Skip to Content
Pavan Geraedts
  • Practice
    • Working With Pavan Geraedts
    • Our Principles
    • About
    • FAQ
  • Services
    • Fiscal Advice
    • Juridical Advice
    • Digital, Data & IP
    • Company Structure & Governance
    • Transactions & Business Change
    • Business Mediation
  • Library
  • Academy
  • Contact
  • 0
  • 0
  • Nederlands English (US) Italiano
  • CLIENT AREA
Pavan Geraedts
  • 0
  • 0
    • Practice
      • Working With Pavan Geraedts
      • Our Principles
      • About
      • FAQ
    • Services
      • Fiscal Advice
      • Juridical Advice
      • Digital, Data & IP
      • Company Structure & Governance
      • Transactions & Business Change
      • Business Mediation
    • Library
    • Academy
    • Contact
  • Nederlands English (US) Italiano
  • CLIENT AREA
  • All Blogs
  • Compliance
  • When Privacy Sanctions Go Public, Small Mistakes Travel Much Further
  • When Privacy Sanctions Go Public, Small Mistakes Travel Much Further

    A new Dutch publication duty gives privacy enforcement a wider audience and makes everyday data controls a question of trust and business continuity.
    August 29, 2026 by
    Paolo Maria Pavan

    A new Dutch publication duty turns everyday data handling into a question of trust and continuity.

    A payroll administrator sends a wage file to an employee’s private address. One letter in the address is wrong. The message is recalled, the owner is informed, and everyone hopes the attachment remains unopened.

    This is how privacy trouble often enters a small company. Not through a dramatic attack, but through a rushed task inside an ordinary working day.

    The Dutch legal change deserves attention. The Verzamelwet gegevensbescherming, published in Staatsblad 2026, 154, inserts Article 21b into the Dutch GDPR implementation law. Once that provision takes effect, the Autoriteit Persoonsgegevens must publish decisions imposing administrative sanctions, subject to the disclosure limits in the Wet open overheid.

    The authority already publishes enforcement decisions under its existing policy. The new rule gives that practice a statutory basis. A sanction can therefore become part of the company’s public business history, alongside its accounts, ownership record and reputation with customers.

    The mistake is often inside the working day

    CBS figures put the usual cybersecurity story in a more useful frame. Among businesses with two or more workers, 7 percent experienced at least one internally caused cybersecurity incident in 2024. The figure for incidents caused by external attacks was 4 percent.

    CBS includes unintentional disclosure by an organisation’s own staff among the internal categories. These figures describe cybersecurity incidents. For a small employer, their practical message is straightforward: ordinary work creates a significant route to data exposure.

    Consider where personal data travels. Payroll exports go to advisers by email. Copies of identification documents sit in shared folders. Customer lists move into spreadsheets. Former workers keep access to software because nobody closed the account. Temporary managers receive broad permissions because there was no time to define a narrower role.

    None of this looks exceptional while the business is busy. Convenience slowly becomes the operating model.

    That makes public enforcement a governance signal, not merely a publicity issue. The central question is whether the company can explain who handled the data, why access was needed, where the information went and what happened after the problem was discovered.

    A sanction can interrupt more than cash

    Dutch administrative law distinguishes punitive sanctions from remedial sanctions. A remedial sanction can aim to end an infringement, prevent repetition or limit its consequences. In a privacy case, corrective action may reach directly into the process that keeps the company running.

    Payroll may need to be handled differently. Customer support access may have to change. Recruitment records may require review. A supplier connection may need to close while contracts, permissions and data transfers are examined.

    For a small employer, these processes rarely sit with separate teams. The owner, office manager and external adviser may carry most of them. If one system stops, invoices, wages or customer work can slow down in the same week that management must answer questions from staff and clients.

    The financial effect starts before any possible fine. Emergency support, delayed work, management time, customer communication and new system controls all carry a cost. A buyer, lender or major client may also ask whether the incident reveals a wider weakness.

    The payroll administrator in our opening scene needs more than reassurance. The company must establish which attachment was sent, who received it, whether it was opened, when management learned of the error and which decisions followed. Memory is a poor incident record when several people remember the sequence differently.

    Public visibility changes the trust conversation

    Under Article 21b, publication generally waits until ten working days have passed after the sanction decision was made known to the offender. Earlier publication is possible in specified circumstances. A request for preliminary relief suspends publication until the judge rules or the request is withdrawn.

    Those safeguards matter. The management lesson matters more. By the time publication is under discussion, the company needs a coherent account of its conduct. Access lists created after the incident, incomplete supplier records and uncertain deletion practices make that account harder to produce.

