《关于GDPR下的个人数据泄露通知的第92022号指南》-33页_636kb
报告摘要
Summary of Guidelines 9/2022 on Personal Data Breach Notification under GDPR
Overview
The European Data Protection Board (EDPB) adopted these guidelines in 2022, updating the WP29 Guidelines on Personal Data Breach Notification. They aim to clarify and provide detailed guidance on the General Data Protection Regulation (GDPR) provisions for reporting data breaches, emphasizing timely and effective handling to protect individuals' rights and freedoms.
Key Requirements
-
Notification to Supervisory Authority (Article 33):
- Required within 72 hours of becoming aware of a breach, if it is likely to result in a risk to individuals' rights and freedoms.
- Must include information on breach nature, categories of affected individuals, likely consequences, and measures taken.
- Exceptions apply for breaches unlikely to cause risk; surveillance may also be needed.
- Joint controllers and processors must coordinate responsibilities, with processors notifying controllers without undue delay.
-
Communication to Data Subjects (Article 34):
- Required if a breach is likely to cause a high risk to individuals' rights and freedoms.
- Communications must be in clear language, direct the affected individuals, and be effective (e.g., via dedicated channels).
- Exceptions include situations where risk is low or disproportionate effort is involved, and data is adequately protected.
Assessment and Risk Factors
- Breaches are defined as security incidents leading to unauthorized access, disclosure, loss, alteration, or destruction of personal data.
- Risk assessment must consider: breach type, data sensitivity, volume, severity of consequences, and likelihood of impact.
- High-risk breaches require notification to both supervisory authority and individuals.
- Documentation of all breaches is mandatory (Article 33(5)), to demonstrate accountability and compliance.
Accountability and Other Considerations
- Designated Data Protection Officers (DPOs) support breach management, advising on compliance and assisting with notifications.
- Other legal instruments, such as the eIDAS Regulation and NIS Directive, may impose additional notification requirements that intersect with GDPR obligations.
- Controllers must establish incident response plans and ensure employees are trained to handle breaches effectively.
These guidelines emphasize the importance of proactive measures to prevent breaches and timely responses to mitigate risks, with potential sanctions for noncompliance.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载