Jeroen van Helden

Jeroen van Helden

Senior Associate | Attorney at law

IT, Privacy & Cybersecurity

Jeroen van Helden acts as lead counsel in matters concerning IT transactions and IT disputes. He also advises clients in the event of cyber attacks and cyber incidents. Jeroen has specific expertise in software licensing, data protection, IT contracts and compliance issues, and enjoys sharing his IT law knowledge and enthusiasm for his field through professional journals, seminars and courses.

Jeroen works a great deal for IT companies ranging from cloud service providers, app builders and managed service providers, to cybersecurity experts. On the buyer side, he frequently works for government authorities, international organisations and companies in the education, healthcare and transport sectors. He is just as enthusiastic about engaging with a CEO on a strategic matter as he is about working with in-house counsel on a complex case. He takes a result-oriented, meticulous and discreet approach to his work.

Education

Jeroen studied Law at the University of Amsterdam and the University of Michigan, graduating cum laude. In 2022, he successfully completed the Grotius specialist programme in Information Technology Law (also cum laude) and in 2023 the specialist programme in Cybercrime & Cybersecurity at Leiden Law Academy.

Career

During his studies, Jeroen worked as a coach in European legal history, gained experience at a law firm in The Hague, and learnt website programming. After earning his Master’s degree, he worked for the government for several years as an IT lawyer, before joining the De Clercq technology team in 2018.

Jeroen's daily practice

Jeroen’s daily practice involves providing advice and litigating in the field of IT law on matters such as transactions for cloud services (SaaS, PaaS, IaaS), the implementation of ERP systems, or complex international privacy issues. He has extensive experience in resolving IT-related disputes, whether by mediation or arbitration, or before the public courts. He is also frequently called upon to assist in the event of major cyber attacks or other cyber incidents, including ransomware attacks, DDoS attacks, CEO fraud, or theft of trade secrets.

Selected cases

Lead counsel for an international organisation in relation to multi-million euro transactions for the use of Google Cloud and AWS (IaaS, PaaS).

Providing advice to a major Dutch e-learning provider regarding a transaction for using a learning management platform (PaaS, SaaS).

Lead counsel for a Dutch software developer with respect to transactions with various research institutions and technology companies in countries such as the U.S., Australia and Switzerland.

Providing advice to a managed service provider in the wake of a major ransomware attack.

Representing a Dutch IT company in a court case relating to a failed agile software development project, which resulted in the plaintiff’s claim of over a million euros being dismissed.

Providing advice to a Dutch company involved in a dispute with an American technology company about matters including unilateral modification of the licence metrics of a low-code platform.

Representing a Dutch/Spanish retailer in international mediation proceedings concerning a failed ERP implementation, resulting in damages from both the software supplier and the implementation partner.

Providing advice to a Dutch SaaS provider on the status of a SaaS solution developed for use in hospitals, under the Medical Devices Regulation (MDR).

Providing advice to an international organisation regarding defence against a multi-million euro claim filed by a U.S. software vendor relating to additional use of on-premises software in connection with a data centre migration.

Representing a Dutch government organisation in a historical arbitration case concerning a failed IT project. It resulted in the recovery of tens of millions of euros from the IT supplier for the benefit of the Dutch taxpayer.

Stay up to date

The latest developments

IT, Privacy & Cybersecurity

The EU e-Evidence Package: What Service Providers Need to Know

30 July 2026

From 18 August 2026, a new EU framework will change how law enforcement authorities obtain electronic evidence from service providers. If your organisation offers services to users in the European Union – whether as a cloud provider, hosting company, messaging platform or domain name service provider – the e-Evidence Package may affect you.

Read more

IT, Privacy & Cybersecurity

AI Act alert: is your AI system considered ‘high risk’? Check the new draft guidelines!

26 May 2026

Op 19 May 2026, the European Commission (EC) published its draft guidelines on the classification of high-risk AI systems. The good news is that the guidelines provide greater clarity. The bad news is that this may result in more AI systems falling within this category. Below, we outline the key points of the guidelines.

 

Read more

IT, Privacy & Cybersecurity

EU Reaches Political Agreement on Amendments to the AI Act

8 May 2026

The European Union has reached a political agreement on an amendment to the AI Act. This does not yet constitute final legislation, but the direction is clear: the introduction of various obligations for high-risk AI systems is likely to be postponed. The amendment follows widespread concerns among businesses, regulators and Member States regarding the feasibility of implementing the rules, partly because sufficient standards and practical guidance are still lacking.

Read more