ssm.ro Docs
Compliance & Data ProtectionGDPR

Personal Data Breach Notification

Procedure for notifying personal data security breaches (GDPR art. 33-34)

A personal data security breach is managed in accordance with GDPR and the incident response procedure.

Notification obligations

RecipientDeadlineCondition
ANSPDCP (supervisory authority)72 hours from becoming awareIf the breach poses a risk to the rights and freedoms of individuals (art. 33)
Data subjectsWithout undue delayIf the breach poses a high risk to their rights (art. 34)

Steps

  1. Detection and confirmation of the breach (through monitoring / reporting)
  2. Risk assessment for the data subjects, with the involvement of the DPO (Neoprivacy SRL)
  3. Containment of the breach and immediate measures (e.g. credential rotation)
  4. Notification of ANSPDCP within 72 hours, if applicable
  5. Informing the data subjects, if the risk is high
  6. Documenting the breach and the measures taken in the internal breach register
  7. Post-incident analysis and corrective actions

Notification content

The notification includes: the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, the measures taken or proposed, and the DPO's contact details.

Controller–processor role

When SSM.ro acts as processor, breaches affecting a client's data are notified to the controller (the client) without delay, so that they can fulfill their own obligations. The allocation of responsibilities is set out in the DPA. Notification to clients: Incident Notifications.