Data Breach Notification Duty

The data breach notification duty under Articles 33 and 34 GDPR requires controllers to report a breach of the protection of personal data that is likely to pose a risk to the people affected to the competent data protection authority within 72 hours of becoming aware of it. Where the risk is high, those people must be informed as well.

In practice

In practice, it pays to define a simple internal emergency plan before anything goes wrong: who is informed, who decides on the notification, what is documented. Without this preparation, valuable time is often lost in the first hours of a real data breach – time that is then missing within the tight 72-hour deadline. Incidents that do not have to be reported should also be documented internally, as the GDPR requires explicitly.

Sources

← Back to the glossary