How to: Handle data breaches

How to: Handle data breaches

This 'How to' applies to data breaches in the Netherlands based on Dutch law Netherlands Flag


Introduction

Our  Information Security policy for employees  asks all colleagues to be alert to potential incidents and report them as soon as possible. This guide is intended for the person handling the reports.
What is a data breach?
The Dutch Data Protection Authority (AP) considers a  data breach  to occur when personal data is accessed without authorisation or without that being the intention, where the cause is a breach of the security of that data. Unintentionally destroying, losing, altering, or disclosing personal data as a result of such a breach also falls under the definition of a data breach.
Examples of data breaches:
  • Loss of a USB stick
  • Theft of a laptop
  • Intrusion by a hacker
  • Accidentally publishing personal data
  • Hacking, malware, or phishing
  • Personal data sent to the wrong person
  • Disasters such as a fire in a data centre

Reporting obligations

Two mandatory notifications may apply:
    Dutch Data Protection Authority (Autoriteit Persoonsgegevens): Report within 72 hours of discovery, unless it is unlikely the breach poses a risk to the rights and freedoms of those involved. (see  AP: meldplicht datalekken )
    Those affected: Notify them if the breach is likely to pose a high risk to their rights and freedoms. Follow the  AP's communication guidance  on how.
Document every decision, including the decision not to report.


Handling reported data breaches step-by-step

Step
Action
Responsible roles
Step 1: Assess the breach
  • Assess the nature of the leaked data, e.g.:
  • (special) personal data?
  • Passwords?
  • Data about financial situation or data that could be used for abuse?
  • Health data?
  • Assess the scale of the breach: how much data is involved?
  • Assess the potential impact on the individuals concerned.
  • Establish what the adverse consequences may be.
  • Assess the other factors  listed on the website of the Data Protection Authority.  
  • Determine who needs to be involved in handling the breach (within the organisation + any data processors).
IT lead + possibly:
  • Lead of the team within which the breach occurred.
  • For larger breaches: at least 1 board member.
Step 2: Limit consequences
  • Stop the breach if still possible.
  • Implement measures to limit the breach and the resulting damage.
Same as above.
Step 3: Report the breach to the Data Protection Authority
  • Determine  whether or not the breach must be reported to the Data Protection Authority  and document this consideration.
  • If it is decided to notify the Data Protection Authority, this must be done within 72 hours of discovering the breach.
  • Report via the  Data Breach Notification Form  of the Data Protection Authority.
  • More information on reporting data breaches can be found on the  website of the Data Protection Authority. 
  • Same as above + possibly: Communications officer.
Step 4: Notify data subjects
  • Determine whether or not the breach must be reported to the individuals concerned and document this consideration.
  • Inform the individuals concerned, following the  communication tips from the Data Protection Authority.  
  • Determine follow-up care actions for those involved.
Same as above + possibly:
  • Communications officer.
Step 5: Evaluate & improve
  • Evaluate how the handling of the breach went, identify lessons that can be learned, and document these.
  • Determine actions for improving security, log and implement them.
All colleagues who were involved in the preceding steps.

Scenario runbooks

Laptop theft or loss

Theft or loss of a laptop is almost always a data breach: laptops typically contain personal data or provide access to systems.
Step 1: Take the report. Note the reporter's name and role, date and time of discovery, last known location of the device, and whether it was theft or loss. Check whether the laptop was encrypted and had a strong password — verify in your device security overview.
Step 2: Take immediate technical action. An admin with access to your identity provider and password manager (see your authorization matrix) must:
  • Change passwords and invalidate active sessions for the affected team member (including their Google or Microsoft account).
  • Check login logs of critical systems (database, website, payment processor) for suspicious activity from the stolen device.
Step 3: Assess the data breach risk. Answer the following together with the reporter:
  • Was personal data stored locally on the laptop?
  • Was the hard drive fully encrypted (BitLocker or FileVault)?
  • Did the laptop have a strong password and automatic screen lock enabled?
  • Is there any indication that someone actually accessed the data?
A fully encrypted device with no signs of unauthorized access lowers the risk of a reportable breach — but the situation must still be documented. Continue with the general procedure above.
Step 4: File a police report (theft only). Advise the reporter to file a police report as soon as possible. Request a copy of the official report for the file. For loss, a police report is not required but can be useful for insurance purposes.


Phishing

A phishing incident may lead to unauthorized system access and therefore to a data breach. Handle it immediately. Two situations apply.
Situation A: the reporter recognized the phishing and did not respond.
Likely no data breach, but still take these steps:
  • Remove the phishing email from the reporter's mailbox and check whether other team members received the same message.
  • Block the sender address and the phishing link in your email system where possible.
  • Document the incident (date, reporter, nature of the email).
Situation B: the reporter clicked or entered credentials.
Treat this as a serious incident. Involve the IT lead immediately:
  • Change all passwords that may have been intercepted, including email and business systems.
  • Invalidate active sessions across all systems for the affected team member.
  • If an attachment was opened: run a virus scan on the device.
  • Check login and activity logs for suspicious access after the moment of phishing.
Continue with the general procedure above for breach assessment, AP notification, and communication to those affected.


Accidental sharing of personal data

Sending personal data to the wrong person (a misdirected email, a wrong attachment, a document shared with the wrong permissions) is a data breach under the AVG.
Step 1: Take the report. Note what was shared (which document, which data), with whom, via which channel (email, file sharing, post), and when. Ask whether the recipient has already viewed or confirmed receipt of the data.
Step 2: Contain the spread.
  • Contact the recipient and request deletion of the data and no further sharing. Confirm this request in writing.
  • For a shared file (e.g. Google Drive): revoke access immediately.
  • For email: use a recall function if available, but do not assume it will succeed.
Step 3: Assess and follow the general procedure. Consider: how sensitive were the data (ordinary or special category), how many people are affected, and who the recipient is (known contact, unknown third party, or competitor). The more sensitive the data and the less known the recipient, the greater the risk and the more likely a reporting obligation applies. Continue with the general procedure above.