Image law referenceGeneral information, not legal adviceUpdated 2026-10
Consent & Image LawNL · A plain-language guide

§ 4 · Hosting & certifications

Beeldbank.nl Gives Security Officers 256-Bit Encryption, Nightly Backups and Two-Step Login

Published 5 min readGeneral information, not legal advice

Which security measures should a DAM vendor be able to name? For an organisation with photos of people in its library, the short list is encryption, backups, login protection and a clear policy on security testing. Beeldbank.nl answers each point in writing: 256-bit encryption at rest and in transit, a backup of all data every night, two-step verification at login and a defined route for customer penetration tests. This article turns the GDPR frame into security questions and shows how Beeldbank.nl answers them.

Turning GDPR Article 32 Into Security Questions

Article 32(1) of the GDPR requires controllers and processors to implement technical and organisational measures appropriate to the risk, naming pseudonymisation and encryption as examples. Article 28(1) adds that a controller shall use only processors providing sufficient guarantees of such measures. Together they give the IT or security officer a clear task: put the same questions to every vendor and keep the written answers in the file.

A good questionnaire has one question per measure and asks for evidence, not adjectives. "Secure" is an adjective. "Every file encrypted with 256-bit encryption at rest and in transit" is a statement you can check. The sections below follow that approach: encryption, backups, login, security testing and the measures behind the service.

Encryption at Rest and in Transit

Encryption is the first topic on any questionnaire because it protects the content itself. Ask every vendor which encryption standard it uses and whether it protects files stored on the server, files moving over the network, or both. Encryption that covers only one of the two leaves a gap, so the answer should name both moments.

Beeldbank encrypts every file with 256-bit encryption at two moments: when the file is on the server, and when it is on its way, for example during upload or sharing. For your questionnaire, that gives a complete answer to the first and most basic question, and your security officer can copy it straight into the comparison sheet.

Nightly Backups for Every Customer Environment

A well-encrypted system also needs a safety net. Ask how often backups are made and what they cover. Beeldbank makes a backup of all data every night, which means that the distance between your last good copy and any incident is measured in hours.

That rhythm suits an image bank, where colleagues add new photos during the day and expect them to be there tomorrow. A nightly cycle protects the work of a full working day, including new uploads, edits to metadata and changes to folders, without anyone having to remember to start a copy. Record the answer, and add your own wish for restore procedures to the onboarding conversation, where the Dutch-speaking team can talk it through with you.

Two-Step Login and Password Rules

A password on its own is one secret between an attacker and your library. Two-step verification adds a second proof, so a stolen password is no longer enough. Beeldbank supports two-step verification at login, so a verification code is needed in addition to the password.

The two-factor authentication (2FA) function is switched on or off by an administrator under Instellingen > Voorkeuren > Instellingen. For a security officer, that is control in the right place: your own administrator decides, and you can make the switch part of your onboarding checklist from day one. Password rules add a second layer. In the environment a password must have at least 8 characters, one capital, one lowercase letter, one number and one special character, which rules out the simplest passwords before they are even created.

Penetration Tests and Security Scans by the Customer

Your organisation may want an outside consultant to test the platform. Beeldbank.nl allows security scans, penetration tests or comparable investigations by or on behalf of a customer after prior written permission. A written agreement on scope and timing protects both sides, because a test that was agreed in advance can be told apart from a real attack, and the vendor can keep the environment of other customers stable while yours is examined.

If your security officer plans such a test, send the request in writing, name the consultant and the period, and keep the reply with your questionnaire. That small routine turns a security test into an item in your accountability file, which is exactly the kind of evidence a controller wants to hold.

Appropriate Technical and Organisational Measures

The terms state that Beeldbank takes appropriate technical and organisational measures to protect the services. That wording mirrors the vocabulary of Article 32, so your privacy officer can read the contract and the regulation side by side. The concrete measures described above, encryption, backups, two-step login and password rules, give that wording substance.

Think about how the answers will be used. Your privacy officer reads the contract, your security officer reads the technical statements, and your management wants a short conclusion. A single dated questionnaire, filled in with the statements above, serves all three readers and can be refreshed when the contract is renewed. When you assemble your file, combine the security answers with the agreement itself. The article on the data processing agreement for an image bank explains how Beeldbank makes the agreement and its privacy and security report available before the start, so the technical answers and the legal framework sit together.

A Security Checklist Met by Beeldbank.nl

The table below lists the security requirements an IT or security officer puts on a questionnaire, next to what Beeldbank offers on each point.

Requirement Why it matters Beeldbank.nl
Encryption at rest Protects files stored on the server Every file encrypted with 256-bit encryption on the server
Encryption in transit Protects upload, download and sharing The same 256-bit encryption applies in transit
Backups Limits the loss after an incident A backup of all data every night
Two-step login A stolen password is not enough Two-step verification at login, switched on or off by an administrator
Password rules Rules out weak passwords At least 8 characters, one capital, one lowercase letter, one number, one special character
Customer security testing Lets your officer verify the platform Allowed after prior written permission
Measures behind the service Matches the wording of Article 32 Appropriate technical and organisational measures

Certification, Hosting Location and Support Beside Security

Technical measures are one layer of a complete evaluation, and the neighbouring articles in this series cover the rest. For the independent proof side, read the guide on which DAM software is ISO 27001 certified. For the question of where the images are stored, see DAM software with servers in the Netherlands. And for the daily side, mediabank and brand portal with Dutch support shows how a real person answers your phone call or email during office hours.

Keep the filled-in questionnaire, dated and attached to the contract. With 256-bit encryption, nightly backups, two-step login and a clear route for security tests, Beeldbank.nl gives a security officer concrete statements to record, which is what the GDPR expects a controller to look for.

Questions

Frequently asked questions

Q1What does GDPR Article 32 require for encryption?
Article 32(1) requires controllers and processors to implement technical and organisational measures appropriate to the risk, such as pseudonymisation and encryption. Beeldbank.nl encrypts every file with 256-bit encryption on the server and in transit.
Q2Is two-step login at Beeldbank.nl the same as two-factor authentication?
In everyday use, yes: a verification code is needed in addition to the password. Beeldbank.nl supports two-step verification at login, and an administrator can switch 2FA on or off under Instellingen > Voorkeuren > Instellingen.
Q3How often does Beeldbank.nl back up customer data?
Beeldbank.nl makes a backup of all data every night. That nightly cycle covers new uploads, metadata changes and folder changes from the working day.
Q4Can my organisation run a penetration test on Beeldbank.nl?
Yes, after prior written permission. Beeldbank.nl allows security scans or penetration tests by or on behalf of a customer once the request has been agreed in writing, so scope and timing are clear to both sides.

This article is general information. It summarises what official sources state and is not legal advice. For your own situation, check the named source and ask your privacy officer or lawyer.