A personal data breach can result from a misdirected email, a lost laptop, a compromised account or an error by a service provider. It is not limited to data being published online. Loss, destruction, alteration, unauthorised disclosure or unauthorised access to personal data may all require assessment.
A business should not begin by looking for a completed form. It should first establish what happened: which data may be affected, how many people may be involved, who could access the data and when the incident became known. Only then can the business assess whether the Austrian supervisory authority or the affected individuals must be notified.
Article 33 GDPR generally sets a 72-hour period from becoming aware of a breach for notifying the supervisory authority where notification is required. This does not mean that every technical cause must be solved within 72 hours. It does mean that the initial assessment, interim findings and decision must be organised without undue delay.
Mag. Bernhard Brandauer, Rechtsanwalt