Privacy
Initial assessment

Data breach initial check

Record a personal data breach, assess the first risk signals and identify the next steps.

BRANDAUER Rechtsanwälte
Contact person

Mag. Bernhard Brandauer, Rechtsanwalt

BRANDAUER Rechtsanwälte

Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.

The first response to a data breach needs a reliable picture: what happened, which data was involved, how many people may be affected and which safeguards limited the incident? Record the time when the responsible organisation became aware of the possible breach.

The check covers these first facts and makes uncertainty visible. It points to the 72-hour process under Article 33 GDPR. Whether the supervisory authority or affected people must be informed depends on the concrete risk assessment.

Mag. Bernhard Brandauer, Rechtsanwalt

Assess the breach

Which first response fits the incident?

Answer based on the facts currently available. If information is missing, choose the uncertain option and obtain the missing facts without delay.

01 Question 1

What type of incident occurred?

A suspected unauthorised access, wrong recipient, loss, encryption or unavailability may be a personal data breach.

Ergebnis

Ihre Orientierung

01

Document the incident and close the risk assessment now

Secure systems and records, stop further access and record data, people, cause, measures and awareness time. Even when notification appears unlikely, the assessment should remain traceable.

02

Complete the delayed assessment and timeline

A contained incident is not automatically complete because more than 72 hours have passed. Assess notification by reference to risk, record the actual awareness time and explain any delay.

03

Escalate the incident and assess notification immediately

Sensitive data, a large scope, open access or missing containment usually require urgent review. Secure evidence, stop further access, involve the responsible teams and assess notification to the supervisory authority and communication to affected people.

04

Assess a possible late notification with a complete timeline

Assess without delay whether the breach still has to be notified. Record awareness time, reasons for delay, safeguards and the decision about communication to affected people. The expiry of 72 hours does not by itself remove the need for a later notification.

05

Clarify awareness time and scope immediately

Secure logs, emails, reports and system data, identify the first reliable state of knowledge and continue risk assessment while the technical facts are being clarified.

06

Secure the data inventory and reach first

Risk cannot be assessed reliably without knowing the affected data. Stop further access, secure copies and logs and identify data categories, people, recipients and awareness time before completing the notification assessment.

Next steps after the initial check

Secure evidence, stop further access and create a short timeline. Record data categories, people, recipients, cause, safeguards and awareness time. Assess notification to the supervisory authority under Article 33 GDPR and communication to affected people under Article 34 GDPR separately.

Documents and information to collect

  • Timeline of discovery, internal report and awareness by the responsible organisation
  • Affected systems, files, data categories and groups of people
  • Estimated number of records and reasons for uncertainty
  • Logs, recipient details, access evidence and technical assessment
  • Containment, recovery, blocks and remaining risks
  • Contracts and incident routes for processors and other service providers

Legal framework

  • General Data Protection Regulation, in particular Articles 4(12), 28, 32, 33 and 34
  • Austrian Data Protection Act, in particular Section 1
  • European Data Protection Board Guidelines on personal data breach notification under the GDPR
  • Information and breach notification form of the Austrian Data Protection Authority

Does every data breach have to be notified?

No. Notification to the supervisory authority must generally be assessed where the breach is likely to result in a risk to the rights and freedoms of natural persons. The assessment and a decision not to notify should be documented.

Does the 72-hour period start with the first technical suspicion?

The relevant point is when the controller has sufficient awareness of a personal data breach. Record the awareness time and information chain. Technical clarification must not delay containment and risk assessment.

Must affected people always be informed?

Communication is particularly relevant where the breach is likely to result in a high risk to affected people. This is a separate assessment and should not be confused with notification to the supervisory authority.

What if the breach occurred at a processor?

The processor must inform the controller without undue delay. The controller then carries out its own risk assessment, documentation and, where appropriate, notification. Contractual routes can accelerate the response but do not replace the statutory assessment.

Subscribe to legal updates

Receive new articles and legal guidance from the firm with BRANDaktuelle Rechtsnews.

Subscribe to the newsletter →

Personal data breaches and notification duties

Deepen the organisational framework for risk assessment, documentation and notification.

Document a data breach

Record first measures and open issues for the internal incident team.

Processors and service providers

Assess roles, incident routes and responsibilities for external providers.

This check provides initial orientation. It does not replace an assessment of the incident, affected people or technical and organisational measures. It does not trigger a notification automatically.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich