Cybersecurity obligations for Dutch businesses

Is the Netherlands Digitally Safe? Find Out Now

Cybersecurity is no longer only a technical question for Dutch businesses; it is a set of legal duties with supervisors attached to them. Three obligations apply to almost every organisation, independently of sector: keeping personal data secure, reporting data breaches, and being able to show that both were done.

Security of personal data

The GDPR requires appropriate technical and organisational measures to protect personal data, assessed against the state of the art, the cost of implementation and the risk to the people concerned. What is appropriate for a two-person practice is not what is appropriate for a company processing health data at scale, and the standard rises as the risk does.

In practice the measures a supervisory authority expects to see are unremarkable: access control and multi-factor authentication, encryption of devices and backups, patching, segregation of environments, logging, and a tested restore procedure. What distinguishes an organisation that survives scrutiny is that these were documented and reviewed before anything went wrong.

Reporting a data breach

A personal data breach must be reported to the Dutch Data Protection Authority within seventy-two hours of becoming aware of it, unless it is unlikely to result in a risk to those affected. Where the risk to them is high, they must be informed as well, without undue delay.

Seventy-two hours is short, and the clock runs from awareness rather than from a completed investigation. That is why an incident procedure – who decides, who is called, what is recorded – is worth more than any single technical control. Every breach must be recorded internally, including those that are not reported, with the reasoning for that decision.

Sector obligations and the supply chain

Organisations in sectors designated as essential or important under the European network and information security framework face additional duties on risk management, incident reporting and management accountability as that framework is implemented in Dutch law. Financial institutions face their own operational resilience regime.

Even outside those sectors, the obligations arrive contractually. Larger customers now impose security requirements, audit rights and breach notification periods in their contracts, and a processing agreement is compulsory whenever personal data are processed on someone else’s behalf. In practice, most Dutch companies first meet these standards because a counterparty demanded them, not because a regulator did.

Liability after an incident

An incident can produce claims from several directions at once: from the regulator, from individuals whose data were exposed, from customers under the contract, and increasingly through collective actions. Whether insurance responds depends on the policy wording and on whether the insurer can point to a failure to maintain agreed measures – which is another reason to be able to evidence what was in place.

What to do first

Three things carry the most weight for the least effort: a written incident procedure that names people rather than roles; a current record of processing activities and of the processors you use; and a tested restore, because the difference between an incident and a catastrophe is usually whether the backups worked.

Advice

We advise on security and processing agreements, on breach notification and regulatory correspondence, and on liability after an incident. Please contact Law & More.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

Facing a conviction can impact family and divorce. Discover your appeal options in the Netherlands

A decentralised autonomous organisation has no legal form of its own under Dutch law. Book

AI tools like ChatGPT and DALL-E can create text, images, and other content in seconds.

The Autoriteit Persoonsgegevens (AP) is the Dutch Data Protection Authority: the independent supervisory authority that

An employer must keep records of its employees, and at the same time may only

Under Dutch and EU law nobody owns data as such, so the data clause in

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.