Unbenanntes Dokument

Reporting to Authority


Intro: What is meant by the obligation to notify the authority, what function does the notification have and what must be observed when implementing it?

To-Dos: What is the specific procedure for notifying the authority and the associated obligations?

Statements: What have the data protection supervisory authorities published on the subject of reporting to the authority?






Report data breaches to the authorities in accordance with the law





What is meant by the obligation to notify the authority, what function does the notification have and what must be observed when implementing it?

A notification to the data protection supervisory authority is always required if a data breach has occurred and a risk has arisen for persons affected by the data breach. Such a data breach always occurs when there has been a breach of data security (e.g. hacker attack) and a risk has arisen as a result (e.g. because the hacker has demonstrably accessed the exposed data (for more details: data breach cluster).

In einem solchen Fall muss die für das Unternehmen zuständige Datenschutzaufsicht innerhalb von 72 Stunden benachrichtigt werden und die gesetzlich definierten Informationen bereitgestellt werden. Hierzu zählen:

  • Description of the nature of the breach: categories and approximate number of data subjects concerned, categories and approximate number of personal data records concerned
  • Name and contact details of data protection officer or other contact point for more information
  • Likely consequences of personal data breach
  • Description of measures taken or proposed to be taken by controller to address personal data breach (including measures to mitigate possible adverse effects).


In addition to the reporting requirements, the controller must document any personal data breach (including description, effects of breach and remedial action taken).

The reporting of a data breach must be fulfilled by the controller. If the data breach takes place on the side of the processor, the latter is obliged to inform the controller. The deadline for such a processor notification is normally specified in a commissioned data processing agreement.

The involvement of the authority enables an independent treatment of the data breach. The authority may instruct the controller on how the breach should be handled. The authority has e.g. the power to direct the controller to inform the data subjects of the breach (even if the controller is of the opinion that the breach does not include a high risk.



What is the specific procedure for notifying the authority and the associated obligations?

1

Inform the department responsible for reporting (usually the data protection or legal department) - a corresponding internal reporting obligation should be anchored in a data breach policy within the company.


2

Determination of the legally defined information together with the respective department concerned


3

Creation of a notification text, if necessary using an online form from the responsible data protection supervisory authority


4

Contacting the authority, receiving assessments/orders from this authority if necessary


5

Documentation of the data breach





>> Find out which other data protection obligations have to be considered with respect to European data protection law.



Unbenanntes Dokument


Appoint a cost-effective data protection officer now

Do you need support with the implementation of data protection requirements? about our data protection packages.
Unbenanntes Dokument

We are

familiar with the characteristics of small and large companies

experienced in communicating with data protection authorities

active in data protection for over 10 years.