Articles

Dutch Data Protection Authority increases maximum fine for data breaches committed by telecom providers

Dutch Data Protection Authority increases maximum fine for data breaches committed by telecom providers

Dutch Data Protection Authority increases maximum fine for data breaches committed by telecom providers

13.10.2016

The Dutch Data Protection Authority (“DPA”) has amended its Penalty Policy Rules under an amendment of the Dutch Telecommunication Act. The new rules apply as from 1 July 2016.

Previously, the DPA could impose an administrative fine up to a maximum of EUR 450,000 if a telecom provider did not (immediately) notify the DPA of a data breach in accordance with Article 11.3(a) of the Dutch Telecommunication Act. This fine’s maximum has now been increased to EUR 900,000 in both the DPA’s Penalty Policy Rules and the Dutch Telecommunication Act.

The starting point of the DPA in determining the amount of the fine is that fines must be proportional to the violation committed. Fines that can be imposed by the DPA can vary from a maximum of EUR 20,250 for relatively minor violations to a maximum of EUR 900,000 (previously: EUR 820,000) for deliberate or repeated violations of the Dutch Data Protection Act. For legal entities that have violated this Act, the fine is flexible: if the amount of fine set for the highest penalty category is not sufficiently punitive, the violation can be sanctioned additionally with a fine equivalent to up to 10% of the company’s annual net turnover.

Fines may only be imposed on a company following a binding instruction given from the DPA. Through this instruction, the DPA can inform the company what steps it should take to avoid paying the fine. But if the violation concerned was either intentional or a matter of serious culpable negligence, the DPA is not obliged to issue an instruction and can impose a fine directly.

We will of course inform you if the DPA imposes significant fines with respect to violations of the Dutch Data Protection Act.

 

This document can be found here (only available in Dutch). 

Team

Related news

07.12.2018 BE law
GDPR-roundtable on practical questions encountered during implementation

Roundtable - After the success of the roundtable sessions we held before the GDPR took effect (in May this year), our TMT team is enthusiastic about the session of 7 December, focusing on the lessons we have learned from working on multiple GDPR-matters in the past year. We will tackle some practical questions that we have encountered and that are not or cannot be readily answered by the new regulation.

Read more

20.11.2018 NL law
Seminar 'Personal data from a broader perspective: overlap inside and outside the privacy domain'

Seminar - On 20 November 2018, Stibbe will host a seminar on privacy. Several Stibbe lawyers will discuss personal data from a broader perspective and the overlap that can occur inside and outside the legal privacy domain.

Read more

07.12.2018 BE law
Virtual Currency Regulation Law Review

Articles - The first edition of the Virtual Currency Regulation Law Review is intended to provide a practical, business-focused analysis of recent legal and regulatory changes and developments, and of their effects, and to look forward at expected trends in the area of virtual currencies on a country-by-country basis.

Read more

Our website uses cookies: third party analytics cookies to best adapt our website to your needs & cookies to enable social media functionalities. For more information on the use of cookies, please check our Privacy and Cookie Policy. Please note that you can change your cookie opt-ins at any time via your browser settings.

Privacy – en cookieverklaring