Compliance & Data ProtectionGDPR
Personal Data Breach Notification
Procedure for notifying personal data security breaches (GDPR art. 33-34)
A personal data security breach is managed in accordance with GDPR and the incident response procedure.
Notification obligations
| Recipient | Deadline | Condition |
|---|---|---|
| ANSPDCP (supervisory authority) | 72 hours from becoming aware | If the breach poses a risk to the rights and freedoms of individuals (art. 33) |
| Data subjects | Without undue delay | If the breach poses a high risk to their rights (art. 34) |
Steps
- Detection and confirmation of the breach (through monitoring / reporting)
- Risk assessment for the data subjects, with the involvement of the DPO (Neoprivacy SRL)
- Containment of the breach and immediate measures (e.g. credential rotation)
- Notification of ANSPDCP within 72 hours, if applicable
- Informing the data subjects, if the risk is high
- Documenting the breach and the measures taken in the internal breach register
- Post-incident analysis and corrective actions
Notification content
The notification includes: the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, the measures taken or proposed, and the DPO's contact details.
Controller–processor role
When SSM.ro acts as processor, breaches affecting a client's data are notified to the controller (the client) without delay, so that they can fulfill their own obligations. The allocation of responsibilities is set out in the DPA. Notification to clients: Incident Notifications.