed against these risks in advance by our IT Law team? Please feel free to contact Law & More for a no-obligation discussion of your situation.
Frequently asked questions
Below we answer the questions we are asked most often on this subject.
Who are the victims of a cyberattack?
There are three layers. First, the affected organisation itself, which bears system downtime, lost turnover, recovery costs, the cost of forensic investigation and reputational harm. Second, the data subjects, the natural persons whose personal data have been exposed, such as customers, employees and patients. Third, third parties suffering loss through a contractual or supply chain relationship, for instance because they depend on a supplier that has gone down. That classification determines on what basis a party can bring a claim, and against whom.
Within what period must I notify a data breach?
Article 33 GDPR requires notification to the supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware of the breach. The duty does not apply where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. That assessment calls for an analysis of the nature of the breach, the categories of data affected and the possible consequences.
When must I inform the data subjects themselves?
Under Article 34 GDPR, where the breach is likely to result in a high risk to the rights and freedoms of the data subjects. Communication may be omitted where appropriate technical measures such as encryption were in place, where subsequent measures ensure the high risk will no longer materialise, or where individual communication would involve disproportionate effort. In that last case a public communication suffices.
Can I compel information from a supplier that has been hacked?
Yes, where a data processing agreement provides for it. In the summary proceedings between Blauw Research and Nebu (District Court of Rotterdam, 6 April 2023, ECLI:NL:RBROT:2023:2931) the interim relief judge held that under the data processing agreement the controller was entitled to more information about the attack, its consequences and the measures taken than had been provided, and ordered the processor to have an independent forensic investigation carried out and to report periodically. That information is needed to discharge your own notification duties.
As a data subject, am I automatically entitled to compensation after a data breach?
No. Article 82 GDPR provides a standalone basis, but you must substantiate that the GDPR has been infringed, that you actually suffered damage, and that there is a causal link between the infringement and that damage. The burden of proof rests on the claimant.
Does fear of identity fraud qualify as non-material damage?
It may. In Natsionalna agentsia za prihodite (CJEU 14 December 2023, C-340/21) the Court of Justice held that the fear of possible future misuse of leaked personal data can in itself constitute non-material damage. The data subject must, however, substantiate that fear and its consequences concretely. Österreichische Post (CJEU 4 May 2023, C-300/21) adds that there is no minimum threshold of seriousness, but that an infringement of the GDPR alone is not sufficient.
Who has to prove that the security measures were appropriate?
The controller. In C-340/21 the Court of Justice confirmed that it is for the controller to show that the security measures taken were appropriate, and that an attack by a third party does not in itself exempt it from liability. In the Netherlands this played out in the case of a car dealer’s hacked email account, where the Court of Appeal of Arnhem-Leeuwarden first gave the dealer the opportunity to furnish that proof (ECLI:NL:GHARL:2024:6812) and then held that it had not been furnished (ECLI:NL:GHARL:2025:4556).
Is my IT supplier liable if it failed to detect an attack?
That depends on what was agreed. In the case concerning the cyberattack on the municipality of Hof van Twente (District Court of Overijssel, 10 May 2023, ECLI:NL:RBOVE:2023:1731) the parties had agreed functional monitoring, not security monitoring. The court held that the duty of care of an IT administrator does not extend so far that security monitoring forms a tacit part of it, and dismissed the claim. Where a broader total package is supplied, the duty of care may instead be far-reaching, as in O’Cliance (District Court of Amsterdam, 14 November 2018, ECLI:NL:RBAMS:2018:10124), where the supplier was held liable for two thirds of the loss.
Can my own conduct reduce the compensation?
Yes. Contributory fault plays a recurring role in these cases. In O’Cliance one third of the loss remained for the customer’s account, and in the hacked email account case the parties were required to address the buyer’s contributory fault. Your own password policy, ports left open or warnings ignored can therefore feed directly into the outcome.
What fines can the data protection authority impose?
For infringements of the GDPR the supervisory authority can impose administrative fines of up to EUR 20 million or 4 per cent of worldwide annual turnover, whichever is higher. These fines are independent of whether individual data subjects actually suffered damage and therefore represent a separate risk alongside civil liability.
Can I report the offence and claim my loss through the criminal proceedings?
Yes. Article 138ab(1) of the Dutch Criminal Code makes it an offence to intentionally and unlawfully gain access to an automated system. You can report the offence to the police and, where a suspect is prosecuted, join the criminal proceedings as an injured party to claim compensation there. The outcome does depend on detection, prosecution and evidence, which with internationally operating offenders frequently yields no result.
What does cyber insurance typically cover?
Usually incident response and forensic investigation, restoration of systems and data, business interruption losses and lost turnover, crisis communication, liability towards third parties and legal costs, and in some cases fines, settlement payments or ransom to the extent insurable under the applicable law. Watch for exclusions, security conditions, notification periods and deductibles, and review the policy before an incident occurs.
Can I lose cover by acting incorrectly after an attack?
That is possible. Article 7:957(1) of the Dutch Civil Code obliges an insured party to take reasonable measures to prevent or limit loss; where that duty of salvage is not observed, the insurer may reduce the payout. Engaging external experts or paying a ransom without the insurer’s consent may also affect cover. Inform your insurer as quickly as possible.
What steps should I take immediately after a cyberattack?
Record the incident and all actions taken, isolate the affected systems without losing evidence, and engage a forensic expert. Then assess whether there is a notifiable data breach and whether the data subjects must be informed. Report the offence, notify your cyber insurer, preserve logs, backups and correspondence, map the damage and the potentially liable parties, and inform customers, employees and supply chain partners carefully and in good time.