GDPR GDPR Data Breach Management & Response 2 — Questions and Answers
Question 1: How does GDPR define a 'personal data breach' under Article 4(12)?
- Any unauthorized access to company IT systems
- A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data (Correct answer)
- Any data subject complaint about data handling
- A failure to respond to a SAR within one month
Correct answer: A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data
Article 4(12) defines a personal data breach broadly as a security incident that compromises the confidentiality, integrity, or availability of personal data.
Question 2: A laptop containing unencrypted patient records is stolen. Which category of personal data breach has occurred?
- Integrity breach only
- Availability breach only
- Confidentiality breach (Correct answer)
- Lawfulness breach
Correct answer: Confidentiality breach
Theft of an unencrypted device results in unauthorized access to data, making it a confidentiality breach where data is exposed to persons not authorized to see it.
Question 3: When a processor becomes aware of a personal data breach, what is their primary obligation toward the controller under Article 33(2)?
- Notify the supervisory authority directly within 72 hours
- Notify the controller without undue delay (Correct answer)
- Notify all affected data subjects immediately
- Submit a DPIA to the relevant DPA
Correct answer: Notify the controller without undue delay
Article 33(2) requires processors to notify the controller without undue delay after becoming aware of a breach, enabling the controller to meet its own 72-hour DPA reporting window.
Question 4: Which factor is most critical in determining whether a data breach must be reported to the supervisory authority?
- The size of the organization involved
- Whether the breach is likely to result in a risk to the rights and freedoms of natural persons (Correct answer)
- The number of data records involved exceeding 500
- Whether the breach was intentional or accidental
Correct answer: Whether the breach is likely to result in a risk to the rights and freedoms of natural persons
Article 33(1) ties the DPA notification obligation to the likelihood of risk to individuals' rights and freedoms, not to breach size or intent.
Question 5: A ransomware attack encrypts personal data but the controller has clean backups and restores data within hours with no evidence of exfiltration. Must the controller notify the DPA?
- No, because data was restored and there was no disclosure to third parties (Correct answer)
- Yes, always, because any ransomware incident is automatically a high-risk breach
- Only if more than 1,000 records were encrypted
- Only if the backup restoration took more than 72 hours
Correct answer: No, because data was restored and there was no disclosure to third parties
If data was not exfiltrated and was fully restored with minimal downtime, the breach may be unlikely to result in risk to individuals, potentially removing the DPA notification requirement, though internal documentation is still mandatory.
Question 6: What is a key purpose of conducting a post-breach 'lessons learned' review under GDPR accountability principles?
- To avoid paying any resulting fines
- To demonstrate accountability by identifying control failures and improving security measures (Correct answer)
- To transfer liability to the data processor
- To delay supervisory authority investigations
Correct answer: To demonstrate accountability by identifying control failures and improving security measures
Post-breach reviews support GDPR's accountability principle by documenting what went wrong, what was fixed, and how recurrence is prevented, all of which can be shared with supervisors.
How does GDPR define a 'personal data breach' under Article 4(12)?