Secure & resilient

Data breach at Ceva Logistics: why this matters for your business too

Logistics provider Ceva Logistics was hit by a cyberattack in which personal data of former employees was stolen. A good moment to check how your own company handles data of people who left long ago.

All articles

Ceva Logistics, one of the larger logistics providers worldwide, has fallen victim to a cyberattack. Personal data was stolen, including data of people who no longer even work there: former employees. For an organisation of that size, this is unpleasant news, but not an earth-shattering event. For you as the owner of a transport or logistics business, it’s mainly something else: a good reason to take a calm look at your own situation.

Because the question isn’t whether this kind of attack affects your sector. That’s been happening for years, and logistics has long been on the list of attractive targets. The real question is: how well have you arranged what happens to the data of employees, drivers and subcontractors, even long after they’ve left?

What happened at Ceva

Attackers managed to steal personal data from Ceva Logistics, including data of people no longer employed there. That last detail matters. This isn’t about current payroll administration or a system used daily, but about data that has been sitting somewhere: in an archive, an old HR system, or a backup nobody actively manages anymore.

That’s exactly the pattern you see in many incidents like this. It’s usually not the newest, best-protected systems that are the problem, but the forgotten corners of the organisation.

This is not an isolated case

It’s tempting to dismiss this as “a Ceva problem”, a large international company operating on a different scale than your business. But the mechanism behind it is universal. Every company that employs people, or has employed people, holds personal data: copies of ID documents, contracts, pay slips, performance reviews, sometimes even application data from people who were never hired.

That data rarely disappears on its own. It stays in systems, folders and backups, often for years longer than necessary or legally allowed. And the longer data sits somewhere unattended, the greater the chance it becomes interesting to someone with bad intentions one day.

Former employees: the blind spot

At most companies, attention to data security focuses on active systems: email, the ERP package, planning software. That makes sense, since those are used daily. Data of people who left long ago rarely gets a second thought. Yet that information is often kept for years, without clear reason and without anyone taking responsibility for it.

The same applies to subcontractors and freelancers, something transport and logistics companies work with a lot. You hold personal data on them too: contracts, invoices with address details, sometimes copies of driving licences. If that data sits somewhere unmanaged, you’re responsible for it, even if it doesn’t concern your own staff.

What this means for liability and reputation

Under GDPR, as an employer you’re responsible for the personal data you process, including that of people no longer working for you. In case of a data breach, you must report it to the data protection authority and, in many cases, to those affected. That’s not just an administrative burden, it directly affects your reputation too.

In transport and logistics especially, the world is small. Clients, shippers and chain partners know each other, and news of a data breach travels fast. Increasingly, clients also explicitly ask how you handle information security, especially now that regulation such as NIS2 places demands on the entire chain. A weak spot on your end can be reason enough for them to look elsewhere.

What you can do now

The good news is that you can make real progress here without major investment.

  • Map out which personal data you hold on former employees, former drivers and subcontractors, and where it’s stored.
  • Look at retention periods. Legal terms apply to much personnel data; anything kept beyond that can simply be deleted.
  • Limit who has access to HR and payroll systems, including old archives.
  • Ask payroll providers, HR software vendors and subcontractors how they handle this data. You remain ultimately responsible, even if another party manages it.
  • Make sure you know what to do if things do go wrong: who to inform, within what timeframe and how.

This doesn’t have to be a big project. It starts with half an hour of thinking about where old data actually sits, and whether it still needs to be there.

A few questions we’re often asked

How long am I actually allowed to keep former employees’ data?

It depends on the type of data. Payroll records must be kept for seven years for the Dutch tax authority, but many other HR records, such as performance reviews or a copy of an ID, can go after two years or sooner. Anything still lying around after that is a risk with no benefit. Set a simple rule per category and stick to it.

My payroll is handled by an external provider. Am I still responsible?

Yes. Under the GDPR you remain the data controller, even when a payroll provider or HR software vendor manages the data for you. Put retention and security in a data processing agreement, and simply ask them about it now and then.

What should I do if former employees’ data leaks at our company after all?

Report it to the Dutch Data Protection Authority within 72 hours and inform the people involved if there is a risk to them, even if they left years ago. Decide in advance who handles this and where the contact details are, so you’re not searching in the middle of an incident.

Does this also apply to drivers and subcontractors who aren’t employees?

Yes. Copies of driving licences, contracts and invoices with address details of freelancers and subcontractors are personal data you’re responsible for too. In transport and logistics this is a frequently forgotten pile.


We regularly help companies in transport, logistics and wholesale map out blind spots like this, without complicated jargon and without unnecessary alarm. Want to know where things stand at your company? We’re happy to think it through with you.

Newsletter

Practical IT insights, once a month

What happened, what it means for your business and one thing you can do today. No sales talk, unsubscribe anytime.

We only use your address for the newsletter. See our privacy statement.

Questions about your own IT?

Take the free scan and see how your own IT is doing, instead of leaving it at general knowledge. Want to talk it through? A no-strings intro call is always an option.

Free and no-strings, no sales pitch.

May we measure what helps you?

Analytical cookies show us which pages help you and which don't, so we can improve the site. No ads, no selling of data. We only place them after your consent. Read our cookie policy.

You can change your choice later via ‘Cookie preferences’ at the bottom of every page.