GDPR GDPR Data Breach Management & Response 1 — Questions and Answers
Question 1: Under GDPR Article 33, a personal data breach must be reported to the supervisory authority within what timeframe?
- 24 hours of discovery
- 72 hours of becoming aware of the breach (Correct answer)
- 7 days of discovery
- Immediately upon detection
Correct answer: 72 hours of becoming aware of the breach
Article 33 requires controllers to notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach, unless it is unlikely to result in risk.
Question 2: Which GDPR article requires controllers to notify affected data subjects directly when a breach is likely to result in high risk?
- Article 33
- Article 34 (Correct answer)
- Article 35
- Article 32
Correct answer: Article 34
Article 34 mandates that controllers communicate a high-risk personal data breach to affected data subjects without undue delay.
Question 3: Under Article 34(3), direct notification to data subjects may be waived if:
- The breach involves fewer than 100 individuals
- The controller has implemented appropriate technical measures rendering data unintelligible to unauthorized persons (Correct answer)
- The breach has already been covered in the news
- The DPO has certified the breach is low priority
Correct answer: The controller has implemented appropriate technical measures rendering data unintelligible to unauthorized persons
Article 34(3)(a) allows omitting direct notification if appropriate protection measures, such as encryption, were applied such that the data is unintelligible to unauthorized parties.
Question 4: What minimum information must a supervisory authority notification under Article 33(3) include?
- Only the controller's name and contact details
- The nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken (Correct answer)
- A full forensic report
- A copy of all affected data records
Correct answer: The nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken
Article 33(3) specifies that the notification must describe the breach's nature, approximate numbers affected, likely consequences, and remedial measures, at minimum.
Question 5: If a controller cannot provide all required breach notification information within 72 hours, what does GDPR permit?
- The notification is invalid and must be re-submitted after full investigation
- The controller may provide information in phases without undue further delay (Correct answer)
- The controller may delay notification entirely until the investigation is complete
- Only the DPO may decide to withhold notification
Correct answer: The controller may provide information in phases without undue further delay
Article 33(4) allows phased notification where full information is not yet available, provided additional information is supplied without undue further delay.
Question 6: Under GDPR, what internal record must controllers maintain for ALL personal data breaches, including those not reported to the DPA?
- A public breach register on their website
- An internal breach register documenting facts, effects, and remedial action under Article 33(5) (Correct answer)
- A breach log submitted to the EDPB annually
- A breach summary forwarded to each affected data subject
Correct answer: An internal breach register documenting facts, effects, and remedial action under Article 33(5)
Article 33(5) requires controllers to document all breaches internally, enabling supervisory authorities to verify compliance even for low-risk breaches not escalated to the DPA.
Under GDPR Article 33, a personal data breach must be reported to the supervisory authority within what timeframe?