03 – 09 – 2025 Following the NOS report of 11 August 2025, public concern arose regarding the data breach involving the personal data of nearly one million women who participated in the national cervical cancer screening program conducted by Bevolkingsonderzoek Nederland. It became known that the laboratory Clinical Diagnostics had fallen victim to a hack. The data breach involves highly sensitive information, including medical test results and citizen service numbers (BSN). Part of the data has already been found on the dark web. According to the NOS report of 27 August, in addition to the investigation by the Dutch Data Protection Authority (AP), the Public Prosecution Service (Openbaar Ministerie) and the police have also launched a criminal investigation into the breach.

Data breaches can lead to targeted phishing attacks, identity fraud, or blackmail. Besides the direct consequences for the individuals affected, an incident of this scale also raises questions and concerns about the protection of personal data in healthcare. The incident at Bevolkingsonderzoek Nederland highlights the importance of being well-prepared for a data breach. Transparent communication, swift action, and clear processes make all the difference in limiting damage. Both for the privacy of your customers, patients, employees, and other stakeholders, as well as for your own organization(s).

What can your organization do in the event of a data breach?

A data breach can happen to any organization. Acting quickly and carefully helps reduce the impact and ensures compliance with legal obligations. Key points to consider:

  • Limit the damage: contain the breach and take measures such as blocking accounts, deleting files, or wiping devices. In complex incidents, such as ransomware attacks, additional forensic research may be needed to assess the scope and impact.
  • Create an overview: identify what happened: when did the breach occur and when was it discovered, which personal data is involved, how many individuals are affected, and what are the risks?
  • Report and inform: if required, the breach must be reported to the Dutch Data Protection Authority within 72 hours. In some cases, customers, patients, or other affected parties must also be informed so they can take their own protective measures.
  • Register: record all breaches in an internal incident register. This helps your organization learn from incidents and demonstrates due diligence.

Stay up to date with legal developments

Case law on data breaches and information security is evolving rapidly. A recent ruling offers important lessons for organizations processing personal data. The Arnhem-Leeuwarden Court of Appeal ruled that an organization can be held liable for damage caused by a hack, even when IT security was outsourced to an ISO 27001-certified supplier. This means that certification alone does not provide a free pass. Data controllers must be able to concretely demonstrate which security measures have been implemented. This requires due diligence when selecting vendors as well as clear contractual agreements.

How Considerati can support your organization

While data breaches can never be fully prevented, organizations can prepare effectively. Our team can support you with:

  • Prevention: our specialized privacy consultants help identify where (sensitive) personal data is located (data mapping), conduct risk assessments, and support in drafting solid (contractual) agreements with vendors.
  • Analysis, response & recovery: Considerati assists in analyzing incidents, reporting to and liaising with the Dutch Data Protection Authority and affected individuals where necessary. We also help draft incident response plans and provide training on how to recognize data breaches, including practical “data breach exercises” to ensure staff are well-prepared.
  • Communication: transparent and timely communication during a breach can positively influence stakeholder trust and limit reputational damage. Considerati provides advice and support in crisis communication towards customers, partners, and the media.

We believe that good preparation and clear processes are essential in mitigating the consequences of data breaches.

Joost van Kleef Legal Consultant

Would you like to know how your organization can be better prepared?

We would be happy to think along with you.

Interested in our Data Protection Officer (DPO) as a Service, or do you need support in setting up a data breach procedure or training? Feel free to contact us.

Our services orContact