What must a controller do with all personal data breaches regardless of whether they are reported to the supervisory authority?
- A.Only inform the DPO verbally, citing Article 33(1), which requires notification only for breaches involving special category data, not ordinary personal data
- B.Nothing if they are not reported, citing Article 34(1), which requires data subject notification before the supervisory authority is notified
- C.Post the breach details on the company website
- D.Document the breach, including the facts, effects, and remedial actions taken under Article 33(5)
Why D is correct
Article 33(5) requires the controller to document any personal data breaches, including the facts, effects, and remedial action taken, regardless of whether the breach meets the notification threshold. This documentation enables the supervisory authority to verify compliance.
Know someone studying for GDPR? Send them this one.