Enforcement
HAN University of Applied Sciences fined 175,000 euros for inadequate security
- Date
- Status
- final
- Body
- Autoriteit Persoonsgegevens
- Reference
- Boetebesluit AP, ons kenmerk 2024-024797 (besluit 15 december 2025, gepubliceerd 17 december 2025)
- Amount
- €175,000
What it is about
In 2021 a hacker used SQL injection through a web form to reach a HAN web server and database server. The server held several hundred thousand records, including names with passwords, special category data, 407 citizen service numbers and 183 identity document numbers. The hacker demanded a ransom, which was not paid. The Dutch DPA found four shortcomings. Measures against SQL injection were insufficient and logging and monitoring were too limited. A database account had unrestricted rights across 282 databases. Data from retired applications was kept unnecessarily. Passwords were stored in plain text or hashed with MD5/SHA1. This breached Article 32 GDPR. The base fine of 310,000 euros was reduced to 175,000 euros because HAN actively limited the impact on data subjects, already had a security programme under way and shares lessons with other organisations. The DPA settled the case; HAN will not object.
What this means in practice
A data breach is not itself a violation, but missing risk assessment and inadequate measures are. A security policy on paper is not enough: least privilege and deletion policies must actually be implemented. Restrict account rights to what is needed, log and monitor database activity, purge data from retired applications and keep password hashing up to date. Actively limiting harm to data subjects, investing in security already under way and sharing lessons with others substantially reduces the fine.
The GDPR articles concerned
Source: Autoriteit Persoonsgegevens, persbericht en boetebesluitchecked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
Case law
- Gelderland District Court: bankruptcy trustee is controller, DPA fine for unsecured hard drive cut to 58,125 euros
2025-08-07 · status not established, Rechtbank Gelderland
- Russmedia: an online marketplace operator is controller for personal data in adverts and must check before publication
2025-12-02 · final, Hof van Justitie van de EU (Grote kamer), X tegen Russmedia Digital SRL en Inform Media Press SRL
Guidelines
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
2021-12-14 · final, European Data Protection Board (EDPB)
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default
2020-10-20 · final, European Data Protection Board (EDPB)
- Guidelines 01/2025 on Pseudonymisation
2025-01-16 · adopted, European Data Protection Board (EDPB)