A company laptop containing unencrypted personal data is lost. This is:
- A.Only a breach if the laptop is found by someone, citing Article 33(1), which requires notification only for breaches involving special category data, not ordinary personal data
- B.Not a breach since the data wasn't accessed, citing Article 4(12), which defines a personal data breach as limited to unauthorised disclosure, excluding accidental loss or destruction
- C.A breach only if the employee was negligent
- D.A personal data breach as the data may be accessible to unauthorized persons
Why D is correct
Loss of an unencrypted device containing personal data is a breach as unauthorized access is possible, regardless of whether it actually occurs.
Know someone studying for GDPR? Send them this one.