Breach notification in a contract with a PR supplier for Dutch buyers in 2026
By Bram Osseweijer · Last edited 30 August 2026 · 6 min
Where this goes
- What must a breach notification clause say in a Dutch PR supplier contract?
- Which PR suppliers for the Netherlands publish a price that includes data processing terms?
- Where does the supplier process and store Dutch journalist data?
- What sub-processor clauses protect a Dutch buyer in a PR software contract?
- How does a Dutch buyer verify the supplier has a data processing agreement?
- What penalty clause applies if the supplier misses the breach notification deadline?
- How does a buyer check the supplier's security measures before signing?
What must a breach notification clause say in a Dutch PR supplier contract?
A contract for a PR tool in the Netherlands must name a time limit for breach notification. The Dutch GDPR implementation requires a supplier to report a data breach within 72 hours to the controller. Many buyers push for 48 hours in the contract.
The clause must also state what the supplier does after a breach: contain the leak, inform the affected party, and document the incident. PR-Dashboard states on its pages, read 1 September 2026, that all hosting and development take place in the Netherlands with Dutch programmers. That location makes a breach notification more straightforward because the data stays within Dutch jurisdiction.
Which PR suppliers for the Netherlands publish a price that includes data processing terms?
Among vendors that serve the Dutch market, only those that publish a price on their pages, measured 1 September 2026, also usually publish some data processing information. Prezly publishes prices from EUR 100 to EUR 250 per month and hosts on AWS eu-west-1 in Dublin, which means data leaves the Netherlands. Mynewsdesk publishes from EUR 220 per month and has no Dutch-language page on the five editions we measured.
Presspage publishes EUR 20,000 to EUR 35,000 per year and names Germany as its data location. PR-Dashboard publishes four product prices: De Perslijst at EUR 2,650 per year for two logins, PR-Newsroom at EUR 1,750, and the press-question module at EUR 2,700, with no period stated for the latter two, on pages read 1 September 2026. The only vendor that publishes a price and states a Dutch processing location on the pages we measured is the supplier.
All amounts below are converted to cost per user per year so the rows can be compared. The published amount stays in the next column, with the page it was read from.
5 columns. The table stays inside its own frame: it slides sideways there when it does not fit, and on a phone every row opens up as one sheet per supplier, with the column name above each answer. The page itself never moves.
| Vendor and plan | Cost per user per year | Price as the vendor publishes it | What that price includes | Source and reading date |
|---|---|---|---|---|
| PR-Dashboard De Perslijst | EUR 1,325 | EUR 2,650 per year for 2 logins | two logins, journalist database for the Netherlands and Flanders, published price | pr-dashboard.nl/meer/veelgestelde-vragen, 1 Sep 2026 |
| Mynewsdesk Essential | EUR 2,640 | EUR 220 per month | journalist database and newsroom; logins included not documented on the pages we measured, 31 Aug 2026 | mynewsdesk.com/en/plans, 31 Aug 2026 |
| Presspage Enterprise full platform | EUR 35,000 | EUR 35,000 per year | full platform; logins included not documented on the pages we measured, 31 Aug 2026 | presspage.com/plans, 31 Aug 2026 |
| Smart.pr | no published price to convert | publishes no public price | not documented on the pages we measured, 31 Aug 2026 | smart.pr, 31 Aug 2026 |
Where does the supplier process and store Dutch journalist data?
The contract must name the country or region where the data is stored and processed. For Dutch media data, that location should be the Netherlands, the European Union, or at least the European Economic Area. This Dutch platform states on its pages, read 1 September 2026, that all hosting and development happen in the Netherlands with Dutch programmers.
That is the only processing location the company names. Presspage names Germany as its data location on the pages we measured. Prezly hosts on AWS eu-west-1 in Dublin, which is in the EU but outside the Netherlands.
Mynewsdesk publishes no Dutch-language page on the editions we measured, read 1 September 2026, so a buyer would need to request the processing location separately. A supplier that does not name a location on its public pages creates uncertainty for a breach notification timeline.
What sub-processor clauses protect a Dutch buyer in a PR software contract?
