What to do in the event of a data breach
A data breach has to be reported to the Dutch Data Protection Authority within 72 hours, but only where the breach is likely to result in a risk to the people whose data has leaked. That deadline starts running as soon as you become aware of the breach.
When someone calls us about a data breach, the first question is nearly always about those 72 hours. Understandable, because that is the number everyone remembers. Except it is not the start of the process, it is the end of it. First you need to know what actually happened.
A data breach means people have access to personal data when they shouldn’t, or when that was never the intention. It can come from a security failure, but just as easily from an email sent to the wrong address or a computer sold on without wiping the hard drive. In our practice that second category is by far the largest.
This is the order we work in.
Step 1: stop the breach
Make sure no further data leaks out. Revoke the access, take the file offline, block the account.
At the same time, record what you find and when you found it. It feels like a side issue at that moment, but you will badly need that timeline later.
Step 2: work out exactly what has leaked
Which data is involved, how many people does it concern, and how sensitive is it? A list of business email addresses is a different story from a file containing citizen service numbers or health data. This step determines everything that follows.
Step 3: assess the risk
If the breach is likely to result in a risk to the data subjects, you are required to report it to the Dutch Data Protection Authority within 72 hours. Factors that may play a part in that risk assessment are the following:
- the nature of the breach;
- the nature, sensitivity and volume of the personal data;
- the ease with which individuals can be identified;
- the severity of the consequences for those affected;
- characteristics of the unauthorised recipient;
- particular characteristics of the individual concerned;
- particular characteristics of your organisation;
- the number of people affected.
Those 72 hours start running as soon as you become aware of the breach, not once you have finished investigating. Still working it out? Report it anyway and supplement it later. Reporting late is a breach in itself, which is a shame when the incident you were reporting wasn’t all that serious to begin with.
Step 4: decide whether to inform those affected
If the breach is likely to result in a high risk to the people involved, you have to inform them as well. That is a higher threshold than the one for reporting to the regulator. In that message you explain in plain language what has happened, what the possible consequences are and what they can do themselves.
We regularly advise clients to inform people even when they are not obliged to. Customers who hear it from someone else tend to react a good deal more sharply than customers who hear it from you.
Step 5: record it in your data breach register
An organisation is required to draw up and maintain a data breach register. Every breach that has occurred within the organisation is recorded there. That can be a wrongly addressed email, a lost laptop full of personal data, or a hack or cyberattack.
Note that the register also covers the breaches you did not report. That is precisely where the regulator wants to see what you weighed up, and why.
And if your supplier causes the breach?
If an external party processes data on your instructions, that party has to report the breach to you. You then remain responsible for reporting it to the regulator. That comes as a surprise more often than you would think.
How quickly your supplier has to report and what they need to hand over should be set out in the data processing agreement. When we pull one of those agreements out after something has gone wrong, that clause turns out to be missing remarkably often.
Prevention is cheaper
Most breaches we see are not the result of a sophisticated attack. They happen because too many people can reach too much data. A tight authorisation policy helps against that, as does following the GDPR principles on data minimisation and retention periods. What you don’t keep cannot leak.
Need help?
We help with the risk assessment and advise on whether a breach needs to be reported to the Dutch Data Protection Authority. We can then make that report on your behalf. We also think through whether the people affected should be informed personally.
In the middle of one right now? Do get in touch, even if you don’t yet know how big it is. You can read more about our work on our page on privacy law.