Organizations must assess breach risk within 72 hours, notify supervisory authorities if required, and inform affected individuals when high risk exists.
Data breach notification is a critical GDPR requirement demanding swift, systematic response to protect individuals and maintain compliance.
Immediate Response (0-24 hours) Contain the breach, assess scope and cause, and document all relevant details. Establish an incident response team including IT security, legal, and communications personnel.
Risk Assessment (24-72 hours) Evaluate likelihood and severity of risk to individuals' rights and freedoms. Consider data types involved, number of affected individuals, potential consequences, and existing safeguards like encryption.
Authority Notification (Within 72 hours) If the breach is likely to result in risk to individuals, notify the relevant supervisory authority. Include breach description, categories and approximate numbers of data subjects affected, likely consequences, and measures taken or proposed.
Individual Notification (Without undue delay) When breach is likely to result in high risk to individuals, notify affected data subjects directly. Use clear, plain language explaining the nature of the breach, contact point for more information, likely consequences, and measures taken.
Documentation Requirements Maintain comprehensive records of all breaches, regardless of notification requirements. Include facts, effects, and remedial actions taken.
Follow-up Actions Implement additional security measures, review policies and procedures, and cooperate with regulatory investigations.
Cybersecurity expert Kenny Hietbrink from Hack-IT stresses that preparation is key—having incident response plans and trained personnel significantly improves breach response effectiveness.
For personalized guidance, consult a Data Protection specialist on TinRate.
The following Data Protection experts on TinRate Wiki can help with this topic:
| Expert | Role | Company | Country | Rate |
|---|---|---|---|---|
| Bob van Bouwel | Your Lead-Out Legal | Lead-Out Legal | Belgium | EUR 100/hr |
| Kenny Hietbrink | Hack-IT | Netherlands | EUR 110/hr | |
| Niels Vandezande | Data, AI, Cybersecurity, Tech and Crypto/Payments Lawyer | Timelex | Belgium | EUR 200/hr |
| Tim Bracke | CISO / Security Expert | Trustbit | Austria | EUR 95/hr |