A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Not every incident has to be notified, but you must be able to demonstrate how you reached that conclusion.
Legal basis
The definition is in Article 4(12) GDPR. Article 33 requires the controller to notify the Dutch Data Protection Authority without undue delay and at the latest within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to the rights and freedoms of individuals. Article 34 adds a duty to inform the individuals themselves where the risk is high. Processors do not notify the regulator but the controller, and must do so without delay. Article 33(5) requires a register of all breaches, including those that were not notified.
How it works in practice
The 72 hours start once you have reasonable certainty that a security incident involving personal data has occurred, not when the investigation is complete. Notification may therefore be made in stages: first what you know, then the additions. The assessment turns on the consequences for the individual: does it involve special category data, combinations that enable identity fraud, large numbers, or people in a vulnerable position? A lost laptop with an encrypted disk is usually not notifiable; a misaddressed mailing containing health data almost always is.
Where it goes wrong
Most enforcement concerns the aftermath rather than the breach itself. Organisations notify late because they first want to establish internally who is at fault, or they skip informing the individuals for fear of reputational damage even though the risk was high enough. A third pitfall is the missing internal register: without it you cannot substantiate why an incident was not notified, and your assessment simply does not count.
Related terms
A breach connects directly to the data processing agreement, which should state your supplier’s reporting deadline, and to the Dutch Cybersecurity Act, which imposes its own shorter deadline on certain sectors.
Unsure whether an incident must be notified? Our IT law specialists will assess it with you, including within the 72-hour window.

