GDPR data breach: action plan and notification of the supervisory authority

When it comes to data breaches, the first cases that usually come to mind are the Ashley Madison case, the activities of the Lizard Squad group, or the Equifax attack. However, real-world practice consists predominantly not of high-profile incidents involving multimillion companies operating large databases, but of breaches occurring in the day-to-day activities of ordinary market participants. Although the scale of such incidents may vary, they share one common feature: a significant proportion of such breaches are either preventable or, through proper response, can be managed in a way that protects a company from hefty fines and data subjects from risks to their rights and freedoms.

The General Data Protection Regulation (GDPR) imposes a number of requirements on companies concerning the implementation of technical and organisational measures aimed at preventing data breaches. At the same time, even the most comprehensive preventive measures cannot guarantee that an incident will not occur. This is why the GDPR and supervisory authorities’ practice upholds a risk-based approach and attach no less importance to how prepared an organisation is for a data breach and how exactly it will act if one occurs. The purpose of this article is to examine what exactly needs to be done after a data breach is detected, when the obligation to notify the supervisory authority and data subjects arises, and how to properly assess the risks to their rights and freedoms.

What is a data breach under the GDPR?

Under Article 4(12) GDPR, a personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. In turn, WP29 in Opinion 03/2014 on personal data breach notification explains this concept through the following three categories:

  • data breach concerning a breach of confidentiality: accidental or unauthorised disclosure of or access to personal data;
  • data breach concerning a breach of integrity: accidental or unauthorised alteration of personal data;
  • data breach concerning a breach of availability: accidental or unauthorised loss of access to personal data or destruction thereof.

It is important to emphasise that not every security incident will automatically qualify as a personal data breach within the meaning of the GDPR. For a particular security incident to qualify as a personal data breach, such incident must concern personal data and result in the controller’s inability to ensure the processing of personal data in accordance with the principles set out in Article 5 GDPR. Typical examples of personal data breaches include unauthorised access by a hacker to a customer database, an employee accidentally sending confidential data to the wrong person, theft of a laptop containing unencrypted personal data, a misconfigured cloud storage accessible to the public, or a ransomware attack as a result of which systems and data become unavailable.

A data breach does not always trigger a notification obligation

Depending on the risks to the rights and freedoms of data subjects, the GDPR establishes a two-level system of notifications concerning personal data breaches. Article 33 requires notification of the supervisory authority within 72 hours where the breach is likely to result in a risk to the rights and freedoms of natural persons. Article 34 provides for direct notification of the affected data subjects where the breach is likely to result in a high risk to their rights and freedoms. The thresholds differ: the existence of a risk to the rights and freedoms of data subjects generally constitutes grounds for notifying the supervisory authority, whereas a high risk is required for direct notification of the data subjects themselves.

1. Notification of the supervisory authority

Article 32 GDPR clearly provides that the controller and processor must implement appropriate technical and organisational measures to ensure an appropriate level of security of personal data. This inter alia includes the ability to detect, respond to and notify personal data breaches in a timely manner. In the context of personal data breaches, the controller remains fully responsible and bears the obligation to notify the supervisory authority of a breach where required. Accordingly, regardless of the model of allocation of roles within a company, the issue of notification of the supervisory authority of a personal data breach must be regulated between the entities involved in the processing of personal data.

Where a processor is engaged in the processing of personal data, the Data Processing Agreement must contain provisions concerning the processor’s obligation to “assist the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36, taking into account the nature of processing and the information available to the processor” under Article 28(3)(f) GDPR. At the same time, in the case of joint controllership, the company responsible for carrying out the notification must be designated at the level of the Joint Controllership Agreement.

As already noted, the obligation to notify the supervisory authority of a personal data breach arises only where there is a risk to the rights and freedoms of data subjects. The focus of such assessment should primarily be on the consequences, including material, non-material, reputational and other consequences, of the personal data breach for data subjects. In Guidelines 9/2022 on personal data breach notification under GDPR, the EDPB recommends considering, when determining whether a risk exists, such factors as the type of personal data breach, the nature, sensitivity and volume of personal data, the ease of identification of individuals, the severity of the consequences for the individual, the special characteristics of the data subjects, as well as the number of data subjects affected.

For example, in situations such as:
a controller suffers a ransomware attack as a result of which all data is encrypted. There are no backups, and the data cannot be restored. During the investigation, it is established that the only functionality of the ransomware was data encryption, and no other functionalities that could result in additional consequences have been identified;
– a natural person calls a bank’s call centre to report a personal data security breach. The natural person has received a monthly statement belonging to another person. The controller conducts a brief investigation (i.e. one that is completed within 24 hours) and establishes, with a sufficient degree of reasonable certainty, that a personal data breach has indeed occurred, and also determines whether there is a systemic issue through which other individuals may already have been or may be affected – notification of the supervisory authority is clearly mandatory.

In any event, the golden rule of this section is to interpret any doubts in favour of the existence of risks, since, unlike failure to notify, notification in the absence of risks does not entail legal liability.

