← All articles

redaction

CEVA Logistics: data leak at supplier — Bol and De Bijenkorf customers warned

On August 6, 2026, Bol and De Bijenkorf warned customers that a possible data leak at CEVA Logistics may have exposed names, addresses and phone numbers. The Dutch DPA was notified on August 3; no payments or passwords are implicated so far.

On August 6, 2026, Dutch retailers Bol and De Bijenkorf emailed some customers about a “possible data leak” at supplier CEVA Logistics that may have exposed personal data (name, address, postcode, phone number). Bol states its own systems were not hit and that the incident is limited to order fulfillment at a single distribution center. CEVA reported a possible unauthorized access on August 1; the Dutch Data Protection Authority was notified on August 3. There is no indication that payment data, passwords or login credentials were affected, but delays/cancellations and temporary data‑flow suspensions were implemented as a precaution.

Legal basis

  • GDPR Article 33: notify the supervisory authority within 72 hours after becoming aware of a breach likely to pose a risk. The timeline (Aug 1–3) suggests the deadline was met.
  • GDPR Article 34: inform data subjects when the breach is likely to result in a high risk, which explains the August 6 customer emails.
  • GDPR Article 28: processor controls (CEVA) with security, assistance and cooperation obligations.
  • GDPR Article 32: appropriate technical and organizational measures, including access control and logging at logistics providers.

This case highlights a classic supply‑chain risk and the need to control processors. For the full regulatory background, see key GDPR obligations and notification timelines.

What changes for Luxembourg companies

  • Beyond core IT: significant customer data transits through 3PLs, carriers and external warehouses; compromising a single site can trigger notifications.
  • Controller accountability: due diligence, contract clauses, audits, testing, logging and sub‑24h contractual incident reporting are essential.
  • Tight deadlines: 72 hours to notify the authority (Art. 33) and “without undue delay” to inform data subjects (Art. 34).
  • Business risk: delays/cancellations and suspended flows cause immediate operational and reputational costs.

Practical actions this week

  • Obtain written commitments from your 3PLs on incident reporting SLAs and their ability to provide, within 24h, the categories of data and the customers/orders potentially affected; reflect these in Article 28 addenda.
  • Exercise your supply‑chain incident plan: fallback/suspension procedures, pre‑drafted Art. 34 messages (FR/NL/DE), and decision matrix for DPA/customer notification; run a 90‑minute tabletop.
  • Refine logistics processing records (Art. 30) and apply data minimization; enforce short retention and verifiable purge at the processor.

To structure governance and notifications, consider a certified DPO mandate focused on compliance and incident handling. For operational resilience against 3PL disruptions, leverage a continuity plan (BCP/DRP) tailored to supply‑chain outages.

Sources

Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →