A data breach is a breach of the security of personal data, for example through loss, unauthorised access or accidental disclosure.
Notifying and responding
Notifiable data breaches must be reported to the supervisory authority within 72 hours. A well-practised internal reporting chain is essential if the deadline is to be met at all.
Typical cases
- email containing personal data sent to the wrong recipient
- loss of an unencrypted laptop or USB stick
- ransomware attack with encryption or exfiltration of data
- databases openly accessible on the internet
A distinction is made between breaches of confidentiality, integrity and availability.
Documentation
Every data breach must be documented internally, even if it is not notifiable. The documentation covers the facts, the effects and the remedial action taken.
Legal provisions
- Art. 4(12) GDPR
- Definition of a personal data breach.
- Art. 33 GDPR
- Notification to the supervisory authority and documentation obligation.
- Art. 34 GDPR
- Communication to data subjects where there is a high risk.