← IP, GDPR & Cybersecurity

GDPR · Incident response

GDPR procedure for personal data breaches

A personal data breach can mean loss, disclosure, unauthorised access or unavailability, not just a sophisticated attack. The internal procedure must move swiftly from alert to triage, evidence preservation, impact reduction and the decision on notifying ANSPDCP and informing individuals.

72 hours risk analysis incident documentation
Authority notificationIf there is a risk, generally within 72 hours
IndividualsWithout undue delay if the risk is high
Continuing obligationAll breaches must be documented
01

From technical alert to data breach

Not every IT incident involves personal data, but every incident must be sufficiently triaged to establish which systems and people are affected. Sending an email to the wrong recipient, losing a device or ransomware locking data may fall within the definition of a breach.

The time of becoming aware is essential for calculating the 72 hours. The processor must inform the controller without undue delay, and the contract must enable swift access to the necessary information.

02

Risk analysis and the notification decision

The team analyses the likelihood and severity of consequences for individuals, not merely the cost to the company. Data type, volume, identifiability, individuals’ vulnerability and protective measures influence the conclusion.

  • Confidentiality: who received or can access the data.
  • Integrity: whether data was altered and which decisions may be affected.
  • Availability: the impact on individuals of being unable to access data.
  • Sensitivity: financial, medical, authentication or special-category data.
  • Measures: encryption, revocation of access, recovery and confirmation of deletion.
  • Consequences: fraud, discrimination, reputational harm or loss of control.
03

Notifying ANSPDCP and communicating with individuals

Where the breach is likely to create a risk, the controller notifies the authority without undue delay and, where possible, within 72 hours of becoming aware. Information may be provided in phases if not fully available, but delay must be justified.

If the risk to individuals is high, they are informed without undue delay, in clear language, with a description of the incident’s nature, likely consequences, measures and contact details. Exceptions must be analysed and documented.

04

The incident register and periodic exercises

The controller documents every breach, its effects and measures, including when deciding that notification is unnecessary. The file shows what information existed at the time of the decision and who approved the conclusion.

Tabletop exercises check contact numbers, log access, provider relationships and message approval. The procedure must align with the technical response plan, business continuity and applicable NIS2 or contractual obligations.

05

How we work together

  1. 01
    Collecting information

    We establish the processes, systems, providers, data categories, roles and existing documents relevant to the breach-response procedure.

  2. 02
    Risk and legality analysis

    We check purposes, legal bases, proportionality, time limits, transfers, security and risks to data subjects.

  3. 03
    Documents and workflow

    We draft the legal documents and align them with internal responsibilities, technical steps, evidence and response deadlines.

  4. 04
    Controlled implementation

    We deliver the final version, practical instructions and clear priorities; compliance is reviewed periodically when processes or providers change.

QUESTIONS

Frequently asked questions

Must every breach be notified to ANSPDCP?

No. Notification is unnecessary if the breach is unlikely to create a risk to individuals’ rights and freedoms, but the incident and assessment must be documented.

Do the 72 hours start from the attack?

The period runs from when the controller became aware of the breach, according to GDPR criteria and EDPB guidelines.

Must customers always be informed?

Direct communication is required where the breach is likely to result in a high risk, subject to the exceptions under Article 34.

Need a security-breach response procedure?

Send your documents for a legal assessment and a solution tailored to your commercial objective.