Jeroen van Helden

Jeroen van Helden

Senior Associate | Attorney at law

IT, Privacy & Cybersecurity

Jeroen van Helden acts as lead counsel in matters concerning IT transactions and IT disputes. He also advises clients in the event of cyber attacks and cyber incidents. Jeroen has specific expertise in software licensing, data protection, IT contracts and compliance issues, and enjoys sharing his IT law knowledge and enthusiasm for his field through professional journals, seminars and courses.

Jeroen works a great deal for IT companies ranging from cloud service providers, app builders and managed service providers, to cybersecurity experts. On the buyer side, he frequently works for government authorities, international organisations and companies in the education, healthcare and transport sectors. He is just as enthusiastic about engaging with a CEO on a strategic matter as he is about working with in-house counsel on a complex case. He takes a result-oriented, meticulous and discreet approach to his work.

Education

Jeroen studied Law at the University of Amsterdam and the University of Michigan, graduating cum laude. In 2022, he successfully completed the Grotius specialist programme in Information Technology Law (also cum laude) and in 2023 the specialist programme in Cybercrime & Cybersecurity at Leiden Law Academy.

Career

During his studies, Jeroen worked as a coach in European legal history, gained experience at a law firm in The Hague, and learnt website programming. After earning his Master’s degree, he worked for the government for several years as an IT lawyer, before joining the De Clercq technology team in 2018.

Jeroen's daily practice

Jeroen’s daily practice involves providing advice and litigating in the field of IT law on matters such as transactions for cloud services (SaaS, PaaS, IaaS), the implementation of ERP systems, or complex international privacy issues. He has extensive experience in resolving IT-related disputes, whether by mediation or arbitration, or before the public courts. He is also frequently called upon to assist in the event of major cyber attacks or other cyber incidents, including ransomware attacks, DDoS attacks, CEO fraud, or theft of trade secrets.

Selected cases

Lead counsel for an international organisation in relation to multi-million euro transactions for the use of Google Cloud and AWS (IaaS, PaaS).

Providing advice to a major Dutch e-learning provider regarding a transaction for using a learning management platform (PaaS, SaaS).

Lead counsel for a Dutch software developer with respect to transactions with various research institutions and technology companies in countries such as the U.S., Australia and Switzerland.

Providing advice to a managed service provider in the wake of a major ransomware attack.

Representing a Dutch IT company in a court case relating to a failed agile software development project, which resulted in the plaintiff’s claim of over a million euros being dismissed.

Providing advice to a Dutch company involved in a dispute with an American technology company about matters including unilateral modification of the licence metrics of a low-code platform.

Representing a Dutch/Spanish retailer in international mediation proceedings concerning a failed ERP implementation, resulting in damages from both the software supplier and the implementation partner.

Providing advice to a Dutch SaaS provider on the status of a SaaS solution developed for use in hospitals, under the Medical Devices Regulation (MDR).

Providing advice to an international organisation regarding defence against a multi-million euro claim filed by a U.S. software vendor relating to additional use of on-premises software in connection with a data centre migration.

Representing a Dutch government organisation in a historical arbitration case concerning a failed IT project. It resulted in the recovery of tens of millions of euros from the IT supplier for the benefit of the Dutch taxpayer.

Stay up to date

The latest developments

IT, Privacy & Cybersecurity

Are your data processing agreements prepared to withstand a cyberattack?

25 November 2025

Cyberattacks are increasingly targeting service providers that process personal data on behalf of multiple organisations. A data breach at such a service provider can have serious consequences for hundreds of organisations and millions of individuals. The Dutch Data Protection Authority (AP) recently examined the role of data processing agreements in major cyberattacks and issued recommendations to help limit the damage.

Read more

IT, Privacy & Cybersecurity

Waiver of rights in public procurement: when is “too late” really too late?

17 November 2025

In public procurement procedures, bidders are expected to adopt a proactive attitude. This has once again been confirmed in a recent judgment of the District Court of Oost-Brabant.

Read more

IT, Privacy & Cybersecurity

Transparency remains mandatory, even when transferring pseudonymised personal data

22 September 2025

On 4 September 2025, the Court of Justice of the EU delivered a judgment in case C-413/23 P (EDPS / SRB). The judgment provides clarity on a fundamental question within data protection law: when do pseudonymised data qualify as ‘personal data’ under the GDPR?

Read more