Skip to main content
Netherlands News in English

Main navigation

  • Top stories
  • Health
  • Crime
  • Politics
  • Business
  • Tech
  • Culture
  • Sports
  • Weird
  • 1-1-2
Image
Odido's headquarters building in The Hague. Undated
Odido's headquarters building in The Hague. Undated - Credit: Odido / Supplied - License: All Rights Reserved
Crime
Odido
hack
data breach
privacy
privacy law
dutch data protection authority
AP
National Inspectorate for Digital Infrastructure
RDI
Thursday, 26 March 2026 - 15:20

Share this article:

Opens in a new window Opens in a new window Opens in a new window Opens in a new window Opens in a new window Opens in a new window

Oidido under investigation for keeping customer data for too long

The Dutch Data Protection Authority (AP) and the National Inspectorate for Digital Infrastructure (RDI) are investigating whether provider Odido is retaining customer data for too long, AD reported. During the recent data theft at the company, hackers stole data of people who had not been Odido customers for years.

European privacy rules state that people’s data “may not be retained longer than strictly necessary, because what does not exist cannot be stolen,” the AP pointed out. The privacy watchdog had already asked Odido for an explanation last month.

The AP will investigate whether Odido complied with privacy rules. The RDI and AP will both investigate whether the provider had the proper technical security in place for its customer data.

It is important to be digitally resilient, said Inspector General Angeline van Dijk, head of the RDI. “As a society, we must be able to rely on the secure operation of our vital services.”

Hacker group ShinyHunters broke into Odido’s systems in February and stole the personal data of 6.2 million current and former customers, eventually publishing the data when Odido refused to pay a ransom. The data included names, addresses, email addresses, phone numbers, and bank account numbers, among other things.

The hack revealed that the company keeps customer data much longer than claimed. Odido’s privacy statement says it retains data for up to two years after the end of the contract. But former customers who switched providers up to 10 years ago received emails informing them that their data had been compromised in the hack.

More like this

Image
Odido's headquarters building in The Hague. Undated
Odido cyber attack: Hackers gained access to 6.2 million people's data
Image
Domestic violence helpline
Details of women staying in domestic violence shelters also leaked in laboratory hack
Image
Odido's headquarters building in The Hague. Undated
Voice of fake IT employee links Dutch criminals to Odido hack
Image
Odido's headquarters building in The Hague. Undated
Odido only noticed theft of 6.2 million people’s data when hackers informed them
Make NL Times your top Google source

Follow us:

Latest stories

  • Dutch farmers gear up for new protests against nitrogen rules
  • Mild weather to favor 45,000 walkers at Nijmegen Vierdaagse; Fireworks canceled
  • Online supermarket Picnic growing fast, but still suffering losses due to investments
  • Prosecutors seek 1-year conditional sentence for taking Vught prison staff hostage
  • Ex-Dutch police officers seek recognition after Prime Minister’s apology to Moluccans

Top stories

  • Swatting as sextortion: Armed cops sent to teen's home after refusing to send nude pics
  • Dutch man arrested for fatal shooting in Antwerp club
  • Drug crimes jump 9% in first half of 2026
  • Video: Man and woman stabbed in Helmond apartment
  • Fourth regional heat wave possible in Netherlands late July

© 2012-2026, NL Times, All rights reserved.

Footer menu

  • Change Privacy Settings
  • Privacy Policy
  • Contact
  • Partner Content