Reinier Russell

managing partner

Reinier advises national and international companies
+31 20 301 55 55

Privacy: New European Data Protection Regulation

Publication date 28 May 2015

In this newsletter Russell Advocaten will inform you, in short, about the most important changes to be expected in the European data protection regulations. More detailed information on this topic can be found in our previous newsletters.

persoonsgegevens - ubo


The new Regulation will introduce extremely severe sanctions on (repeated) breaches of privacy of EU citizens. Currently, for instance, the Dutch Data Protection Agency (CBP) can impose a fine of a maximum of EUR 4,500. The new fines can be up to a maximum of EUR 100,000,000 or 5% of the global annual turnover, depending on which amount is higher.

Data protection officer

The following businesses and organizations will have to appoint an independent data protection officer:

  • businesses with more than 250 employees
  • companies processing data of more than 5000 persons within a period of 12 months
  • government authorities, public bodies

The main tasks of the data protection officer include monitoring of the general quality of the data protection policy of a company and controlling whether the data processing is in accordance with the laws and regulations.

Reporting a data leak

If your business is affected by a data leak, you will have to report it within 24 hours and without delay to the competent Data Protection Agency and potential persons concerned. Violations of the notification requirement will be fined up to a maximum of EUR 1,000,000 or 2% of the global annual turnover of the business.

The “right to be forgotten”

Consumers will be given the right that companies and institutions will take care to delete their data and prevent further spread of the data, if:

  • there is no longer reason to store the processed data for the purpose they used to be collected or processed for
  • the person in question withdraws his/her consent, and/or when the period allowed for data storage has passed
  • the person in question lodges a complaint against the processing of personal data
  • the company or institution does not comply with the other provisions of the Regulation

More information

Would you like to know more about the new European Data Protection Regulation or do you have any other questions about how to organize your business with regard to the new European Data Protection Regulation? Please contact:

    We process the personal data above with your permission. You can withdraw your permission at any time. For more information please see our Privacy Statement.

    Related publications

    1 January 2024: Model agreement on unrestricted substitution to disappear

    An important way to prevent an assignment contract from turning out to be an employment contract after all is to use and correctly implement the model agreements on the website of the Dutch Tax and Customs Administration. However, from 1 January 2024, all models that partially or completely assume the possibility of substitution will expire. What does this mean for principals and contractors?

    Read more

    What does the Homologation Act (WHOA) mean for creditors?

    The WHOA makes it easier for a company facing bankruptcy to avoid bankruptcy. This can be done through a binding agreement with all creditors, even if they do not all agree to the arrangement. What rights do creditors have in WHOA proceedings?

    Read more

    New EU General Product Safety Regulation

    On 12 June 2023, the new EU General Product Safety Regulation entered into force. As of 13 December 2024, products must comply with this regulation. What are the consequences of the new Product Safety Regulation? Which entrepreneurs should start taking measures now?

    Read more

    Fraud prevention in the company

    Fraud causes billions in damages each year. Companies face, for example, fraudulent contracting parties, directors and employees. The management and supervisory board might play the most important role in a company when it comes to fraud prevention. In this newsletter we will give them some legal tools to prevent fraud.

    Read more

    Protecting your company’s assets and interests. The importance of getting it right from the start

    Company directors and company owners are more than ever reliant on assets such as a company’s brand name, patented inventions, trade secrets, customer data base and skillful employees. Yet, all too often, when faced with a potential infringement or misappropriation, companies find themselves woefully underprepared in terms of risk management. This may prove highly detrimental to the company’s best interests.

    Read more

    Doing business in Europe: Changes in European Union legislation and their impact on EU member state law

    During the summer months of 2022, the necessary relevant changes at the European level for, in particular, suppliers and distributors, founders of legal entities and employers came into force. It is therefore time for these distributors and employers to update their distribution and labor agreements, while it becomes easier for foreign founders of companies to establish themselves in the Netherlands for the first time or expand their presence here.

    Read more