An investigation by NOS and Nieuwsuur revealed that Dutch municipalities were inadvertently publishing citizens’ personal data online, despite long-standing awareness of the issue. Documents containing email addresses, phone numbers, and home addresses were publicly accessible, with some even including sensitive information like identification and citizen service numbers. This occurred when citizens applied for permits or responded to local proposals, utilizing the Public Access to Government Information Act (WOO). The exposure of such data constitutes a data breach, prompting municipalities like Voorschoten to remove documents after discovering personal information of foundation administrators – including passport numbers – had been compromised. While no misuse of data has been detected, the incident is considered serious, and authorities have been notified. The Privacy Authority (AP) previously warned municipalities about this risk in 2017, receiving numerous reports of similar incidents, and is now being revisited due to this new exposure.