The 72-hour rule

A common misconception is that the 72-hour period under Article 33 GDPR starts running from the moment the personal data breach itself occurred. Fortunately for controllers, the GDPR links the time limit for notifying the supervisory authority to the moment when the controller becomes aware of the existence of the personal data breach.

As the EDPB notes: “the controller is considered to have become aware of a breach when the controller has a sufficient degree of reasonable certainty that a security incident has occurred that has led to personal data being compromised”. In order to establish a “sufficient degree of reasonable certainty”, the controller will in most cases need to conduct an internal investigation aimed at establishing the occurrence of the breach and determining whether such notification is required.

Where it is established that notification of the supervisory authority of a personal data breach is required, the controller must, pursuant to Article 33(3) GDPR, provide the following information:

  • the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
  • the name and contact details of the data protection officer (DPO) or other contact point from whom more information can be obtained;
  • a description of the likely consequences of the personal data breach;
  • a description of the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
Case study: Booking.com B.V. notified the Dutch supervisory authority 22 days after becoming aware of the personal data breach, significantly exceeding the 72-hour period established by the GDPR. The personal data of more than 4,000 customers were accessible to unauthorised persons, including financial information and passport data. A fine of EUR 475,000 was imposed not for the personal data breach itself, but for the failure to notify it in a timely manner.

It is important to note that the “72-hour rule” is not absolute and contains several exceptions:

  1. Taking into account the nature and scope of personal data breaches, the controller may provide the relevant information gradually (“in phases”) if it was unable to collect all details concerning a particular incident within 72 hours. The controller may indicate this in the notification itself.
  2. There may be cases where there are justified reasons why the controller did not notify the supervisory authority within 72 hours. Such a delay may be acceptable, for example, where the controller experiences several similar personal data breaches within a short period of time, affecting a large number of data subjects in the same manner. The controller may become aware of one breach and, having commenced its investigation but before submitting the notification, identify additional similar breaches having different causes. Depending on the circumstances, the controller may need some time to establish the scope of such breaches. Therefore, instead of notifying each breach separately, the controller may prepare one comprehensive notification covering several very similar breaches, even if they have different causes.

2. Notification of data subjects

Pursuant to Article 34 GDPR, where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller must also communicate the personal data breach to the affected data subjects without undue delay, using clear and plain language.

Although this rule primarily concerns serious and large-scale incidents involving personal data, the controller will in any event be required to determine whether the relevant risks exist. Since the main idea underlying the provision concerning notification of the supervisory authority of a personal data breach is the prevention and minimisation of the adverse consequences of such incidents for data subjects, interaction with the supervisory authority may contribute to a proper assessment of the level of risk to the rights and freedoms of data subjects and, accordingly, to determining whether they need to be informed further.

At the same time, Article 34(3) GDPR establishes exceptions where direct notification of data subjects is not required if any of the following conditions is met:

  • the controller has implemented appropriate technical and organisational measures, such as encryption, which render the personal data unintelligible to any person who is not authorised to access it;
  • the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of natural persons referred to in paragraph 1 is no longer likely to materialise;
  • it would involve disproportionate effort.

In such a case, a public communication or similar measure may be used instead to inform data subjects in an equally effective manner.

It should be noted that these exceptions may be interpreted narrowly by supervisory authorities and require an appropriate case-by-case assessment.

Documentation is your cornerstone

Pursuant to Article 5(2) GDPR, the controller is responsible for, and must be able to demonstrate compliance with, the principles of the GDPR (“accountability”). This fundamental principle of the GDPR is particularly important in the context of personal data breaches, since where a decision is made not to notify the supervisory authority or data subjects, and in the event of subsequent incidents, the controller will need to demonstrate to the supervisory authority that all legally prescribed procedures have been properly followed.

In addition, Article 33(5) GDPR establishes a separate obligation for the controller to document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken.

At the organisational level, such documentation may be maintained through a Personal Data Breach Register, while the incident response process itself is best established at the level of a Personal Data Breach Notification Procedure.

Action plan instead of conclusions

1.Identify and recordRecord the fact, time and circumstances of the breach
2.Assess the riskDetermine the scope and risk to individuals’ rights and freedoms
3. Notify the supervisory authorityWithin 72 hours from becoming aware of the breach
4. Notify affected data subjectsIf the risk is high –  without undue delay
5. DocumentRecord the incident and the measures taken in the register

As a result, the management of personal data breach risks should not be reduced to a reaction to a specific incident after the fact. An appropriate approach requires systematic work long before a breach occurs: implementing preventive measures, developing incident response procedures and clearly allocating responsibilities. If a breach occurs, the existence of such a system and the company’s ability to apply it quickly and effectively become evidence to the supervisory authority of the company’s actual ability to manage the relevant risks and may, to a significant extent, prevent the adverse legal consequences that generally await a company following a personal data breach.

Tags
  • GDPR
  • GDPR data breach
Do you have any questions for the lawyers?
up to 500 characters
An error occurred
The request has been sent Thank you for your message! We will process it as soon as possible.

Articles on the topic