This 'How to' applies to data breaches in the Netherlands based on Dutch law
Introduction
Our Information Security policy for employees asks all colleagues to be alert to potential incidents and report them as soon as possible. This guide is intended for the person handling the reports.
What is a data breach?
The Dutch Data Protection Authority (AP) considers a data breach to occur when personal data is accessed without authorisation or without that being the intention, where the cause is a breach of the security of that data. Unintentionally destroying, losing, altering, or disclosing personal data as a result of such a breach also falls under the definition of a data breach.
Examples of data breaches:
Loss of a USB stick
Theft of a laptop
Intrusion by a hacker
Accidentally publishing personal data
Hacking, malware, or phishing
Personal data sent to the wrong person
Disasters such as a fire in a data centre
Reporting obligations
Two mandatory notifications may apply:
Dutch Data Protection Authority (Autoriteit Persoonsgegevens): Report within 72 hours of discovery, unless it is unlikely the breach poses a risk to the rights and freedoms of those involved. (see AP: meldplicht datalekken)
Those affected: Notify them if the breach is likely to pose a high risk to their rights and freedoms. Follow the AP's communication guidance on how.
Document every decision, including the decision not to report.
Handling reported data breaches step-by-step
Step
Action
Responsible roles
Step 1: Assess the breach
Assess the nature of the leaked data, e.g.:
(special) personal data?
Passwords?
Data about financial situation or data that could be used for abuse?
Health data?
Assess the scale of the breach: how much data is involved?
Assess the potential impact on the individuals concerned.
Determine follow-up care actions for those involved.
Same as above + possibly:
Communications officer.
Step 5: Evaluate & improve
Evaluate how the handling of the breach went, identify lessons that can be learned, and document these.
Determine actions for improving security, log and implement them.
All colleagues who were involved in the preceding steps.
Scenario runbooks
Laptop theft or loss
Theft or loss of a laptop is almost always a data breach: laptops typically contain personal data or provide access to systems.
Step 1: Take the report. Note the reporter's name and role, date and time of discovery, last known location of the device, and whether it was theft or loss. Check whether the laptop was encrypted and had a strong password — verify in your device security overview.
Step 2: Take immediate technical action. An admin with access to your identity provider and password manager (see your authorization matrix) must:
Change passwords and invalidate active sessions for the affected team member (including their Google or Microsoft account).
Check login logs of critical systems (database, website, payment processor) for suspicious activity from the stolen device.
Step 3: Assess the data breach risk. Answer the following together with the reporter:
Was personal data stored locally on the laptop?
Was the hard drive fully encrypted (BitLocker or FileVault)?
Did the laptop have a strong password and automatic screen lock enabled?
Is there any indication that someone actually accessed the data?
A fully encrypted device with no signs of unauthorized access lowers the risk of a reportable breach — but the situation must still be documented. Continue with the general procedure above.
Step 4: File a police report (theft only). Advise the reporter to file a police report as soon as possible. Request a copy of the official report for the file. For loss, a police report is not required but can be useful for insurance purposes.
Phishing
A phishing incident may lead to unauthorized system access and therefore to a data breach. Handle it immediately. Two situations apply.
Situation A: the reporter recognized the phishing and did not respond.
Likely no data breach, but still take these steps:
Remove the phishing email from the reporter's mailbox and check whether other team members received the same message.
Block the sender address and the phishing link in your email system where possible.
Document the incident (date, reporter, nature of the email).
Situation B: the reporter clicked or entered credentials.
Treat this as a serious incident. Involve the IT lead immediately:
Change all passwords that may have been intercepted, including email and business systems.
Invalidate active sessions across all systems for the affected team member.
If an attachment was opened: run a virus scan on the device.
Check login and activity logs for suspicious access after the moment of phishing.
Continue with the general procedure above for breach assessment, AP notification, and communication to those affected.
Accidental sharing of personal data
Sending personal data to the wrong person (a misdirected email, a wrong attachment, a document shared with the wrong permissions) is a data breach under the AVG.
Step 1: Take the report. Note what was shared (which document, which data), with whom, via which channel (email, file sharing, post), and when. Ask whether the recipient has already viewed or confirmed receipt of the data.
Step 2: Contain the spread.
Contact the recipient and request deletion of the data and no further sharing. Confirm this request in writing.
For a shared file (e.g. Google Drive): revoke access immediately.
For email: use a recall function if available, but do not assume it will succeed.
Step 3: Assess and follow the general procedure. Consider: how sensitive were the data (ordinary or special category), how many people are affected, and who the recipient is (known contact, unknown third party, or competitor). The more sensitive the data and the less known the recipient, the greater the risk and the more likely a reporting obligation applies. Continue with the general procedure above.