Skip to main content

Have a process in place to notify the authorities — Have a process in place to notify the authorities and your data subjects in the event of a data breach

If there's a data breach and personal data is exposed, you are required to notify the supervisory authority in your jurisdiction within 72 hours. A list of many of the EU member states supervisory authorities can be found here. The GDPR does not specify whom you should notify if you are not an EU-based organization. For those in English-speaking non-EU countries, you may find it easiest to notify the Office of the Data Protection Commissioner in Ireland. You are also required to quickly communicate data breaches to your data subjects unless the breach is unlikely to put them at risk (for instance, if the stolen data is encrypted).

PropertyValue
SectionData security
Ownerplatform

Mapped Controls

ControlTitle
SID-OPS-01Incident Response and Management
SID-AUDIT-01Structured Security Event Logging

Source: GDPR Checklist for Data Controllers