GDPR Practice Question: When must a controller communicate a personal data breach to data... | CyberCertPrep
EUGDPRBreach NotificationEASYFree question
When must a controller communicate a personal data breach to data subjects under Article 34?
A.For every breach, regardless of risk
B.Only if the media has reported on the breach
C.Only if the data subjects request it
D.When the breach is likely to result in a high risk to the rights and freedoms of natural persons
Why D is correct
Article 34(1) requires communication to data subjects when the breach is likely to result in a high risk to their rights and freedoms, a higher threshold than the notification to the supervisory authority which requires only a 'risk'.
Know someone studying for GDPR? Send them this one.
Where this fits in the GDPR exam
Breach Notification
Covers breach notification concepts and practices within GDPR.
This question belongs to the "Data Protection by Design & Default" domain, which makes up about 15% of the GDPR exam.
CyberCertPrep gives you 20 free GDPR questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
GDPR and EU are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by EU or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
Under GDPR, what constitutes a 'personal data breach'?