Externen Datenschutzbeauftragten gesucht?DATUREX GmbH Dresden
DATUREXDatenschutz-Gesetze
GDPR — Inhaltsverzeichnis

KI-generierte Zusammenfassung

This provision requires controllers to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals. Processors must notify the controller without undue delay, and the notification must describe the nature, consequences, and remedial measures taken.

Art. 33 GDPR

Notification of a personal data breach to the supervisory authority

(1.)In the case of a , the shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the to the competent in accordance with Article 55, unless the is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the is not made within 72 hours, it shall be accompanied by reasons for the delay.
(2.)The shall notify the without undue delay after becoming aware of a .
(3.)The notification referred to in paragraph 1 shall at least: (a) describe the nature of the including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of records concerned; (b) communicate the name and contact details of the data protection officer or other contact point where more information can be obtained; (c) describe the likely consequences of the ; (d) describe the measures taken or proposed to be taken by the to address the , including, where appropriate, measures to mitigate its possible adverse effects.
(4.)Where, and in so far as, it is not possible to provide the information at the same time, the information may be provided in phases without undue further delay.
(5.)The shall document any breaches, comprising the facts relating to the , its effects and the remedial action taken. That documentation shall enable the to verify compliance with this Article.
Quelle:
EUR-Lex CELEX 02016R0679-20160504
Fundstelle:
OJ L 119, 04.05.2016, p. 1; corrected by OJ L 127, 23.05.2018, p. 2
Stand:
2016-05-04
Abgerufen:
2026-02-25