Skip to content
Back to WikiDefinitions

What is a data breach

A data breach is any event where personal data is accessed, copied, lost, or altered without authorisation. Under the GDPR, a lost USB stick with customer records counts the same as a ransomware attack that exfiltrates two million records. Organisations established in the Netherlands must report qualifying breaches to the Autoriteit Persoonsgegevens within 72 hours of becoming aware, unless the breach is unlikely to create a risk for the people involved. When in doubt, report. Severity is assessed on the type of data, the number of people affected, and the likelihood of further misuse.

When an incident qualifies as a data breach

The GDPR defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. That language is broad on purpose. A stolen laptop with unencrypted customer files qualifies. So does an email sent to the wrong recipient, a misconfigured cloud bucket exposed to the public internet, or a ransomware group exfiltrating employee records before encrypting the servers.

Not every security incident is a data breach. A blocked phishing attempt is not. A successful brute-force login attempt on an account that holds no personal data is not. The test is whether personal data was, or is likely to have been, accessed, altered, or lost.

Immediate steps after discovery

Start the clock. The 72-hour notification window begins the moment your organisation becomes aware of a breach, not when investigation is complete. Contain first: isolate affected systems, revoke compromised credentials, preserve log data and disk images for forensic review. Do not wipe systems or reset them to a clean state before evidence is secured. Attackers often leave clues that point to the initial access vector, and a premature wipe destroys them.

Record every action with a timestamp. If a fine follows, the Autoriteit Persoonsgegevens asks for the timeline of the response, not just the outcome. For live incident support, SecDesk delivers [Incident response](/phishing-incident-response) with a senior responder on the line within two hours.

Reporting to the Autoriteit Persoonsgegevens

A breach must be reported to the Autoriteit Persoonsgegevens unless it is unlikely to result in a risk to the rights and freedoms of the people whose data was affected. Risk is assessed on the sensitivity of the data, the volume, the ease of identification, and the potential for downstream harm such as identity fraud or financial loss.

When the risk to individuals is high, those people must also be informed directly and in clear language. For a step-by-step walkthrough of the Dutch filing process, see our guide on [reporting a data breach in the Netherlands](/wiki/reporting-a-data-breach-netherlands).

What data may have been exposed

Start with the data categories present in the affected system. Customer records usually mean names, email addresses, phone numbers, postal addresses, and transaction history. Employee systems hold salary data, bank account numbers, BSN-equivalents, and performance records. Medical providers hold diagnoses, treatment plans, and insurance data, all of which qualify as special-category data under the GDPR and trigger stricter notification rules.

Attackers increasingly target backup systems and email archives because these contain years of accumulated data in one place. A breach of a single email archive can expose more sensitive data than a breach of a transactional database.

Preventing the next breach

Most breaches start with a known, fixable cause: a phished credential without multi-factor authentication, an unpatched public-facing server, or a misconfigured cloud resource. Closing those three gaps eliminates the majority of realistic attack paths. Maintain a tested backup strategy with offline copies, segment networks to limit lateral movement, and rehearse the incident response plan at least twice a year. For ongoing visibility into the gaps attackers would actually use, [threat exposure management](/threat-exposure-management) continuously maps the external attack surface and flags new weaknesses as they appear.

Discuss this with a senior responder.

Discuss this with a senior responder
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now