Law / Netherlands

GDPR Articles 33-34 and UAVG Article 42, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34; UAVG, Art. 42

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

A breach notification rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Notify the AP within 72 hours of becoming aware of a personal-data breach affecting a person in the Netherlands, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, subject to UAVG Article 42's national exception.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A controller must notify the AP within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. UAVG Article 42 adds one national exception to the Article 34 individual-notification duty: it disapplies Article 34 for financial undertakings within the meaning of the Wet op het financieel toezicht (Financial Supervision Act).

Corrected during the #8352 wave 4 review: the article's full text is a single sentence stating exactly this exception, not merely confirmed by a table-of-contents heading.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics

Read the law

GDPR Arts. 33-34
UAVG Art. 42 (heading confirmed, full text not read)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app