From the course: Certified Information Privacy Manager (CIPM) Cert Prep: 6 Privacy Operational Life Cycle: Respond

Unlock this course with a free trial

Join today to access over 23,200 courses taught by industry experts.

Reporting privacy incidents

Reporting privacy incidents

- Organizations may have an obligation to report privacy incidents to data subjects and/or regulators. These obligations may come as a result of national, state, province, or local laws. For example, GDPR contains two related articles, Article 33 and Article 34. Article 33 requires that data controllers notify the supervisory authority of any personal data breach. It requires that data controllers notify the supervisory authority within 72 hours of a breach, unless that breach is unlikely to result in a risk to the rights and freedoms of individuals. Article 33 also includes four requirements for these notifications. They must describe the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned. They must also communicate the name and contact details of the data protection officer or other contact point where more information can be…

Contents