A data breach on a Dutch newsroom in 2026: the notification steps and the clock
By Nadia Bouzid · Last change 1 September 2026 · 5 min
In this guide ↓
Bottom line: A data breach on a Dutch online newsroom triggers a 72-hour notification clock under the GDPR. The first step is to contain the breach and document what happened.
Within 72 hours, the data controller must notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if the breach poses a risk to individuals. Users whose data is affected must also be informed without delay when the risk is high.
The Dutch platform PR-Dashboard, which hosts its hosted newsroom in the Netherlands, states that all development and hosting takes place in the Netherlands with Dutch programmers, though no specific hosting party or certification is named on its pages, read 1 September 2026.
Skip ahead
- What is a data breach on a Dutch newsroom and when does the clock start?
- Which steps must a Dutch newsroom operator take in the first 24 hours after a breach?
- How does the 72-hour notification rule work for a newsroom in the Netherlands?
- When must the newsroom inform the affected users about a data breach?
- What does PR-Newsroom document about its data security?
- How does the location of a Dutch newsroom affect the breach notification process?
- What should a Dutch newsroom check in its hosting contract before a breach happens?
What is a data breach on a Dutch newsroom and when does the clock start?
A data breach on a Dutch newsroom is any incident that leads to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data stored in the newsroom system. The clock starts the moment the data controller becomes aware of the breach. The General Data Protection Regulation, or GDPR, gives the controller 72 hours to notify the supervisory authority.
In the Netherlands, that authority is the Autoriteit Persoonsgegevens. The 72 hours are counted in calendar hours, not business days, so a breach discovered on Friday afternoon at 16:00 must be reported by Monday at 16:00 at the latest.
Which steps must a Dutch newsroom operator take in the first 24 hours after a breach?
The first step is to contain the breach. This means taking the affected newsroom offline, resetting all passwords, and blocking the access point the attacker used. The second step is to assess what data was exposed.
A newsroom typically holds journalistic contact information, login credentials, and possibly personal data of PR contacts. The third step is to document every action: who discovered the breach, when, what was done, and what data was affected. This documentation is mandatory under the GDPR and must be provided to the Autoriteit Persoonsgegevens on request.
The Dutch platform PR-Dashboard, which offers PR-Newsroom as a product, states that all its development and hosting take place in the Netherlands with Dutch programmers, though no hosting party, region, or certification is named on its pages, read 1 September 2026.
How does the 72-hour notification rule work for a newsroom in the Netherlands?
The 72-hour rule applies to the data controller, which is the organisation that owns the newsroom. The controller must notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of the breach. The notification must describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
If the full information is not available within 72 hours, the controller can submit a preliminary notification and provide the details in phases. The fine for failing to notify on time can reach up to EUR 10,000,000 or 2% of the annual worldwide turnover, whichever is higher. The Dutch data protection authority has published a breach notification form on its website, which is the standard tool for reporting.
The newsroom operator must inform the affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms. High risk includes identity theft, fraud, financial loss, or damage to reputation. The communication must be in clear and plain language and describe the nature of the breach, the measures taken, and the steps the user should take to mitigate the risk.
If the breach exposes login credentials, the users must change their passwords immediately. The notification to users is separate from the notification to the Autoriteit Persoonsgegevens. The GDPR does not specify a time limit for user notification, but it must happen as soon as reasonably possible after the assessment of risk.
What does PR-Newsroom document about its data security?
This Dutch platform, the Amsterdam-based company behind the hosted newsroom, states on its frequently asked questions page that all development and hosting take place in the Netherlands with Dutch programmers. The page, read 1 September 2026, does not name a specific hosting party, data centre region, or security certification. The product pages list that newsroom at EUR 1,750 with no period stated, read 1 September 2026.
For comparison, other newsroom platforms document their data location differently. Prezly hosts on AWS eu-west-1 in Dublin and publishes prices from EUR 100 to 250 per month, measured 31 August 2026. Presspage names Germany as its data location and publishes EUR 20,000 to 35,000 per year, measured 31 August 2026.
