Document the incident and close the risk assessment now
Secure systems and records, stop further access and record data, people, cause, measures and awareness time. Even when notification appears unlikely, the assessment should remain traceable.
Record a personal data breach, assess the first risk signals and identify the next steps.
Mag. Bernhard Brandauer, Rechtsanwalt
BRANDAUER Rechtsanwälte
Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.
The first response to a data breach needs a reliable picture: what happened, which data was involved, how many people may be affected and which safeguards limited the incident? Record the time when the responsible organisation became aware of the possible breach.
The check covers these first facts and makes uncertainty visible. It points to the 72-hour process under Article 33 GDPR. Whether the supervisory authority or affected people must be informed depends on the concrete risk assessment.
Mag. Bernhard Brandauer, Rechtsanwalt
Answer based on the facts currently available. If information is missing, choose the uncertain option and obtain the missing facts without delay.
A suspected unauthorised access, wrong recipient, loss, encryption or unavailability may be a personal data breach.
Secure systems and records, stop further access and record data, people, cause, measures and awareness time. Even when notification appears unlikely, the assessment should remain traceable.
A contained incident is not automatically complete because more than 72 hours have passed. Assess notification by reference to risk, record the actual awareness time and explain any delay.
Sensitive data, a large scope, open access or missing containment usually require urgent review. Secure evidence, stop further access, involve the responsible teams and assess notification to the supervisory authority and communication to affected people.
Assess without delay whether the breach still has to be notified. Record awareness time, reasons for delay, safeguards and the decision about communication to affected people. The expiry of 72 hours does not by itself remove the need for a later notification.
Secure logs, emails, reports and system data, identify the first reliable state of knowledge and continue risk assessment while the technical facts are being clarified.
Risk cannot be assessed reliably without knowing the affected data. Stop further access, secure copies and logs and identify data categories, people, recipients and awareness time before completing the notification assessment.
Secure evidence, stop further access and create a short timeline. Record data categories, people, recipients, cause, safeguards and awareness time. Assess notification to the supervisory authority under Article 33 GDPR and communication to affected people under Article 34 GDPR separately.
No. Notification to the supervisory authority must generally be assessed where the breach is likely to result in a risk to the rights and freedoms of natural persons. The assessment and a decision not to notify should be documented.
The relevant point is when the controller has sufficient awareness of a personal data breach. Record the awareness time and information chain. Technical clarification must not delay containment and risk assessment.
Communication is particularly relevant where the breach is likely to result in a high risk to affected people. This is a separate assessment and should not be confused with notification to the supervisory authority.
The processor must inform the controller without undue delay. The controller then carries out its own risk assessment, documentation and, where appropriate, notification. Contractual routes can accelerate the response but do not replace the statutory assessment.
Receive new articles and legal guidance from the firm with BRANDaktuelle Rechtsnews.
Subscribe to the newsletter →Deepen the organisational framework for risk assessment, documentation and notification.
Record first measures and open issues for the internal incident team.
Assess roles, incident routes and responsibilities for external providers.
This check provides initial orientation. It does not replace an assessment of the incident, affected people or technical and organisational measures. It does not trigger a notification automatically.
Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000