01
The short answer
An understandable procedure for a data breach defines in advance who detects the incident, who assesses the risk, and who decides whether to notify the Data Protection Authority or communicate the event to affected individuals. Controllers and processors are encouraged to plan these steps before an incident occurs, so they can act promptly and objectively.
02
What is a personal data breach
A personal data breach is a security breach that leads to destruction, loss, alteration, unauthorised disclosure of, or access to personal data, whether accidental or unlawful. Not every security incident is a data breach: it only qualifies as such when personal data is involved. This includes both unintentional mistakes, such as sending an email to the wrong recipient, and deliberate acts, such as phishing.
03
The three fundamental rules for those acting as a processor
Steps
- Document every personal data breach, even those assessed as posing no risk.
- Notify the competent Data Protection Authority within 72 hours, unless a risk to individuals is unlikely.
- Communicate the breach to affected individuals without undue delay if the risk to them is high.
- Record at least the essential details of the incident, its assessment, its effects, and the measures taken, as required by Article 33(5) of the GDPR.
04
Hypothetical example
Scenario: an employee loses a USB drive containing customers' personal data. The data protection officer detects the incident, assesses whether encryption keys were compromised, and determines whether the risk to individuals is high before deciding on notification to the Authority or communication to customers.
05
Elements to have ready before an incident
- Unique identifiers and authentication to access IT systems.
- Permission management with periodic review and removal of outdated access rights.
- Encryption of data to prevent unauthorised access.
- A security policy for remote work and protection of personal devices used for work (BYOD).
- A form or procedure to quickly record the nature, effects, and measures taken for each incident.
06
What a company can configure to govern the process
An organisation can define with its software partner who is responsible for detecting, assessing, and recording an incident, keeping track of the date, nature of the event, risk assessment, and measures taken, in line with the documentation requirement of Article 33(5). These are operational choices to configure or request, not features that are already built in.
07
Frequently asked questions about the internal process
- Who must document a breach? The controller, for every incident, even when it is not notified to the Authority.
- When should individuals be notified? Without undue delay, when the risk to their rights and freedoms is high.
- Is notifying the Authority always required? No, if a risk to individuals is unlikely.
08
Next step
Define with your team who detects, who assesses the risk, and who decides on notification, before a real incident occurs.
FAQ
Frequently asked questions
What is the difference between a security incident and a personal data breach?
A security incident becomes a personal data breach only if it involves personal data, through destruction, loss, alteration, or unauthorised access.
What must the communication to affected individuals contain?
It must include the contact details of the data protection officer, a description of the likely consequences of the breach, and the measures taken or proposed to address it and mitigate its effects.
In which cases is it not necessary to notify affected individuals?
When the data was encrypted and the keys were not compromised, when subsequent measures eliminate the high risk, or when notification would require disproportionate effort — in which case a public communication of equivalent effectiveness is still required.
✓