Notification of Personal Data Breach to the Data Controller, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 33(2).

Assessment Step

1
Notification of Personal Data Breach to the Data Controller (NotificationofPersonalDataBreachtotheDataController)
Does the entity notify the data controller without undue delay after becoming aware of a personal data breach?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Notification of Personal Data Breach to the Data Controller
The data processor must notify the data controller without undue delay after becoming aware of a personal data breach.
Citation
GDPR
Art. 33(2), Recital 85