The Regulation requires the Controller to notify, without undue delay, the personal data breach to the supervisory authority. Whenever the personal data breach is likely to adversely affect the protection of the personal data, the privacy, the rights or the legitimate interests of the data subject, the Controller must also communicate the personal data breach to the data subject without undue delay.
This topic covers all aspects related to Data Breach such as, for example, how to define a correct organizational process to manage a data breach, how to estimate the brand and reputation damage in case an incident is disclosed, which contractual clauses to put in contracts with vendors and how to manage the communication following a data breach on social networks.