Skip to content

GDPR-compliant password sharing in the Netherlands

P
PassTransfer
Published June 14, 20244 min read

The General Data Protection Regulation (GDPR) — known in the Netherlands as the AVG (Algemene Verordening Gegevensbescherming) — places clear obligations on organizations that process personal data. While GDPR is most often discussed in the context of customer data, it also applies to internal processes — including how your team handles credentials that grant access to systems containing personal data.

Sharing passwords insecurely is not just a security risk; in the Netherlands, it can constitute a breach of your GDPR obligations.

Why password sharing is a GDPR concern

Access credentials are the keys to systems that may contain personal data. If those credentials are shared insecurely, you may be in violation of Article 32 of the GDPR, which requires organizations to implement "appropriate technical and organisational measures" to ensure data security.

Specific concerns include:

  • Unauthorized access: If a password is shared via email and that email is forwarded, compromised, or simply never deleted, unintended parties may gain access to personal data
  • Lack of accountability: Shared credentials make it impossible to audit who accessed what and when
  • Storage limitation violations: Storing credentials in email threads or chat logs creates persistent copies with no defined deletion schedule

The Autoriteit Persoonsgegevens (AP) — the Dutch data protection authority — has the power to impose fines of up to €20 million or 4% of global annual turnover for serious GDPR violations. While password sharing is rarely the direct cause of enforcement action, it can be a contributing factor in larger data breach investigations.

GDPR principles relevant to password sharing

Data minimization (Article 5(1)(c)): Only share credentials with people who genuinely need access. One-time links help enforce this — if a credential is shared with the wrong person, it can only be used once before becoming invalid.

Storage limitation (Article 5(1)(e)): Data should not be kept longer than necessary. Self-expiring credential links directly support this principle: after the expiry time passes, the credential is no longer accessible via the link.

Integrity and confidentiality (Article 5(1)(f)): Appropriate security must be applied to personal data. Encrypted, one-time credential links offer stronger confidentiality guarantees than email.

Accountability (Article 5(2)): Organizations must be able to demonstrate compliance. Using a purpose-built tool with defined data handling practices supports your accountability posture.

What Dutch organizations should look for in a compliant tool

When selecting a tool for credential sharing, Dutch organizations should verify:

  1. EU data residency: Is data processed and stored within the EU? Transfers outside the EU require additional safeguards under Chapter V of the GDPR.
  2. Data Processing Agreement (DPA): Does the vendor offer a DPA (verwerkersovereenkomst)? If the tool processes personal data on your behalf, a DPA is legally required.
  3. Encryption: Are credentials encrypted at rest and in transit?
  4. Automatic deletion: Are credentials deleted after retrieval and/or after expiry?
  5. Access controls: Can you limit who receives a credential link?

PassTransfer and GDPR compliance

PassTransfer is designed with these requirements in mind. Data is hosted in the EU, credentials are encrypted using strong symmetric encryption, and passwords are deleted from the server after retrieval. Links expire after a configurable period, even if not used.

For Pro users operating on custom subdomains, the tool can be presented as part of your own service infrastructure — which is relevant for organizations that maintain records of the processors they use (required under Article 30 GDPR records of processing activities).

Practical next steps for Dutch businesses

If you currently share passwords via email, WhatsApp, or shared documents, the path to compliance is straightforward:

  1. Adopt a dedicated credential-sharing tool with EU data residency
  2. Establish an internal policy prohibiting credential sharing via uncontrolled channels
  3. Ensure a DPA is in place with any credential-sharing tool provider
  4. Train staff on the new process

The technical solution is simple. The organizational discipline to consistently use it is where most teams need to focus. For a broader look at tooling and practice, see secure password sharing for Dutch businesses.

Share this article
P
PassTransfer

The team behind PassTransfer writes about secure sharing, compliance and practical security for teams and agencies.

Ready to get started?

Sharing securely takes 10 seconds

Paste your password, pick an expiry time and share the link. Free and without an account.

Share a password