You are on page 1of 1

Download our GDPR Kit

http://hubs.ly/H06XByz0

GDPR MINI-WEBINAR SERIES

CYBER MANAGEMENT ALLIANCE’S


Key Facts from Episode 7 – Incident Response

A breach under the GDPR is accidental or unlawful destruction,


• loss, alteration, unauthorised disclosure of, or access to, personal
data transmitted, stored or other wise processed.

Data controllers are expected to report breaches to the super visor y


• authority within 72 hours of becoming aware, unless the breach is
not likely to affect the rights and freedoms of data subjects.

• Data processors are expected to notif y their controller without


undue delay.

• Data controllers are expected to notif y data subjects of any breaches


which may cause a risk to data subjects rights or freedoms. Unless it
is demonstrable that the breach data is unintelligible.

When reporting a breach to the supervisory authority, the data

• controller must disclose information such as the number of ac-


counts breached, its likely impact and steps to reduce the impact
to data subjects.

When notifying both the supervisory authority and data subjects of


• a breach, the data controller must provide the contact details of the
DPO or a responsible person for further information.

info@cm-alliance.com https://cm-alliance.com +44 203 189 1422 @cm_alliance

You might also like