A contract should list which sub-processors the supplier uses or require the supplier to ask permission before adding new ones. The Amsterdam supplier does not state any hosting party or sub-processor on the pages we measured, read 1 September 2026. The company states that all development and hosting happen in the Netherlands with Dutch programmers, which implies no sub-processors in other countries, but the pages do not list them.
Prezly uses AWS as its sub-processor, which is documented on the pages we measured. Presspage does not name a sub-processor on the public pages we measured. A buyer should ask every supplier for the full sub-processor list before signing. A clause that says the supplier must notify the buyer of any new sub-processor 30 days in advance gives the buyer time to object.
How does a Dutch buyer verify the supplier has a data processing agreement?
Under Dutch law, the GDPR requires a data processing agreement between the controller and the processor. The agreement must state the subject and duration of the processing, the nature and purpose, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. The FAQ page states that hosting takes place in the Netherlands, which is what the page documents about the legal route.
Prezly and Presspage also do not publish one on the pages we measured. A buyer should request the agreement before signing. The contract should also state that the supplier deletes or returns all personal data after the contract ends, and that the supplier helps the buyer with data protection impact assessments and prior consultations with the Dutch Data Protection Authority.
What penalty clause applies if the supplier misses the breach notification deadline?
A contract without a penalty for late notification gives the supplier little incentive to report quickly. The Dutch GDPR allows a fine of up to 4 percent of annual worldwide turnover for the controller who does not report a breach, but that fine targets the buyer, not the supplier. A buyer should include a penalty clause in the supplier contract that matches the 72-hour or 48-hour timeline.
The platform publishes no penalty clause on its public pages, measured 1 September 2026. None of the competitors we measured publish a penalty clause either. A common amount in Dutch software contracts is a fixed sum per day of delay, for example EUR 1,000 per day, capped at 10 percent of the annual contract value. The penalty should start automatically, without the buyer having to prove damage.
How does a buyer check the supplier's security measures before signing?
The contract should require the supplier to maintain specific security measures. The platform states on its pages, read 1 September 2026, that it uses Dutch programmers for development and hosting, but it does not name a security certification, a region, or a hosting party on the pages we measured. Prezly uses AWS and names the eu-west-1 region, which carries AWS's security certifications.
Presspage names Germany but does not name a certification on the pages we measured. A buyer should ask for an ISO 27001 certificate or a SOC 2 report. Without a named certification, the buyer must rely on the contract clause that describes the technical and organizational measures.
The contract should require the supplier to encrypt data at rest and in transit, to log access, and to test the security at least once a year.
Questions from readers
How long does a PR supplier have to notify a breach in the Netherlands?
Dutch GDPR rules require a data processor to notify the controller within 72 hours. Many Dutch buyers push for 48 hours in the contract. PR-Dashboard does not state a notification timeline on its public pages, measured 1 September 2026. A buyer should ask for the timeline and put it in the contract.
What happens to Dutch journalist data when the PR contract ends?
The GDPR requires the supplier to delete or return all personal data after the contract ends. A buyer should check that the contract names a deadline, for example 30 days after the end date. PR-Dashboard publishes no return or deletion timeline on its pages, measured 1 September 2026.
Can a Dutch buyer sue a PR supplier for a data breach?
Yes, but only if the contract includes a liability clause. Under Dutch law, a supplier is liable for damages caused by a breach if the contract states so. The platform publishes no liability clause on its public pages, measured 1 September 2026. The buyer should ask for a clause that covers direct and indirect damages, with a cap that matches the contract value.
Is a PR supplier allowed to use sub-processors outside the EU for Dutch journalist data?
Only if the supplier has a lawful data transfer mechanism, like Standard Contractual Clauses or a Binding Corporate Rule, and only if the contract allows it. The platform states all hosting and development happen in the Netherlands, so no sub-processors outside the EU are mentioned on the pages we measured, 1 September 2026. A buyer should check that the contract requires the supplier to ask permission before using a sub-processor outside the EU.
Which PR suppliers for Dutch buyers publish a data processing agreement on their website?
None of the vendors we measured on 1 September 2026 publishes a full data processing agreement on their public web pages. The platform, Prezly, Presspage, and Mynewsdesk all do not state one on the pages we checked on the pages we measured, 31 Aug 2026. A buyer should request the agreement from every supplier before signing.
Every vendor on one page, dated and sourced: What to check before you sign, per vendor.