Cybersecurity obligations for Dutch businesses

Is the Netherlands Digitally Safe? Find Out Now

Dutch businesses face three cybersecurity duties that apply almost regardless of sector: keeping personal data secure, reporting breaches on time, and being able to show that both were done. Since 15 August 2026 a fourth duty has been added for around 8,000 designated organisations: the Cyberbeveiligingswet (Cbw), the Dutch implementation of the EU NIS2 directive.

What does the GDPR require for data security?

The GDPR requires appropriate technical and organisational measures to protect personal data, assessed against the state of the art, the cost of implementation and the risk to the people concerned. What is appropriate for a two-person practice is not what is appropriate for a company processing health data at scale, and the standard rises as the risk does.

In practice, the measures a supervisory authority expects to see are unremarkable: access control and multi-factor authentication, encryption of devices and backups, patching, segregation of environments, logging, and a tested restore procedure. What distinguishes an organisation that survives scrutiny is that these were documented and reviewed before anything went wrong.

When must a data breach be reported?

A personal data breach must be reported to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within seventy-two hours of becoming aware of it, unless it is unlikely to result in a risk to the people affected. Where the risk to them is high, those people must be informed as well, without undue delay.

Seventy-two hours is short, and the clock runs from awareness rather than from a completed investigation. That is why an incident procedure – who decides, who is called, what is recorded – is worth more than any single technical control. Every breach must be recorded internally, including those that are not reported to the regulator, together with the reasoning for that decision.

What does the Cyberbeveiligingswet add?

The Cyberbeveiligingswet and the related Wet weerbaarheid kritieke entiteiten entered into force on 15 August 2026, replacing the earlier network and information systems security rules. Organisations that fall within its scope – essential and important entities across sectors such as energy, transport, healthcare, digital infrastructure and public administration – must register with the authorities, take appropriate risk-management measures, and report significant incidents to the national CSIRT and their sector supervisor.

Management bodies carry personal accountability for approving and overseeing these measures; this cannot simply be delegated to an IT department. Financial institutions instead fall under their own EU operational resilience regime (DORA) rather than the Cyberbeveiligingswet.

How does this reach organisations outside the scope of the Cyberbeveiligingswet?

Even outside the designated sectors, the same standards tend to arrive contractually. Larger customers increasingly impose security requirements, audit rights and breach-notification periods in their contracts, and a processing agreement is compulsory whenever personal data are processed on someone else’s behalf. In practice, many Dutch companies first meet these standards because a counterparty demanded them, not because a regulator did.

Who can bring a claim after an incident?

An incident can produce claims from several directions at once: from the regulator, from individuals whose data were exposed, from customers under the contract, and increasingly through collective actions. Whether insurance responds depends on the policy wording and on whether the insurer can point to a failure to maintain the agreed measures – another reason to be able to evidence what was in place.

What should you do first?

Three things carry the most weight for the least effort: a written incident procedure that names people rather than roles; a current record of processing activities and of the processors you use; and a tested restore, because the difference between an incident and a catastrophe is usually whether the backups worked. If your organisation may fall within the scope of the Cyberbeveiligingswet, check your registration obligation without delay.

In summary

  • The GDPR requires security measures matched to the state of the art and the risk involved, for every organisation that processes personal data.
  • A data breach must normally be reported to the Autoriteit Persoonsgegevens within seventy-two hours of becoming aware of it.
  • Since 15 August 2026, the Cyberbeveiligingswet adds registration, risk-management and incident-reporting duties for around 8,000 designated organisations, with personal accountability for management.
  • Financial institutions fall under DORA rather than the Cyberbeveiligingswet.
  • An incident can trigger claims from regulators, affected individuals, contractual counterparties and, increasingly, collective actions.

Advice

We advise on security and processing agreements, on breach notification and regulatory correspondence, on Cyberbeveiligingswet compliance, and on liability after an incident.

Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.

How Law & More can help you with this is explained on our IT lawyer page.

Tom Meevis
Tom Meevis is an attorney-at-law at Law & More in Eindhoven and Amsterdam. He handles general practice and is the negotiator and litigator of the firm.

Need Legal Assistance?

Have you received a letter, a writ of summons or a judgment? Send us the documents. We will check which deadlines apply and what your options are.

This article provides general information and is not a substitute for advice on your specific situation.

Related articles

This article covers arbitral awards under the New York Convention. For court judgments, see our

Agile development calls for different contractual arrangements: best-efforts or results obligation, acceptance criteria, deadlines and

Almost every international company operating in the Netherlands buys computing capacity from someone else. The

When may you collect and reuse platform data? Database rights, copyright, contract, art. 138ab Dutch

The EU AI Act, Regulation (EU) 2024/1689, has applied in stages since it entered into

A photo of you online without permission can be removed under Dutch law by two

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.