Data breach notification protocol

Introduction

The information on this page relates to the website available under the domain harmjagerman.com and is owned by Harm Jagerman. Details of ownership of this website can be found in the colophon of this website (also known as the imprint).

No rights can be derived from this protocol.
This protocol is in place because the website owner considers it important that there is openness about how to proceed during and after a data breach. In addition, the owner wants to comply with the legal requirements in this area as they apply. This is based on European legislation (General Data Protection Regulation (GDPR)). This is so because the owner is based within the European Union and this is leading. It does not (otherwise) matter where the visitor comes from.
Furthermore, the owner respects local, Dutch provisions, as observed and enforced by the Autoriteit Persoonsgegevens (Personal Data Authority).

A final motivation that justifies this protocol is the owner’s use of personal data.

For these reasons, a policy has been formulated to ensure the most appropriate action is taken if a data breach occurs.

Owner/administrator

The owner is also the administrator of the website. Therefore, both are equal in this case. From now on, only the word administrator is used.

1. Definition of data breach

A data breach occurs when a security breach occurs that accidentally or unlawfully results in the destruction, loss, alteration or the unauthorised disclosure of, or unauthorised access to, data transmitted, stored or otherwise processed.

2. Internal responsible

This website is owned by a Dutch company defined as Zelfstandige Zonder Personeel, ZZP. In English, it is self-employed without staff. This ensures that no separate person is appointed as internally responsible or internal manager.

3. Internal notification upon discovery of a data breach

See 2, because again, no internal notification will be made when a data breach is discovered.

If possible, remote erasure and/or inaccessibility of the leaked data will be ensured.

4. Research

The study consists of:

5. Fightin the data breach

Immediately after the data breach was identified, investigations began. The data breach will also be fought. Necessary measures will be taken to resolve and prevent this leak in the future.

6. Determination of consequences

The purpose of the investigation should lead to clarity on the (possible) consequences, the extent and the leaked data. It will also need to clarify what the adverse consequences may be for the data subjects.

7. Cooperation in data disclosure

The discoverer/notifier of the data breach offers full cooperation to the administrator by providing answers (in writing) to the following questions as soon as possible:

  • What happened – A description of the incident – Did this incident occur accidentally or was it deliberate? Perhaps there was a hack or it was a matter of ‘trying something out’.
  • When was this discovered – Date and time are necessary here. – What kind of data (records) were leaked? – Could the data be remotely deleted or made inaccessible and, if so, was this done?
  • What are the possible adverse consequences for the data subjects?
  • Which group(s) of persons were affected?
  • How many persons are (approximately) affected by this?
  • Were data of persons in other EU countries also affected by this data breach?
  • Were technical and/or organisational measures already in place as a result of this incident?

8. Availability

It is possible that due to this data breach, the administrator’s availability will be reduced, as the data breach will be given increased priority.

9. Decision in case of data breach

Within sixty (60) hours of identifying a data breach, a decision on further steps to be taken will follow. It then becomes clear whether a report should be made to the Personal Data Authority or data subjects. In principle, a data leak is always reported to the Personal Data Authority, unless the data leak is unlikely to pose a risk to the rights and freedoms of data subjects. The data breach notification is accompanied by the answering of questions as described in part 7.have since been taken that have averted the high risk.

If a notification is made to the Personal Data Authority, it will be reported to the data subjects if it poses a high risk to the rights and freedoms of natural persons, unless appropriate measures have since been taken that have averted the high risk.

10. Data breach notification

The administrator shall make a notification to the Personal Data Authority/affected parties if necessary. This notification shall be made within 72 hours of a data breach occurring.

11. Consequences of data breach notification

If the data breach has adverse consequences for data subjects, the administrator will make every effort to minimise these consequences. Depending on the nature and extent of the data breach to the data subjects will be determined:

  • In what way the data subjects are informed (including in any case the announcements as to what types of personal data are affected, what the possible consequences are, what measures are being or have been taken and what the data subjects themselves can do to prevent or limit damage).
  • What aftercare the data subjects will receive.
  • What actions are necessary in the interest of the organisation.

If the data breach has occurred – whether reported or not – adequate technical and/or organisational measures will be taken as soon as possible to prevent such data breaches in the future.

12. Maintain data breach register

The internal manager keeps a register of all data breaches, recording all details surrounding the data breach such as:

  • A description of the incident.
  • Date and time of the data breach.
  • Date and time of discovery of the data breach.
  • Description of the type of personal data leaked.
  • Description of the category(ies) of data subjects affected.
  • Description of several data subjects (approximate).
  • Whether data of persons in other EU countries were also leaked.
  • Whether the incident was reported to the Personal Data Authority and, if so, date and time of reporting.
  • Whether the incident was reported to the data subjects and, if so, the date and time of notification.
  • In what way data subjects were informed?
  • The consequences of the data breach, stating the date and time if possible.
  • Which technical and/or organisational measures were taken after the data breach, stating the date and time?

13. Update

Last update: March 11, 2025.

Skip to content