Incident response
- 24/7 reporting line
- Forensic investigation
- Recovery and restart
An HR or recruitment agency holds information that people deliberately keep hidden from their own employer, and that makes a breach here personal rather than financial.
This page in another language: Nederlands
Work out for yourself what it would cost.
Enter your details; you will receive a proposal within one working day.
A premium indication, not personal advice. Prefer to talk it through? Call 072 - 509 24 56.
Your systems hold CVs, covering letters, interview notes, assessment reports, salary expectations and reference checks. For a candidate, the mere fact that he is applying is sensitive information: if it reaches his current employer, the damage is his position or his job. On top of that, you often serve two sides, the candidate and the client, and you have a different confidentiality arrangement with each. A breach affects both relationships at once.
In law you are on two tracks. For candidate data you are usually the controller yourself, with retention periods you have to set out and observe: normally a short period after the process ends, and longer only with consent. If you carry out work within a client's personnel administration, you are a processor there and the periods in his data processing agreement apply. In the event of a data breach, the report to the Autoriteit Persoonsgegevens (the Dutch data protection authority) within 72 hours applies, and where the risk is high so does the duty to inform the people concerned.
Pay particular attention to health information. Around sickness absence and reintegration you as an adviser may record only very limited data. That belongs with the company doctor. If medical information does appear in your files, that makes both the acceptance and the consequences of a breach more serious. Insurers ask about it expressly and incorrect answers affect the duty of disclosure under Article 7:928 of the Dutch Civil Code and the consequences of this in Article 7:930 of the Dutch Civil Code.
We compare your cyber insurance across dozens of insurers, explain where the real differences lie, and arrange the switch from start to finish — without you having to chase it yourself.
Cyber insurance
Compare
Get coveredThe structure of the cover in three parts, with an overview per situation below.
Specialists who look into it within hours.
What the incident costs you yourself.
Claims from customers and data subjects.
What is covered
| Situation | Cyber | AVB | BAV |
|---|---|---|---|
| Ransomware brings your systems down | Yes | No | No |
| Data breach involving personal data | Yes | No | Sometimes |
| Costs of notification and informing those affected | Yes | No | No |
| Fraud through a falsified payment instruction | Sometimes | No | No |
| Administrative fine from the regulator | No | No | No |
| Hardware that is physically damaged | No | No | No |
This overview is general in nature and is not personal advice. What is actually covered, including exclusions, limits and the excess, is set out in the policy conditions and the insurance card (verzekeringskaart) of the insurer; you receive both before you take out cover. Taking out cover without advice? Then read what execution only means for you.
Insurers weigh these details differently. That is where your saving is.
We look at the terms as well as the premium, and stay your point of contact when there is a claim.
We are not tied to one insurer and compare on the basis of an objective analysis of several companies.
You call or email someone who knows your file. No menu options, no changing call centres.
We cancel your old policy and align the start date, so you are never a day without cover.
We report the claim and monitor how it is handled. In urgent cases you can reach us on the emergency line.
Customers rate our service on four aspects: personal service, service delivery, availability and the outcome. The reviews are collected and published by NH1816 and come from customers who have actually taken out a policy with Finass Advies B.V. or reported a claim.
Four points that make the difference between a policy that pays out and one that does not.
If an application becomes known to the current employer, the candidate suffers concrete loss while you yourself have lost nothing. That is exactly what the third-party section exists for: claims from individuals after a breach, plus the legal assistance that goes with them. Reduce the risk by controlling access file by file and clearing out completed processes in line with your own retention period, and record that you demonstrably do so.
A personality profile, an integrity investigation or a reference report contains judgements that were not intended for the person concerned and that can follow him for years. Keep such reports separate from ordinary candidate data and with restricted access. Also check whether the party carrying out the assessment is your processor. If so, there should be a data processing agreement in place with its own reporting deadline.
A message that appears to come from a placed candidate or from a contact at the client, asking for a bank account number or address to be changed, is a recurring scenario in this sector. Nobody has broken in there; someone has been manipulated, and that falls under the separate module for fraud and social engineering. Ask whether that module is included and what control procedure the insurer requires with it.
Not covered are administrative fines of a punitive nature, placement fees lost because an assignment was withdrawn, and improving your systems afterwards. A complaint about the quality of your advice or of a candidate you put forward also belongs with the professional indemnity insurance (BAV). Intent and wilful recklessness remain excluded under Article 7:952 of the Dutch Civil Code.
This is what people ask us most.
The usual line is a short period after the process ends, and longer only with the candidate's express consent for a talent pool. The GDPR sets no fixed period, but requires you to set one, record it and keep to it. After a breach, the question is whether data was still held that should no longer have been there.
The third-party section handles claims from individuals arising from a breach of their data, including the costs of defence. The insurer assesses whether you are liable and whether the loss is substantiated. Report a claim without delay; Article 7:941 of the Dutch Civil Code requires you to report an event as soon as it is reasonably possible to do so.
You remain the controller for the candidate data. The supplier is your processor and must report a breach to you. Your own duty to report to the Autoriteit Persoonsgegevens within 72 hours still stands. Set out contractually the period within which the supplier informs you and what investigation he provides, because without that information you cannot report.
Only to a very limited extent. Data about the nature of the complaints and the treatment belongs with the company doctor and not in an HR file. If you do record it, you are processing health data with all the additional requirements that entails, and a breach is judged more seriously. Insurers ask about this explicitly at the acceptance stage.
Every situation is different. For these situations we have a separate page.
Request a quote without obligation. We will look at which insurer best matches your activities and your risk.
Prefer to call? 072 - 509 24 56, weekdays 09:00–17:00.
Claim on the road? Emergency line 06 - 55 20 40 72.
Finass Verzekert is a trading name of Finass Advies B.V. We advise on and arrange non-life insurance on the basis of an objective analysis of several insurers, and receive commission for this from the insurer, which is included in the premium. You pay no separate advice fee. Before you take out cover, we establish your wishes and needs.
You will find our licence, KvK and Kifid details and our complaints procedure at the foot of every page.
This page was compiled by Finass Verzekert (LinkedIn). Last updated on .
The information on this page is general in nature and is not personal advice.
Maandag- Vrijdag: 09:00- 17:00
We use cookies and similar technologies to improve your experience on our website.