Direct answer · GDPR
Notifying a personal data breach
Notify the supervisory authority, in the Netherlands the Autoriteit Persoonsgegevens: without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33(1)). Every breach is documented internally, also when it does not have to be notified (Article 33(5)). The data subjects themselves are only informed if the breach is likely to result in a high risk to them (Article 34(1)). Even then that obligation lapses if, for example, the data were encrypted, if the high risk has been removed by subsequent measures, or if informing each person individually would involve disproportionate effort; in that last case a public communication follows (Article 34(3)).
For you to establish
- Which data were breached, of how many people, and were they encrypted?
Articles
- Art. 33(1) GDPR Notification within 72 hours, unless no risk is likely.
- Art. 33(5) GDPR Document every breach internally.
- Art. 34(1) GDPR Inform data subjects where a high risk is likely.
- Art. 34(3)(a) to (c) GDPR Exceptions: encryption, subsequent measures, disproportionate effort.
Guidelines and decisions
- Guidelines 9/2022 on personal data breach notification under GDPR (EDPB, v2.0, 2023-03-28)Guidelines on personal data breach notification.
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification (EDPB, v2.0, 2021-12-14)Examples of personal data breaches and how to handle them.
