Skip to main content
Netherlands News in English

Main navigation

  • Top stories
  • Health
  • Crime
  • Politics
  • Business
  • Tech
  • Culture
  • Sports
  • Weird
  • 1-1-2
Image
Odido's headquarters building in The Hague. Undated
Odido's headquarters building in The Hague. Undated - Credit: Odido / Supplied - License: All Rights Reserved
Crime
Odido
hack
data breach
privacy
privacy law
dutch data protection authority
AP
National Inspectorate for Digital Infrastructure
RDI
Thursday, 26 March 2026 - 15:20

Share this article:

Oidido under investigation for keeping customer data for too long

The Dutch Data Protection Authority (AP) and the National Inspectorate for Digital Infrastructure (RDI) are investigating whether provider Odido is retaining customer data for too long, AD reported. During the recent data theft at the company, hackers stole data of people who had not been Odido customers for years.

European privacy rules state that people’s data “may not be retained longer than strictly necessary, because what does not exist cannot be stolen,” the AP pointed out. The privacy watchdog had already asked Odido for an explanation last month.

The AP will investigate whether Odido complied with privacy rules. The RDI and AP will both investigate whether the provider had the proper technical security in place for its customer data.

It is important to be digitally resilient, said Inspector General Angeline van Dijk, head of the RDI. “As a society, we must be able to rely on the secure operation of our vital services.”

Hacker group ShinyHunters broke into Odido’s systems in February and stole the personal data of 6.2 million current and former customers, eventually publishing the data when Odido refused to pay a ransom. The data included names, addresses, email addresses, phone numbers, and bank account numbers, among other things.

The hack revealed that the company keeps customer data much longer than claimed. Odido’s privacy statement says it retains data for up to two years after the end of the contract. But former customers who switched providers up to 10 years ago received emails informing them that their data had been compromised in the hack.

More like this

Image
Odido's headquarters building in The Hague. Undated
Odido cyber attack: Hackers gained access to 6.2 million people's data
Image
Domestic violence helpline
Details of women staying in domestic violence shelters also leaked in laboratory hack
Image
Odido's headquarters building in The Hague. Undated
Odido only noticed theft of 6.2 million people’s data when hackers informed them
Image
Gurneys in a hospital corridor
Hospital patient data may have leaked in Chipsoft hack, sources say
Make NL Times your top Google source

Follow us:

Latest stories

  • Police: Young fatbike rider suspected of groping 8 women in Dordrecht area
  • Six arrested in electoral fraud investigation; Allegations of forgery, voter coercion
  • Monkey on the loose in Hilvarenbeek after Beekse Bergen escape
  • Dutch government irritated by U.S. plans for new ASML export restrictions
  • Health risks at dozens of outside swimming locations in Netherlands

Top stories

  • Six arrested in electoral fraud investigation; Allegations of forgery, voter coercion
  • Hottest night on Dutch records expected tomorrow; Code Orange takes effect at noon
  • 270 children abducted to or from the Netherlands last year; Increase of over 25%
  • Public transport strike from 4 a.m. to 8 a.m.: No trains, buses, trams, metros running
  • Life sentence sought for Dutch-Rwandan man over massacre of 3,000 Tutsi in 1994 genocide

© 2012-2026, NL Times, All rights reserved.

Footer menu

  • Change Privacy Settings
  • Privacy Policy
  • Contact
  • Partner Content