Document a data breach
Secure the first facts, assess the risk and keep every decision traceable.
Structure a data breach record: immediate measures, affected data, risk assessment, notification review and follow-up documentation.
The first priority after a data breach is a reliable overview. Record what happened, when the responsible function became aware of it and which personal data may be affected. A preliminary assessment may contain uncertainty, but it should state that uncertainty clearly.
This checklist supports an internal incident team during initial intake and continuing documentation. It covers loss, destruction, alteration and unauthorised disclosure of personal data. A technical investigation may continue in parallel, but it does not replace the data protection assessment.
Notification to the supervisory authority and communication to affected people are separate questions. Assess both against the actual risk and update the decision when new information becomes available.
Work through the points using the facts currently available. Each tick is stored only on this device. You can reset your progress or print the list for an internal meeting.
0 of 30 points completed
01 Secure the incident and record awareness
First preserve the ability to act and separate established facts from assumptions.
02 Narrow down the affected data and people
The risk assessment needs concrete information about data types, people, access and reach.
03 Assess the timeline and risk
Document not only the result, but also how you reached the assessment.
04 Prepare notification and communication
Prepare decisions and communications from the documented facts without assuming that every breach must be reported.
05 Close and follow up the incident file
A breach that is not reported must not disappear without a record. The file should show the assessment and its reasons.
What matters legally
Article 33(5) GDPR requires controllers to document personal data breaches. The documentation must include the facts relating to the breach, its effects and the remedial action taken. This also applies where the risk assessment concludes that notification to the supervisory authority is not required.
Where a breach is likely to result in a risk to the rights and freedoms of individuals, notification under Article 33 GDPR must generally be assessed without undue delay and, where feasible, within 72 hours after awareness. Where a high risk is likely, Article 34 GDPR may additionally require communication to affected people. The technical investigation may continue while the data protection assessment is updated.
A processor must generally inform the controller of a breach without undue delay. In Austria, the Data Protection Authority is the competent supervisory authority. The information and measures required in a particular incident depend especially on the data, scale, recipients, safeguards and possible consequences.
This checklist is general guidance on the Austrian legal position and does not replace a review of the specific incident. It is not a finished notification and does not automatically decide whether notification or communication is required.
What you can do next
Secure the incident file and have the risk assessment updated by the responsible people. If the data, recipients or risk are not yet reliable, mark those points as open and reassess them as soon as new facts emerge.
Mag. Bernhard Brandauer, Rechtsanwalt
BRANDAUER Rechtsanwälte
Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.
Discuss your data protection matter
Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000