    Public visibility also changes who may care. An employee may wonder whether sickness or wage information was handled properly. A customer may ask which supplier received an export. An insurer may examine the company’s controls and response. A potential buyer may treat the event as a reason to inspect other records more closely.

    A published sanction does not automatically cause lasting commercial damage. Context matters. A business that can explain the problem, its response and its correction may preserve trust more effectively than one that hides behind a polished privacy statement.

    Insurance and control solve different problems

    CBS reported that 19 percent of businesses with two or more workers had cybersecurity insurance in 2025. Coverage was 7 percent among self-employed businesses and 46 percent among businesses with 250 or more workers. Construction, transport and storage, and hospitality each recorded 12 percent.

    Insurance may help with parts of an incident response, depending on the policy. It cannot decide who should have access to payroll, remove an old account or reconstruct a missing decision trail. Financial recovery, operational recovery and reputational recovery remain separate jobs.

    A useful small-business review can stay concrete. Look at payroll, absence records, customer exports, recruitment folders and supplier portals. Ask whether access still matches current roles. Check how departures are handled. See whether an incident could be reconstructed from records rather than hurried recollections.

    Give one person clear responsibility for coordinating the facts when something goes wrong. This does not require a privacy department around a ten-person company. It requires someone to ensure that a busy Tuesday afternoon does not leave the owner searching through mailboxes while customers, staff and regulators wait for an answer.

    Return to the payroll file. The wrong address may have been a single keystroke. The company’s response will reveal something larger: whether data handling is a collection of informal habits or a process the business can explain under pressure.

    Public enforcement gives ordinary privacy discipline a wider audience. The calm response is not fear or another policy document. It is a business that knows where its personal data goes, who can touch it and how it will account for its decisions when a small mistake travels further than expected.

    If your business needs a clearer view of its privacy controls and incident readiness, let us review the practical risks with you.

    DISCUSS YOUR PRIVACY CONTROLS

    The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.

    References

    • AVG-sancties vanaf 1 september verplicht openbaar · Salaris Vanmorgen
    • Wettenbank - Dutch data-protection enforcement powers
    • Wettenbank - Meaning of administrative sanctions
    • Wettenbank - Objection and interim court protection
    • CBS - Cyber incidents and data exposure at businesses
    • CBS - Internal causes, external attacks and data disclosure
    • CBS - Uneven cyber resilience and insurance cover
    • Wettenbank
    in Compliance
    # COMPLIANCE Dutch GDPR Privacy enforcement business continuity cybersecurity small business
    Paolo Maria Pavan August 29, 2026
    Share this post

    Share

    Tags
    COMPLIANCE Dutch GDPR Privacy enforcement business continuity cybersecurity small business
    Our blogs
    • Market Pulse
    • Ledger & Tax
    • Human Resources
    • Compliance
    • Governance
    • Real Estate

    Read Next
    A Customs Dispute Can Reach Your Cash Before Your Lawyer
    A Dutch customs dispute can become a cash-flow and governance problem when an importer cannot locate the declaration, evidence or responsible decision-maker.

    Upcoming Events

    Explore what’s happening next and join the moments that matter.

    See All
    Your Dynamic Snippet will be displayed here... This message is displayed because you did not provide enough options to retrieve its content.

    Pavan Geraedts Adviseurs

    Altroverso VOF trading as Pavan Geraedts Adviseurs. A boutique professional practice in Amersfoort for fiscal advice, juridical advice and business mediation.

    Chamber of Commerce: 56530021
    VAT: NL852171936B01
    BECON: 746393

    Complaints
    Email pg@altroverso.nl
    We acknowledge complaints as soon as possible and make reasonable efforts to find a satisfactory solution. Telephone and postal details are listed opposite.

    2012-2026 © Altroverso VOF
    All rights reserved.

    Practice

    About Pavan Geraedts
    Working With Pavan Geraedts
    Our Professional Principles
    Frequently Asked Questions
    Contact

    Areas of practice

    Fiscal Advice and Tax Matters
    Juridical Advice and Contracts
    Business Mediation
    Company Structure and Governance
    Digital, Data & IP
    Transactions & Business Change

    Knowledge and contact
    • Library
      Academy
      Client Area
    • Professional updates and invitations are shared with clients and contacts when they are relevant to the work of the practice.
    Pavan Geraedts
    • +31 (0)85 40 12 459

    • Rigaweg 9
    • 3825 PP Amersfoort
      The Netherlands
    Legal
    • Terms and Conditions
    • Privacy Manifesto
    • Cookie Policy
    • Salary and Employment Policy

    Your privacy matters.

    May this website use cookies in this browser?

    Essential cookies support the operation of the website. With your permission, additional cookies may be used to improve your experience. Further information is available in our Cookie Policy and change your choice later.

    Allow all cookiesAllow essential cookies only