Notification of Personal Data Breach to the Data Controller, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 33(2).
Assessment Step
1
Notification of Personal Data Breach to the Data Controller (NotificationofPersonalDataBreachtotheDataController)
Does the entity notify the data controller without undue delay after becoming aware of a personal data breach?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Notification of Personal Data Breach to the Data Controller
The data processor must notify the data controller without undue delay after becoming aware of a personal data breach.
Citation
GDPR
Art. 33(2), Recital 85
|