Breach notification requirements in the Netherlands
Dutch organisations must report a qualifying personal data breach to the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, under article 33 of the GDPR. If the breach is likely to create a high risk to the rights and freedoms of the people affected, those people must also be informed directly, in clear language, under article 34. Not every breach needs a filing: if the data was effectively anonymised or encrypted with a key the attacker cannot access, and the breach is unlikely to create risk, the filing may be omitted. Organisations in scope of NIS2 (implemented in the Netherlands as the Cyberbeveiligingswet, Cbw) and sector-specific regulations face additional notification duties to their sector supervisor and the NCSC.
The 72-hour rule
The 72-hour clock starts when your organisation becomes aware that a breach has occurred, not when investigation is complete. Awareness means a reasonable degree of certainty that a security incident leading to the compromise of personal data has taken place. A forwarded suspicious email is not awareness. A confirmed unauthorised login to a mailbox containing personal data is.
If the initial filing is incomplete because investigation is ongoing, the Autoriteit Persoonsgegevens accepts a staged notification: file within 72 hours with the facts known, and supplement the filing as investigation produces more detail. Missing the window entirely is the more serious failure.
Who must file
The data controller files the notification. If a processor (for example, a cloud provider or an outsourced payroll company) detects the breach, they must notify the controller without undue delay, and the controller then files with the Autoriteit Persoonsgegevens. The processor does not file directly, even if they detected the incident.
For joint controllers, the agreement between them should specify which party takes the lead. In the absence of such an agreement, both parties remain responsible.
When affected individuals must be told
If the breach is likely to result in a high risk to the rights and freedoms of individuals, those people must also be informed directly, in clear and plain language, as soon as reasonably possible. High risk typically means the data enables identity fraud, financial loss, discrimination, reputational damage, or physical harm.
Notification to individuals can be omitted if the data was encrypted or anonymised effectively, if subsequent measures have neutralised the risk, or if individual notification would require disproportionate effort (in which case a public communication is acceptable instead). For the practical filing process, see our guide on [reporting a data breach in the Netherlands](/wiki/reporting-a-data-breach-netherlands).
Documentation requirements
Every breach, whether notified to the Autoriteit Persoonsgegevens or not, must be documented internally. The register includes the facts of the incident, its effects, and the remedial actions taken. The Autoriteit Persoonsgegevens can request this register during an audit or investigation, and a missing or incomplete register is itself a GDPR violation.
Documentation covers the timeline (detection, confirmation, containment, filing), the categories and approximate number of records affected, the likely consequences, and the measures taken. Start the register from the first moment of suspected breach, not after the dust settles.
NIS2 and sector-specific duties
Organisations classified as essential or important entities under NIS2, in the Netherlands implemented as the Cyberbeveiligingswet (Cbw) (energy, healthcare, digital infrastructure, transport, financial markets, and others) must report significant incidents to their sector supervisor and the NCSC, in addition to the Autoriteit Persoonsgegevens filing if personal data is involved. Initial notification is within 24 hours of awareness, a detailed report within 72 hours, and a final report within one month.
Financial sector firms have additional obligations under DORA. Healthcare providers have sector rules under the Wegiz. Organisations in scope should map all applicable notification duties in advance so that a live incident does not trigger a frantic regulatory inventory.
Discuss this with a senior responder.
Discuss this with a senior responderNeed incident response?
- Two-hour SLA
- Dutch senior responders