Source methodology
Implemented official source
Netherlands AP data breach statistics
One attributed annual aggregate for a source-defined notification, cause, or incident-type dimension
Reviewed annual figures for 2024 and 2025 in the regulator's July 2026 publication.
- Regulator
- Autoriteit Persoonsgegevens
- Jurisdiction
- Netherlands
- Reporting scheme
- GDPR personal data breach notifications
- Publication level
- National Aggregate
- Coverage type
- Aggregate Reporting Periods
- Reporting threshold
- The figures concern personal data breach notifications received by Autoriteit Persoonsgegevens under the GDPR reporting framework.
- Source population
- Notifications received by Autoriteit Persoonsgegevens and included in its annual published figures; this is not a census of all breaches in the Netherlands.
- Licence state
- No explicit open-data licence was identified on the reviewed publication. Breach Gazette retains only attributed factual aggregate values and does not reproduce source prose or documents.
- Rights boundary reviewed
- 26 July 2026
- Redistribution decision
- Approved With Conditions
- Automated health
- Healthy
- Snapshot completeness
- Complete
- Update checkpoint
- Complete
- Reviewed record floor
- 5
- Accepted records
- 5
- Rejected records
- 0
- Bounded retrieval limit
- 10
- Source revision
- ap-datalekken-2025:26958b6c419fe53f
- Snapshot checksum
- 26958b6c419fe53fa2ca8ae00c6a34e3212973204152e65bd51a38aa213bcb96
- Latest update attempt
- 7 Sept 2026
- Last successful update
- 7 Sept 2026
Limitations
- Notification counts are not automatically unique real-world incidents.
- Cyberattack and account-takeover figures describe source-defined dimensions and must not be summed with the annual total or each other.
- The regulator may revise the published figures.
- No notifying or affected organizations are identified by these aggregate records.
- Only factual aggregate values are retained because no explicit open-data licence was identified.
Correction process
Check the current official publication, retain annual notification semantics, and do not treat cause or incident-type dimensions as additive totals.
Attribution
Autoriteit Persoonsgegevens