If you live in the Netherlands you most likely heard the news: data from 700,000 women who took part in population screening (bevolkingsonderzoek) has been leaked.

This was not basic contact data. It involved highly sensitive personal and medical detail: names, addresses, citizen service numbers (BSN), and screening outcomes. The kind of information people trust an organization to protect with the highest possible care.

It is not an isolated case. Even with security programs and technical controls in place, breaches still happen. Millions of records are stolen every year, and SMEs and enterprises alike report incidents annually.

Organizations carry the responsibility

Every organization that processes personal data carries a legal duty under GDPR, NIS2 or HIPAA, and, as far as we are concerned, an ethical one. The consequences of a breach go well past technical clean-up:

  • Direct. Fines, lawsuits, forensic investigation, operational disruption.
  • Indirect. Reputational damage, loss of customer trust, and a long decline in confidence.

The fallout does not stop there. For individuals the impact is personal.

The personal cost of a leak

For an individual a breach is not abstract. It is a hit to confidence and to a sense of safety. Victims often feel exposed, stressed and vulnerable, and the practical damage follows.

  • Identity theft is rising. CBS figures show identity fraud in the Netherlands doubled, from 0.5% of the population in 2022 to 1% in 2024.
  • Financial loss. Criminals rarely use one leak in isolation. They combine information from several breaches, piece it together, and use it to apply for loans, impersonate victims or commit fraud.

Of the 700,000 women affected, roughly 7,000 could statistically face identity fraud in the coming years.

Because this leak involves highly sensitive medical and personal data, the likelihood of targeted misuse is higher than average.

What to do if your data leaks

Organizations have playbooks for a breach. For individuals it is less clear. Some practical first steps if you suspect your data has been exposed.

Check for leaks. Visit Have I Been Pwned to see whether your email address appears in known breach databases, and turn on the notifications while you are there. Check your BKR registration for suspicious loans or credit activity, and report anything out of the ordinary to the police. For stolen identity documents, follow the guidance via Rijksoverheid or register with the CMI. If you have become a victim of fraud or ransomware, Slachtofferhulp Nederland offers support.

Act immediately. Change your passwords, especially any you have reused. Turn on multi-factor authentication wherever it is available. Use a password manager to generate and store unique passwords.

Reduce future risk

Add a watermark to sensitive documents before uploading, something like for use by [organization] only. The Dutch government’s KopieID app does this for identity documents: it lets you redact the fields the recipient does not need and marks the file clearly as a copy.

The names of the agencies differ by country, but most offer the same services as the Netherlands: credit bureaus, government identity fraud reporting, and breach checkers. The point is the same everywhere. Act quickly, limit the damage, and prevent re-use of your data.

Why this matters at the organizational level

These incidents make the same point every time: protecting customer and citizen data is not optional. Real security goes past compliance. It means continuous monitoring, strong governance, and layered controls, from access control and encryption through to employee awareness and incident response.

Written by Sander Rurup, GRC & IT architecture

Cybersecurity consultant with close to a decade of consulting experience in enterprise architecture, information security management and security auditing across regulated European industry. Sander translates exposure into business requirement, governance and ownership.

TOGAF · ISO 27001 · CISM