Regardless of whether notification is required, the controller must:
- A.Document any personal data breach, including facts, effects, and remedial actions taken
- B.Only document breaches that are reported in the media, citing Article 5(2) accountability, which shifts the burden of proof to the data subject rather than the controller
- C.Do nothing if the breach is minor, citing Article 83(4)(a), which caps breach notification failures at a fixed fine regardless of the controller's turnover
- D.Only document breaches involving special category data
Why A is correct
Article 33(5) requires the controller to document any personal data breach, enabling the supervisory authority to verify compliance with GDPR.
Know someone studying for GDPR? Send them this one.