Dutch businesses face three cybersecurity duties that apply almost regardless of sector: keeping personal data secure, reporting breaches on time, and being able to show that both were done. Since 15 August 2026 a fourth duty has been added for around 8,000 designated organisations: the Cyberbeveiligingswet (Cbw), the Dutch implementation of the EU NIS2 directive.
What does the GDPR require for data security?
The GDPR requires appropriate technical and organisational measures to protect personal data, assessed against the state of the art, the cost of implementation and the risk to the people concerned. What is appropriate for a two-person practice is not what is appropriate for a company processing health data at scale, and the standard rises as the risk does.
In practice, the measures a supervisory authority expects to see are unremarkable: access control and multi-factor authentication, encryption of devices and backups, patching, segregation of environments, logging, and a tested restore procedure. What distinguishes an organisation that survives scrutiny is that these were documented and reviewed before anything went wrong.
When must a data breach be reported?
A personal data breach must be reported to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within seventy-two hours of becoming aware of it, unless it is unlikely to result in a risk to the people affected. Where the risk to them is high, those people must be informed as well, without undue delay.
Seventy-two hours is short, and the clock runs from awareness rather than from a completed investigation. That is why an incident procedure – who decides, who is called, what is recorded – is worth more than any single technical control. Every breach must be recorded internally, including those that are not reported to the regulator, together with the reasoning for that decision.
What does the Cyberbeveiligingswet add?
The Cyberbeveiligingswet and the related Wet weerbaarheid kritieke entiteiten entered into force on 15 August 2026, replacing the earlier network and information systems security rules. Organisations that fall within its scope – essential and important entities across sectors such as energy, transport, healthcare, digital infrastructure and public administration – must register with the authorities, take appropriate risk-management measures, and report significant incidents to the national CSIRT and their sector supervisor.
Management bodies carry personal accountability for approving and overseeing these measures; this cannot simply be delegated to an IT department. Financial institutions instead fall under their own EU operational resilience regime (DORA) rather than the Cyberbeveiligingswet.
How does this reach organisations outside the scope of the Cyberbeveiligingswet?
Even outside the designated sectors, the same standards tend to arrive contractually. Larger customers increasingly impose security requirements, audit rights and breach-notification periods in their contracts, and a processing agreement is compulsory whenever personal data are processed on someone else’s behalf. In practice, many Dutch companies first meet these standards because a counterparty demanded them, not because a regulator did.
Who can bring a claim after an incident?
An incident can produce claims from several directions at once: from the regulator, from individuals whose data were exposed, from customers under the contract, and increasingly through collective actions. Whether insurance responds depends on the policy wording and on whether the insurer can point to a failure to maintain the agreed measures – another reason to be able to evidence what was in place.
What should you do first?
Three things carry the most weight for the least effort: a written incident procedure that names people rather than roles; a current record of processing activities and of the processors you use; and a tested restore, because the difference between an incident and a catastrophe is usually whether the backups worked. If your organisation may fall within the scope of the Cyberbeveiligingswet, check your registration obligation without delay.
In summary
- The GDPR requires security measures matched to the state of the art and the risk involved, for every organisation that processes personal data.
- A data breach must normally be reported to the Autoriteit Persoonsgegevens within seventy-two hours of becoming aware of it.
- Since 15 August 2026, the Cyberbeveiligingswet adds registration, risk-management and incident-reporting duties for around 8,000 designated organisations, with personal accountability for management.
- Financial institutions fall under DORA rather than the Cyberbeveiligingswet.
- An incident can trigger claims from regulators, affected individuals, contractual counterparties and, increasingly, collective actions.
Advice
We advise on security and processing agreements, on breach notification and regulatory correspondence, on Cyberbeveiligingswet compliance, and on liability after an incident.
Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.
How Law & More can help you with this is explained on our IT lawyer page.


