GDPR Practice Question: What must a controller do with all personal data breaches regardless... | CyberCertPrep
EUGDPRBreach NotificationEASYFree question
What must a controller do with all personal data breaches regardless of whether they are reported to the supervisory authority?
A.Document the breach, including the facts, effects, and remedial actions taken under Article 33(5)
B.Nothing if they are not reported
C.Only inform the DPO verbally
D.Post the breach details on the company website
Why A is correct
Article 33(5) requires the controller to document any personal data breaches, including the facts, effects, and remedial action taken, regardless of whether the breach meets the notification threshold. This documentation enables the supervisory authority to verify compliance.
Know someone studying for GDPR? Send them this one.
Where this fits in the GDPR exam
Breach Notification
Covers breach notification concepts and practices within GDPR.
This question belongs to the "Data Protection by Design & Default" domain, which makes up about 15% of the GDPR exam.
CyberCertPrep gives you 20 free GDPR questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
GDPR and EU are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by EU or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
Under GDPR, what constitutes a 'personal data breach'?