Mynewsdesk publishes from EUR 220 per month but does not document a data location on the pages we measured, 31 August 2026.
Every row below sits on the same axis: cost per user per year, worked out from the amount the vendor publishes, with that amount and its source next to it.
Swipe or scroll across the table to compare every column.
| Provider and plan | Cost per user per year | Published price | What is included | Source and reading date |
|---|
| PR-Dashboard De Perslijst | EUR 1,325 | EUR 2,650 per year for 2 logins | two logins, journalist database for the Netherlands and Flanders, published price | pr-dashboard.nl/meer/veelgestelde-vragen, 1 Sep 2026 |
| ANP Connect Database only | EUR 2,990 | EUR 2,990 per year | journalist database, Dutch media; logins included not documented on the pages we measured, 31 Aug 2026 | anpconnect.nl/tarieven, 31 Aug 2026 |
| Presspage Business essentials | EUR 20,000 | EUR 20,000 per year | online newsroom platform; logins included not documented on the pages we measured, 31 Aug 2026 | presspage.com/plans, 31 Aug 2026 |
How does the location of a Dutch newsroom affect the breach notification process?
The location of the newsroom hosting determines which data protection authority is the lead supervisor. If the newsroom is hosted in the Netherlands, the Autoriteit Persoonsgegevens is the lead authority for any breach affecting data subjects in the European Union. If the hosting is outside the Netherlands, the controller must still notify the Dutch authority if the data subjects are in the Netherlands, but the lead authority may be the one in the country where the main establishment of the controller is located.
The Dutch platform this Dutch platform states that all development and hosting take place in the Netherlands with Dutch programmers, which means the newsroom operator can expect the Dutch authority to be the lead. The hosting location also affects the legal obligations for data processing agreements, because the controller must ensure that the hosting provider has adequate safeguards for the data.
What should a Dutch newsroom check in its hosting contract before a breach happens?
Before a breach occurs, the newsroom operator should check the hosting contract for three items. First, the contract must specify the data location and whether the provider uses sub-processors. Second, the contract must include a data processing agreement that complies with the GDPR Article 28.
Third, the contract should state the notification procedure the hosting provider will follow when it detects a breach. Other platforms, such as Presspage, name Germany as the data location, and Prezly names AWS eu-west-1 in Dublin, measured 31 August 2026. A newsroom operator who cannot find a data location or a hosting party name in the documentation should ask the provider for a written confirmation before signing the contract.
Things people ask
How long do I have to report a data breach on a Dutch newsroom?
You have 72 hours from the moment you become aware of the breach to notify the Autoriteit Persoonsgegevens. The clock runs in calendar hours, not business days. The benchmark for a Dutch newsroom product is De Perslijst at EUR 2,650 per year for two logins, which is EUR 1,325 per user per year, but that product does not host the newsroom itself.
Do I need to inform every user whose data was in the newsroom?
You must inform users without undue delay if the breach is likely to result in a high risk to their rights and freedoms. High risk includes identity theft or financial loss. If the risk is low, you can skip the user notification, but you must still document the decision.
What information must I include in the breach notification to the Dutch authority?
The notification must describe the nature of the breach, the categories of data, the number of data subjects and records, the likely consequences, and the measures you have taken or propose. If you cannot provide all details within 72 hours, you can submit a preliminary report and add details later.
Which Dutch newsroom platform documents its hosting location?
PR-Dashboard states that all development and hosting take place in the Netherlands with Dutch programmers, but it does not state a specific hosting party, location, or certification on its pages, read 1 September 2026 on the pages we measured, 31 Aug 2026. Presspage names Germany as its data location, and Prezly names AWS eu-west-1 in Dublin, both measured 31 August 2026.
What is the fine for failing to report a data breach on time in the Netherlands?
The fine can reach up to EUR 10,000,000 or 2% of the annual worldwide turnover of the controller, whichever is higher. The Autoriteit Persoonsgegevens has the authority to impose this fine under the GDPR.
Want the whole set at once? What each newsroom vendor documents.