A new Dutch publication duty turns everyday data handling into a question of trust and continuity.
A payroll administrator sends a wage file to an employee’s private address. One letter in the address is wrong. The message is recalled, the owner is informed, and everyone hopes the attachment remains unopened.
This is how privacy trouble often enters a small company. Not through a dramatic attack, but through a rushed task inside an ordinary working day.
The Dutch legal change deserves attention. The Verzamelwet gegevensbescherming, published in Staatsblad 2026, 154, inserts Article 21b into the Dutch GDPR implementation law. Once that provision takes effect, the Autoriteit Persoonsgegevens must publish decisions imposing administrative sanctions, subject to the disclosure limits in the Wet open overheid.
The authority already publishes enforcement decisions under its existing policy. The new rule gives that practice a statutory basis. A sanction can therefore become part of the company’s public business history, alongside its accounts, ownership record and reputation with customers.
The mistake is often inside the working day
CBS figures put the usual cybersecurity story in a more useful frame. Among businesses with two or more workers, 7 percent experienced at least one internally caused cybersecurity incident in 2024. The figure for incidents caused by external attacks was 4 percent.
CBS includes unintentional disclosure by an organisation’s own staff among the internal categories. These figures describe cybersecurity incidents. For a small employer, their practical message is straightforward: ordinary work creates a significant route to data exposure.
Consider where personal data travels. Payroll exports go to advisers by email. Copies of identification documents sit in shared folders. Customer lists move into spreadsheets. Former workers keep access to software because nobody closed the account. Temporary managers receive broad permissions because there was no time to define a narrower role.
None of this looks exceptional while the business is busy. Convenience slowly becomes the operating model.
That makes public enforcement a governance signal, not merely a publicity issue. The central question is whether the company can explain who handled the data, why access was needed, where the information went and what happened after the problem was discovered.
A sanction can interrupt more than cash
Dutch administrative law distinguishes punitive sanctions from remedial sanctions. A remedial sanction can aim to end an infringement, prevent repetition or limit its consequences. In a privacy case, corrective action may reach directly into the process that keeps the company running.
Payroll may need to be handled differently. Customer support access may have to change. Recruitment records may require review. A supplier connection may need to close while contracts, permissions and data transfers are examined.
For a small employer, these processes rarely sit with separate teams. The owner, office manager and external adviser may carry most of them. If one system stops, invoices, wages or customer work can slow down in the same week that management must answer questions from staff and clients.
The financial effect starts before any possible fine. Emergency support, delayed work, management time, customer communication and new system controls all carry a cost. A buyer, lender or major client may also ask whether the incident reveals a wider weakness.
The payroll administrator in our opening scene needs more than reassurance. The company must establish which attachment was sent, who received it, whether it was opened, when management learned of the error and which decisions followed. Memory is a poor incident record when several people remember the sequence differently.
Public visibility changes the trust conversation
Under Article 21b, publication generally waits until ten working days have passed after the sanction decision was made known to the offender. Earlier publication is possible in specified circumstances. A request for preliminary relief suspends publication until the judge rules or the request is withdrawn.
Those safeguards matter. The management lesson matters more. By the time publication is under discussion, the company needs a coherent account of its conduct. Access lists created after the incident, incomplete supplier records and uncertain deletion practices make that account harder to produce.
Public visibility also changes who may care. An employee may wonder whether sickness or wage information was handled properly. A customer may ask which supplier received an export. An insurer may examine the company’s controls and response. A potential buyer may treat the event as a reason to inspect other records more closely.
A published sanction does not automatically cause lasting commercial damage. Context matters. A business that can explain the problem, its response and its correction may preserve trust more effectively than one that hides behind a polished privacy statement.
Insurance and control solve different problems
CBS reported that 19 percent of businesses with two or more workers had cybersecurity insurance in 2025. Coverage was 7 percent among self-employed businesses and 46 percent among businesses with 250 or more workers. Construction, transport and storage, and hospitality each recorded 12 percent.
Insurance may help with parts of an incident response, depending on the policy. It cannot decide who should have access to payroll, remove an old account or reconstruct a missing decision trail. Financial recovery, operational recovery and reputational recovery remain separate jobs.
A useful small-business review can stay concrete. Look at payroll, absence records, customer exports, recruitment folders and supplier portals. Ask whether access still matches current roles. Check how departures are handled. See whether an incident could be reconstructed from records rather than hurried recollections.
Give one person clear responsibility for coordinating the facts when something goes wrong. This does not require a privacy department around a ten-person company. It requires someone to ensure that a busy Tuesday afternoon does not leave the owner searching through mailboxes while customers, staff and regulators wait for an answer.
Return to the payroll file. The wrong address may have been a single keystroke. The company’s response will reveal something larger: whether data handling is a collection of informal habits or a process the business can explain under pressure.
Public enforcement gives ordinary privacy discipline a wider audience. The calm response is not fear or another policy document. It is a business that knows where its personal data goes, who can touch it and how it will account for its decisions when a small mistake travels further than expected.
If your business needs a clearer view of its privacy controls and incident readiness, let us review the practical risks with you.
The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.
References
- AVG-sancties vanaf 1 september verplicht openbaar · Salaris Vanmorgen
- Wettenbank - Dutch data-protection enforcement powers
- Wettenbank - Meaning of administrative sanctions
- Wettenbank - Objection and interim court protection
- CBS - Cyber incidents and data exposure at businesses
- CBS - Internal causes, external attacks and data disclosure
- CBS - Uneven cyber resilience and insurance cover
- Wettenbank
