Communication of High-Risk Personal Data Breach to the Data Subject, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 34(1).

Assessment Step

1
Communication of High-Risk Personal Data Breach to the Data Subject (CommunicationofHigh-RiskPersonalDataBreachtotheDataSubject)
When a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, does the entity communicate the breach to the affected data subjects without undue delay?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Communication of High-Risk Personal Data Breach to the Data Subject
The data controller must communicate the personal data breach to the data subject without undue delay when the breach is likely to result in a high risk to the rights and freedoms of natural persons.
Citation
GDPR
Art. 34(1), Recital 86