Hollantilaisten yritysten kyberturvallisuusvelvoitteet

Onko Alankomaat digitaalisesti turvallista? Ota selvää nyt

Cybersecurity is no longer only a technical question for Dutch businesses; it is a set of legal duties with supervisors attached to them. Three obligations apply to almost every organisation, independently of sector: keeping personal data secure, reporting data breaches, and being able to show that both were done.

Henkilötietojen turvallisuus

The GDPR requires appropriate technical and organisational measures to protect personal data, assessed against the state of the art, the cost of implementation and the risk to the people concerned. What is appropriate for a two-person practice is not what is appropriate for a company processing health data at scale, and the standard rises as the risk does.

In practice the measures a supervisory authority expects to see are unremarkable: access control and multi-factor authentication, encryption of devices and backups, patching, segregation of environments, logging, and a tested restore procedure. What distinguishes an organisation that survives scrutiny is that these were documented and reviewed before anything went wrong.

Reporting a data breach

A personal data breach must be reported to the Dutch Data Protection Authority within seventy-two hours of becoming aware of it, unless it is unlikely to result in a risk to those affected. Where the risk to them is high, they must be informed as well, without undue delay.

Seventy-two hours is short, and the clock runs from awareness rather than from a completed investigation. That is why an incident procedure – who decides, who is called, what is recorded – is worth more than any single technical control. Every breach must be recorded internally, including those that are not reported, with the reasoning for that decision.

Sector obligations and the supply chain

Organisations in sectors designated as essential or important under the European network and information security framework face additional duties on risk management, incident reporting and management accountability as that framework is implemented in Dutch law. Financial institutions face their own operational resilience regime.

Even outside those sectors, the obligations arrive contractually. Larger customers now impose security requirements, audit rights and breach notification periods in their contracts, and a processing agreement is compulsory whenever personal data are processed on someone else’s behalf. In practice, most Dutch companies first meet these standards because a counterparty demanded them, not because a regulator did.

Liability after an incident

An incident can produce claims from several directions at once: from the regulator, from individuals whose data were exposed, from customers under the contract, and increasingly through collective actions. Whether insurance responds depends on the policy wording and on whether the insurer can point to a failure to maintain agreed measures – which is another reason to be able to evidence what was in place.

Mitä tehdä ensin

Three things carry the most weight for the least effort: a written incident procedure that names people rather than roles; a current record of processing activities and of the processors you use; and a tested restore, because the difference between an incident and a catastrophe is usually whether the backups worked.

Neuvot

We advise on security and processing agreements, on breach notification and regulatory correspondence, and on liability after an incident. Please contact Law & More.

Tarvitsetko oikeusapua?

Ota yhteyttä Law & More asiantuntevaa ohjausta oikeudellisissa asioissasi. Monikielinen tiimimme on valmiina auttamaan.

Liittyvät artikkelit

Työnantajan on pidettävä kirjaa työntekijöistään, ja samalla se voi vain

Kuusi Alankomaissa laillisesti merkityksellistä työpaikkakonfliktityyppiä ovat tehtävä, prosessi,

IT-lakimies auttaa yrityksiä IT-sopimusten, GDPR-vaatimustenmukaisuuden, tekoälylain, kyberturvallisuuden ja muiden asioiden kanssa.

Puolison elatusapu Alankomaissa päättyy lain nojalla, kun elatusapunsa saaja menee uudelleen naimisiin, tulee

EU-asetus 261/2004 antaa lentomatkustajille oikeuden apuun, hyvitykseen tai uudelleenreititykseen

Aloitussuunnitelmassa esitetään sijoituksen ehdot ennen lopullista

Pysy ajan tasalla Alankomaiden laista

Tilaa uutiskirjeemme saadaksesi uusimmat lakitiedot, sääntelypäivitykset ja käytännön neuvot.