01

What is needed for a clear procedure

An effective procedure allows an organization to quickly identify and contain a breach, assess the risk to individuals, and decide whether to notify the competent Authority and inform affected people.

Controllers and processors are encouraged to plan these steps in advance, so they can act promptly and objectively when an incident occurs.

02

What is a personal data breach

A personal data breach is a security breach leading to the destruction, loss, alteration, unauthorized disclosure of, or access to, personal data, whether accidental or unlawful. It is not only about 'losing' data: it includes incidents affecting confidentiality, integrity or availability, whether caused by error (an email sent to the wrong recipient, a lost USB key) or by deliberate acts such as phishing.

Not every security incident is a personal data breach: it is one only if personal data is involved.

03

The three fundamental obligations when acting as controller

  • Document every personal data breach, including those not notified because they were assessed as posing no risk
  • Notify the breach to the competent Data Protection Authority within 72 hours, unless risk is unlikely
  • Communicate the breach to affected individuals without undue delay if the risk to them is high
  • Use the forms or online procedures provided by the Authority for notification

04

Hypothetical example

Scenario: an SME discovers that an employee mistakenly sent an unencrypted customer list to the wrong external recipient. The controller assesses the risk, documents the incident, and — if risk to individuals cannot be excluded — notifies the Authority within 72 hours and informs affected customers, describing likely consequences and measures taken.

05

What to verify before and after an incident

  • Access permissions kept up to date and reviewed periodically, with unique identifiers per user
  • Sensitive data encrypted or pseudonymized to limit re-identification
  • A security policy for remote work and protection of personal devices (BYOD)
  • A log documenting details, assessment, effects and measures taken for every breach, even those not notified

06

How to set up the procedure with a software partner

A company can ask its software provider to support a central incident log, with fields for date, nature of the breach, people involved, risk assessment and measures taken, to make required documentation easier.

It is useful to define clear roles — who detects, who assesses risk, who decides on notification — and to keep track of decisions and communications to the Authority and to affected individuals, as a suggested operational choice rather than a legal requirement imposed by the software.

07

Operational steps to sequence

Steps

  1. Detect the incident and contain it as quickly as possible
  2. Assess whether personal data is involved and what risk people face
  3. Document details, assessment, effects and measures taken, regardless of outcome
  4. Notify the competent Authority within 72 hours if risk is not unlikely
  5. Communicate to affected individuals without undue delay if risk is high, except in cases such as encrypted data with uncompromised keys

08

Frequently asked questions

The following questions clarify aspects already covered in the article on data breach management procedures.

09

Next step

Check whether your organization already has a documented breach log and defined roles for risk assessment; if not, now is the time to set it up before an incident occurs.

FAQ

Frequently asked questions

Does every security incident need to be notified to the Authority?

No, only breaches involving personal data that create a risk that is not unlikely need to be notified within 72 hours; others must still be documented.

When must affected individuals be informed directly?

When the breach could result in a high risk to their rights and freedoms, except in cases such as encrypted data with intact keys or subsequent measures that eliminate the risk.

What must breach documentation include?

At least the fundamental details of the incident, the risk assessment, its effects and the measures taken, even if the breach is not notified to the Authority.

Sources and verification