Law note · Netherlands

GDPR Articles 33-34 and UAVG Article 42, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34; UAVG, Art. 42 stage In effect since 2018-05-25 reviewed 2026-08-24

A controller must notify the AP within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. UAVG Article 42 adds one national exception to the Article 34 individual-notification duty; this session confirmed the article's existence and heading via the table of contents but did not fetch its full substantive text.

What it asks of an app

  • Notify the AP within 72 hours of becoming aware of a personal-data breach affecting a person in the Netherlands, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, subject to UAVG Article 42's national exception.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics

Primary source: GDPR Arts. 33-34
UAVG Art. 42 (heading confirmed, full text not read this session)

← Back to the example  ·  Lint your app →