Personal Data Breach Response
A personal data breach must, in general, be notified to the supervisory authority without undue delay and, where feasibl…
Personal Data Breach Response
A personal data breach must, in general, be notified to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it; where the breach is likely to result in a high risk, the data subjects must also be informed. We provide the breach-response procedure, the breach register and on-call support during an incident.
What it includes
- Breach-response playbook and register
- 72-hour notification to the CNPD
- Communication to data subjects, where required
Legal basis: GDPR, Arts. 33–34