EU GDPR—personal data breach notification—flowchart
Published by a LexisNexis EU Law expert
FlowchartsEU GDPR—personal data breach notification—flowchart
Published by a LexisNexis EU Law expert
FlowchartsThe EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) is directly applicable and fully enforceable in EU and EEA states. This Flowchart focuses on personal data breach notification under the EU GDPR.
It covers:
- •
a summary of the overarching obligations
- •
key guidance
- •
types of personal data breaches
- •
the flowchart of notification requirements
- •
general examples of personal data breaches and who to notify
- •
detailed examples of personal data breaches and who to notify
The EU GDPR includes the following definition of a personal data breach:
‘…a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.’
Overarching obligations
In summary, among other things, the EU GDPR provides that:
- •
data processors must notify the data controller without undue delay after becoming aware of a personal data breach
- •
unless the personal data breach is unlikely to result in a risk to the rights and freedoms of individuals, the data controller must notify the appropriate supervisory
To view the latest version of this document and thousands of others like it,
sign-in with LexisNexis or register for a free trial.