The notification to the supervisory authority must include:
- A.The nature of the breach, categories and number of data subjects/records affected, DPO contact details, likely consequences, and measures taken
- B.Only a statement that a breach occurred, citing Article 34(1), which requires data subject notification before the supervisory authority is notified
- C.Only the controller's name, per Article 34(1), which requires data subject notification only if the supervisory authority has already been notified and responded
- D.Only the date of the breach
Why A is correct
Article 33(3) lists required content: nature of breach, categories/numbers affected, DPO contact, likely consequences, and measures taken or proposed.
Know someone studying for GDPR? Send them this one.