What are NAWT details?
NAWT is Dutch administrative shorthand for naam, adres, woonplaats, telefoonnummer — name, address, place of residence and telephone number. They are the four fields Dutch forms, suppliers and helpdesks ask for most often, sometimes labelled "nawt", sometimes "naw", sometimes simply "your details". A date of birth or citizen service number is not part of it.
So this is not a technical term but an administrative one. Which is exactly why it is fragile: these are details anyone could write down about you, and in practice they are used as if they were passwords.
Why this is not an innocent question
Many organisations verify your identity with NAWT data: the helpdesk asks your date of birth and address before anyone will speak to you, the supplier invoices "the known address", the carrier confirms a number transfer after three questions. That is dangerous, because it treats publicly reconstructable data as proof of who you are.
An attacker does not need to break anything. They look up your name at the chamber of commerce, your address on a delivery list, your number on a job posting, and call. In the Netherlands that is no longer theory: after the Odido and Ben leak (6.2 million records, February 2026) it became clear how widely this data circulates. Taking over your number afterwards is a matter of phoning with the right answers.
What to do about it
- Ask for no more than necessary. The GDPR calls it data minimisation. A supplier wanting your date of birth to deliver a parcel usually does not need it.
- Keep it no longer than necessary. An old customer file with NAWT data on ten thousand people is not an asset, it is a liability with an expiry date.
- Do not send it by e-mail. Mail is a postcard. For sensitive data there are portals and encryption.
- The main rule: NAWT data is not identification. Where it truly matters, use a real second factor, not an address question.
For staff: the "helpdesk" call
Helpdesk phishing does not use technique but NAWT data: "to verify, your date of birth and the last four digits". Your staff need to know two things:
- Genuine support never asks for a one-time code or password, and never treats a date of birth as the only proof.
- When in doubt: hang up and call back to a number you looked up yourself. Never the number the caller gives you.
And for the employer: if an employee mishandles that call, the damage is not their fault but a process that trusted addresses. We build that verification differently: a message in your own chat, or a confirmation inside a system the employee already knows.
Recovery codes: the most common failure
Nearly everyone received them and almost nobody knows where they are: recovery codes from Google, Microsoft, Apple, your password manager or your bank. Lose your phone or your authenticator and they are your only rescue. Lose both and you are not the victim of an attack but of administration — and the account is still gone.
The correct way:
- Generate new codes and download or print them immediately after enabling, not later.
- Store them in two places: in your password manager and on paper under lock, never in your mail or only on your phone.
- Give every account a recovery route you can actually reach: a second device, a trusted person, or a fixed number not tied to one SIM.
- Test it. A recovery method never tried is a guess.
Where to find your codes
| Service | Where |
|---|---|
| myaccount.google.com → Security → 2-Step Verification → Backup codes | |
| Microsoft | account.microsoft.com → Security → Advanced security options |
| Apple | Settings → Password & Security → Recovery Keys / Recovery Contact |
| Settings → Account → Two-step verification (PIN plus recovery e-mail) | |
| Dutch banks | Mostly inside the banking app or via support; some require an appointment at a branch |
| DigiD | DigiD app or digid.nl; if the app is lost, identity verification is required |
What GSAP does for you
- Inventory. Which accounts exist, who has access, and what happens when that person is unavailable or leaves.
- Recovery plan. Per account: which factor, where the codes live, who the backup person is, and what the service itself demands.
- Keys in case of absence. Agreements for illness, departure and death — in the Netherlands you can register who manages your digital estate, and that is not a detail but the only route to your own data.
- Drills. An untested recovery plan is a text. We run one exercise a year with you.
- Devices included. On a privacy phone or managed laptop, codes and profiles can actually be recovered; on a departed employee's private device, often not.
Questions
May a supplier ask for all my NAWT details?
Only what the purpose requires. Ask why. Refusing to hand over unnecessary data is your right, and a supplier that refuses you for it tells you something.
What if I lost my recovery codes?
Generate new ones from a device you are still signed in on and store them twice this time. If that fails, an identity check at the service itself begins; our influence ends there and your patience starts.
Is a password manager not enough?
For passwords: yes. For recovery codes and routes: only if the manager itself has a sound recovery route, and someone else can reach the account when you cannot.
Do we do this per employee?
Per account, not per person. That is why the inventory comes before the advice.
Back to the overview · Privacy phone with GrapheneOS · Ask about a recovery plan