Introduction
The information on this page relates to the website available under the domain harmjagerman.com and is owned by Harm Jagerman. Details of ownership of this website can be found in the colophon of this website (also known as the imprint).
A final motivation that justifies this protocol is the owner’s use of personal data.
For these reasons, a policy has been formulated to ensure the most appropriate action is taken if a data breach occurs.
Owner/administrator
The owner is also the administrator of the website. Therefore, both are equal in this case. From now on, only the word administrator is used.
1. Definition of data breach
A data breach occurs when a security breach occurs that accidentally or unlawfully results in the destruction, loss, alteration or the unauthorised disclosure of, or unauthorised access to, data transmitted, stored or otherwise processed.
2. Internal responsible
This website is owned by a Dutch company defined as Zelfstandige Zonder Personeel, ZZP. In English, it is self-employed without staff. This ensures that no separate person is appointed as internally responsible or internal manager.
3. Internal notification upon discovery of a data breach
See 2, because again, no internal notification will be made when a data breach is discovered.
If possible, remote erasure and/or inaccessibility of the leaked data will be ensured.
4. Research
The study consists of:
- Checking whether personal data has been lost.
- Checking whether personal data may be used unlawfully.
- Which systems are involved.
- Which processor is involved.
5. Fightin the data breach
Immediately after the data breach was identified, investigations began. The data breach will also be fought. Necessary measures will be taken to resolve and prevent this leak in the future.
6. Determination of consequences
The purpose of the investigation should lead to clarity on the (possible) consequences, the extent and the leaked data. It will also need to clarify what the adverse consequences may be for the data subjects.
7. Cooperation in data disclosure
The discoverer/notifier of the data breach offers full cooperation to the administrator by providing answers (in writing) to the following questions as soon as possible:
- What happened – A description of the incident – Did this incident occur accidentally or was it deliberate? Perhaps there was a hack or it was a matter of ‘trying something out’.
- When was this discovered – Date and time are necessary here. – What kind of data (records) were leaked? – Could the data be remotely deleted or made inaccessible and, if so, was this done?
- What are the possible adverse consequences for the data subjects?
- Which group(s) of persons were affected?
- How many persons are (approximately) affected by this?
- Were data of persons in other EU countries also affected by this data breach?
- Were technical and/or organisational measures already in place as a result of this incident?
8. Availability
It is possible that due to this data breach, the administrator’s availability will be reduced, as the data breach will be given increased priority.
9. Decision in case of data breach
Within sixty (60) hours of identifying a data breach, a decision on further steps to be taken will follow. It then becomes clear whether a report should be made to the Personal Data Authority or data subjects. In principle, a data leak is always reported to the Personal Data Authority, unless the data leak is unlikely to pose a risk to the rights and freedoms of data subjects. The data breach notification is accompanied by the answering of questions as described in part 7.have since been taken that have averted the high risk.
If a notification is made to the Personal Data Authority, it will be reported to the data subjects if it poses a high risk to the rights and freedoms of natural persons, unless appropriate measures have since been taken that have averted the high risk.
10. Data breach notification
The administrator shall make a notification to the Personal Data Authority/affected parties if necessary. This notification shall be made within 72 hours of a data breach occurring.
11. Consequences of data breach notification
If the data breach has adverse consequences for data subjects, the administrator will make every effort to minimise these consequences. Depending on the nature and extent of the data breach to the data subjects will be determined:
- In what way the data subjects are informed (including in any case the announcements as to what types of personal data are affected, what the possible consequences are, what measures are being or have been taken and what the data subjects themselves can do to prevent or limit damage).
- What aftercare the data subjects will receive.
- What actions are necessary in the interest of the organisation.
If the data breach has occurred – whether reported or not – adequate technical and/or organisational measures will be taken as soon as possible to prevent such data breaches in the future.
12. Maintain data breach register
The internal manager keeps a register of all data breaches, recording all details surrounding the data breach such as:
- A description of the incident.
- Date and time of the data breach.
- Date and time of discovery of the data breach.
- Description of the type of personal data leaked.
- Description of the category(ies) of data subjects affected.
- Description of several data subjects (approximate).
- Whether data of persons in other EU countries were also leaked.
- Whether the incident was reported to the Personal Data Authority and, if so, date and time of reporting.
- Whether the incident was reported to the data subjects and, if so, the date and time of notification.
- In what way data subjects were informed?
- The consequences of the data breach, stating the date and time if possible.
- Which technical and/or organisational measures were taken after the data breach, stating the date and time?
13. Update
Last update: March 11, 2025.