Notification of Personal Data Breach to the Supervisory Authority, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 33(1).

Assessment Step

1
Notification of Personal Data Breach to the Supervisory Authority (NotificationofPersonalDataBreachtotheSupervisoryAuthority)
Does the entity notify the supervisory authority of personal data breaches without undue delay and, where feasible, within 72 hours after becoming aware of them, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Notification of Personal Data Breach to the Supervisory Authority
The data controller must notify the supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.
Citation
GDPR
Art. 33(1), Recital 85