Skip to main content
Netherlands News in English

Main navigation

  • Top stories
  • Health
  • Crime
  • Politics
  • Business
  • Tech
  • Culture
  • Sports
  • Weird
  • 1-1-2
Image
Odido's headquarters building in The Hague. Undated
Odido's headquarters building in The Hague. Undated - Credit: Odido / Supplied - License: All Rights Reserved
Crime
Odido
hack
data breach
privacy
privacy law
dutch data protection authority
AP
National Inspectorate for Digital Infrastructure
RDI
Thursday, 26 March 2026 - 15:20

Share this article:

Oidido under investigation for keeping customer data for too long

The Dutch Data Protection Authority (AP) and the National Inspectorate for Digital Infrastructure (RDI) are investigating whether provider Odido is retaining customer data for too long, AD reported. During the recent data theft at the company, hackers stole data of people who had not been Odido customers for years.

European privacy rules state that people’s data “may not be retained longer than strictly necessary, because what does not exist cannot be stolen,” the AP pointed out. The privacy watchdog had already asked Odido for an explanation last month.

The AP will investigate whether Odido complied with privacy rules. The RDI and AP will both investigate whether the provider had the proper technical security in place for its customer data.

It is important to be digitally resilient, said Inspector General Angeline van Dijk, head of the RDI. “As a society, we must be able to rely on the secure operation of our vital services.”

Hacker group ShinyHunters broke into Odido’s systems in February and stole the personal data of 6.2 million current and former customers, eventually publishing the data when Odido refused to pay a ransom. The data included names, addresses, email addresses, phone numbers, and bank account numbers, among other things.

The hack revealed that the company keeps customer data much longer than claimed. Odido’s privacy statement says it retains data for up to two years after the end of the contract. But former customers who switched providers up to 10 years ago received emails informing them that their data had been compromised in the hack.

More like this

Image
Odido's headquarters building in The Hague. Undated
Odido cyber attack: Hackers gained access to 6.2 million people's data
Image
Domestic violence helpline
Details of women staying in domestic violence shelters also leaked in laboratory hack
Image
Odido's headquarters building in The Hague. Undated
Odido only noticed theft of 6.2 million people’s data when hackers informed them
Image
Gurneys in a hospital corridor
Hospital patient data may have leaked in Chipsoft hack, sources say
Make NL Times your top Google source

Follow us:

Latest stories

  • Man who held hostages in Ede, Vught moved to Groningen psychiatric clinic
  • Rotterdam-based chip inspection technology firm raises €331 million in deeptech funding
  • PostNL removes 800 mailboxes as Dutch mail reliability stays below legal standard
  • PRO, VVD, D66, Volt, and CDA strike deal to govern Rotterdam
  • Drug activity overruns Den Helder neighborhood, dealers take over at-risk locals’ homes

Top stories

  • Heat wave: Code Orange weather alert for 36°C temps takes effect on Wednesday
  • More international students facing housing issues in Netherlands, from bedbugs to fraud
  • Woman, 42, drowns in Waal after rescuing children from water
  • Average Netherlands home price rose by 4.4% to €487,383 in May
  • Video: Explosion damages Amsterdam-Oost apartment building; Two teens on fatbike sought

© 2012-2026, NL Times, All rights reserved.

Footer menu

  • Change Privacy Settings
  • Privacy Policy
  • Contact
  • Partner Content