GDPR Practice Question: Under GDPR Article 33, within what timeframe must a controller notify... | CyberCertPrep
EUGDPRBreach NotificationEASYFree question
Under GDPR Article 33, within what timeframe must a controller notify the supervisory authority of a personal data breach?
A.Without undue delay and where feasible not later than 72 hours after becoming aware of it
B.24 hours
C.7 business days
D.30 days
Why A is correct
Article 33(1) requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after the controller has become aware of the breach.
Know someone studying for GDPR? Send them this one.
Where this fits in the GDPR exam
Breach Notification
Covers breach notification concepts and practices within GDPR.
This question belongs to the "Data Protection by Design & Default" domain, which makes up about 15% of the GDPR exam.
CyberCertPrep gives you 20 free GDPR questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
GDPR and EU are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by EU or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
Under GDPR, what constitutes a 'personal data breach'?