01

The short answer

A clear procedure for a personal data breach should be prepared in advance, not improvised during an emergency. It must allow you to quickly identify and contain the incident, assess the risk to individuals, and decide whether to notify the data protection authority and inform the people affected.

02

What distinguishes a security incident from a data breach

Not every security incident is a personal data breach: it becomes one only when personal data is involved. A personal data breach is a security incident that leads to destruction, loss, alteration, unauthorized disclosure of, or access to personal data, whether by human error or deliberate acts such as phishing.

03

The operational sequence to put in writing

Steps

  1. Detect and contain the incident as soon as it is identified, limiting access to the affected data.
  2. Assess the concrete risk to the individuals affected by the breach.
  3. Always document the details, risk assessment, effects and measures taken, even if the breach is not notified to the authority.
  4. Notify the competent data protection authority within 72 hours, unless the risk to individuals is unlikely.
  5. Communicate the breach to the affected individuals without undue delay if the risk to them is high.

04

A hypothetical case

Hypothetical example: an employee mistakenly sends a file with customers' personal details to the wrong external recipient. This is a personal data breach even if unintentional. The procedure calls for: containing it immediately by recalling the email if possible, assessing how much data and which categories are involved, documenting what happened, and, if the risk to customers is high, informing them in clear language about the likely consequences and the measures taken.

05

Controls to have ready before you need them

  • Authentication and unique identifiers for every user accessing the systems.
  • Access management with separate profiles and periodic review of permissions.
  • Encryption of data to prevent unauthorized access in case of theft or loss.
  • Timely removal of outdated access permissions.
  • An internal log documenting every breach, including those not notified to the authority.

06

How management software can support this process

A company can ask its software partner to set up a traceable path: who detects the incident, who assesses it, who decides on notification, and who communicates with those affected, with the date and time of each step. This does not replace the legal risk assessment, but it makes the sequence of decisions reconstructable and keeps the documentation required for every breach, even those not notified.

07

Frequently asked questions

Do we have to notify every breach to the authority? No: notification is not needed when it is unlikely that the breach poses a risk to individuals, but internal documentation is still required.

When must we inform the affected individuals directly? When the breach may pose a high risk to their rights and freedoms, and the communication must happen without undue delay.

What must the communication to individuals contain? The contact for more information, the likely consequences of the breach, and the measures taken or proposed to address it and mitigate its effects.

08

Next step

Put the detection, assessment and notification sequence in writing today, before a real incident occurs: this is the difference between an orderly response and an improvised one.

FAQ

Frequently asked questions

Do we have to notify every breach to the data protection authority?

No: notification is not needed when it is unlikely that the breach poses a risk to individuals. Internal documentation, however, is still required in every case.

When is it necessary to communicate the breach directly to those affected?

When the breach may pose a high risk to their rights and freedoms. The communication must happen without undue delay and, where appropriate, in cooperation with the competent authority.

Is a data breach always a cyberattack?

No: it can also result from unintentional errors, such as sending an email to the wrong recipient or losing a USB key, not only from deliberate acts such as phishing.

Sources and verification