Skip to content
Guidance · Autoriteit Persoonsgegevens ·boete-han NL LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Artikelen

AP

AP

Guidance

Full text

Na een datalek melding op 1 sept 2021 is de Autoriteit Persoonsgegevens onderzoek gaan doen en heeft uiteindelijk 15 dec 2025 een boete opgelegd van EUR 175.000 aan de HAN. De overtredingen zijn (1) Onvoldoende maatregelen tegen SQL-injectie genomen ; (2) Het niet beperken van toegangsrechten van database-gebruiker; (3) Het onnodig bewaren van persoonsgegevens van uitgefaseerde applicaties; (4) Het niet en niet-toereikend hashen van wachtwoorden. De AP weegt mee dat de basisboete van EUR 310.000 gematigd dient te worden gelet op de maatregelen die de HAN heeft genomen; (factor 'c'), maar ook dat er een project gestart was over informatiebeveiliging en dat de HAN de kennis en ervaringen rond het incident niet alleen intern onder de aandacht heeft gebracht, “maar vanuit haar maatschappelijke rol als kennisinstituut ook bij verschillende externe aangelegenheden heeft gedeeld”. (p.

How it connects

S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Integrity and Confidentiality Principle
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece ·HDPA ·Art. 5, 28, 32 Jul 28, 2026 Controllers Data Breaches Integrity and Confidentiality Principle
HDPA: Hellenic Open University found to have met breach notification duties after The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware… 14/2026 ·Greece ·Art. 32, 33, 34 +1 Aug 19, 2026 Data Breaches Notification Obligation Integrity and Confidentiality Principle
C-768/21 TR v Land Hessen In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of… CJEU ·First Chamber Sep 26, 2024 Supervision Data Breaches Integrity and Confidentiality Principle
AEPD: Data subject entitled to identity of professionals who accessed medical records Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of… pd-00055-2026 ·Spain ·Art. 5, 12, 15 +2 Sep 15, 2026 Personal Data Healthcare Right of Access