The Dutch Parliament will hold a session on cybersecurity on May 20 amid growing concerns over the digital resilience of businesses in the country, after the Dutch Data Protection Authority (AP), warned that security standards “have remained too low for years,” and called for stronger preventive oversight powers.
In a position paper released ahead of the discussion, the independent regulator identified three “urgently needed improvements” to cybersecurity in the Netherlands:
- raising baseline security standards across organizations and suppliers;
- limiting the impact of data breaches through stricter data governance; and
- expanding supervisory capacity so that authorities can conduct more preventive, risk-based enforcement.
The AP said cyber incidents and data breaches in the Netherlands have become routine, pointing to a sharp rise in reported breaches. More than 44,000 data breaches were reported to the regulator in 2025, up from about 38,000 in 2024, according to the paper. Part of the regulator’s supervision includes mandatory reporting requirements and risk-based supervision under the legal framework of the General Data Protection Regulation (GDPR).
“Prevention remains better than cure,” the regulator said, while warning that limited resources force it to focus primarily on the most serious incidents after breaches occur, rather than on proactive monitoring before attacks happen.
Wednesday’s meeting is expected to bring together government officials, regulators, businesses and cybersecurity stakeholders as the Netherlands faces increasing pressure to strengthen digital defenses against ransomware attacks, data theft and supply-chain vulnerabilities.
The AP said that years of breach notifications have revealed persistent weaknesses in both technical safeguards and organizational governance. According to the regulator, 33 percent of surveyed organizations admitted that incidents were caused by an absence of adequate policy, while 40 percent said policies existed but were implemented poorly or not monitored sufficiently.
AP Calls for Higher Cybersecurity Standards and Stronger Oversight
The AP urged organizations to gain a thorough understanding of the cybersecurity risks they face and the measures they need to take, including around the processing and storage of data, and added:
“They must also take responsibility and control by not shifting cybersecurity onto the shoulders of individual employees, but by ensuring it centrally and placing it high on the agenda of executives.”
The regulator noted that audits, security tests and technical safeguards “are essential in this regard to detect and rectify errors early.”
The risks extend beyond regulatory exposure and operational disruption. Breaches involving customer data can erode consumer trust, disrupt digital services and damage customer experience through account lockouts, payment interruptions, exposure to fraud and delays in support response.
Poor data governance, excessive data retention and weak communication after breaches can intensify the impact on individuals, particularly when organizations fail to quickly notify affected users or provide clear guidance on protective measures.




