GDPR · Incident response
GDPR procedure for personal data breaches
A personal data breach can mean loss, disclosure, unauthorised access or unavailability, not just a sophisticated attack. The internal procedure must move swiftly from alert to triage, evidence preservation, impact reduction and the decision on notifying ANSPDCP and informing individuals.
From technical alert to data breach
Not every IT incident involves personal data, but every incident must be sufficiently triaged to establish which systems and people are affected. Sending an email to the wrong recipient, losing a device or ransomware locking data may fall within the definition of a breach.
The time of becoming aware is essential for calculating the 72 hours. The processor must inform the controller without undue delay, and the contract must enable swift access to the necessary information.
Risk analysis and the notification decision
The team analyses the likelihood and severity of consequences for individuals, not merely the cost to the company. Data type, volume, identifiability, individuals’ vulnerability and protective measures influence the conclusion.
- Confidentiality: who received or can access the data.
- Integrity: whether data was altered and which decisions may be affected.
- Availability: the impact on individuals of being unable to access data.
- Sensitivity: financial, medical, authentication or special-category data.
- Measures: encryption, revocation of access, recovery and confirmation of deletion.
- Consequences: fraud, discrimination, reputational harm or loss of control.
Notifying ANSPDCP and communicating with individuals
Where the breach is likely to create a risk, the controller notifies the authority without undue delay and, where possible, within 72 hours of becoming aware. Information may be provided in phases if not fully available, but delay must be justified.
If the risk to individuals is high, they are informed without undue delay, in clear language, with a description of the incident’s nature, likely consequences, measures and contact details. Exceptions must be analysed and documented.
The incident register and periodic exercises
The controller documents every breach, its effects and measures, including when deciding that notification is unnecessary. The file shows what information existed at the time of the decision and who approved the conclusion.
Tabletop exercises check contact numbers, log access, provider relationships and message approval. The procedure must align with the technical response plan, business continuity and applicable NIS2 or contractual obligations.
How we work together
- 01Collecting information
We establish the processes, systems, providers, data categories, roles and existing documents relevant to the breach-response procedure.
- 02Risk and legality analysis
We check purposes, legal bases, proportionality, time limits, transfers, security and risks to data subjects.
- 03Documents and workflow
We draft the legal documents and align them with internal responsibilities, technical steps, evidence and response deadlines.
- 04Controlled implementation
We deliver the final version, practical instructions and clear priorities; compliance is reviewed periodically when processes or providers change.
Frequently asked questions
Must every breach be notified to ANSPDCP?+
No. Notification is unnecessary if the breach is unlikely to create a risk to individuals’ rights and freedoms, but the incident and assessment must be documented.
Do the 72 hours start from the attack?+
The period runs from when the controller became aware of the breach, according to GDPR criteria and EDPB guidelines.
Must customers always be informed?+
Direct communication is required where the breach is likely to result in a high risk, subject to the exceptions under Article 34.
Need a security-breach response procedure?
Send your documents for a legal assessment and a solution tailored to your commercial objective.
Aveți nevoie de asistență juridică urgentă sau de consultanță de specialitate?
Notă juridică și limitarea răspunderii
Informațiile și articolele publicate pe acest site web sunt puse la dispoziție de Avocatul „Basuc Cosmin Ștefan” exclusiv în scop informativ și educativ general. Materialele prezentate reprezintă analize teoretice și opinii de specialitate la data redactării lor, fără a constitui consultanță juridică, asistență legală sau o opinie aplicabilă unui caz concret. Lectura sau utilizarea acestui conținut nu creează o relație profesională avocat-client între cititor și Cabinet. Având în vedere dinamica legislativă și specificul fiecărei situații de fapt, interpretările conținute nu pot substitui analiza individuală a unei cauze. Pentru stabilirea cadrului juridic aplicabil problemei dumneavoastră și obținerea unei consultații profesionale dedicate, vă invităm să contactați Cabinetul prin mijloacele oficiale de comunicare afișate.
Linkuri utile și legislație
