EU issues draft guidance on data breach handling

There has been a lot to do about the changes that are to be implemented by companies processing personal data due to the GDPR. One of those changes is the obligation to notify national data protection authorities (“DPA”) of personal data breaches. 

Fortunately, the Article 29 Working Party (“WP29”), the EU data protection advisory body, provided guidance on 3 October 2017 clarifying the extent of such notification obligation.

A data breach is a breach of security leading to any accidental or unlawful destruction/loss/disclosure of or access to any personal data, possibly requiring notification to the DPA or the affected data subjects.

Notification to the DPA is not required when the data breach is unlikely to result in a risk for the rights and freedoms of natural persons. For example, if the breached personal data is already publicly available,  the disclosure of such data will probably not constitute a risk to the data subject.

If notification is required, the data controller must inform the DPA without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Data controllers are allowed a short leeway period to undertake investigations, but the period within which the notification must be made starts as soon as there is a reasonable degree of certainty of the occurrence of the data breach or once its data processor has become aware of it. Notification in phases is allowed when the exact information (e.g. the exact number of affected data subjects) is not known at the first notification, but becomes available after further investigations.

Further, except under particular circumstances, the data controller needs to inform data subjects whether the breach is likely to constitute a high risk for their rights and freedoms.

Non-compliance with the obligation to notify personal data breaches may be punished with a fine of up to EUR 20,000,000 or 4% of the total worldwide annual turnover of the data controller, whichever is higher.

Therefore, the following three action points are crucial for any data controller:

1. Bind your data processors contractually (i.e. in the data processing/transfer agreement) to inform you of a data breach immediately (e.g. within 12 hours) after they have become aware of it.

2. Take into account the criteria set out by ENISA when assessing the severity of a data breach (and the obligation to make a notification).

3. Roll out the appropriate policies to handle data security/data breaches (e.g. data breach policy, data breach handling procedure, setting up a data security incident response team) and raise awareness among employees (e.g. through training). 


AnneMichèle Goris

Junior Associate, Brussels

Tom De Cordier

Partner, Brussels

Related : CMS Belgium

Click here to see the ad(s)
All articles European Law

Lastest articles European Law

Géoblocage : aperçu des nouveautés du Règlement européen

Le 28 février 2018, le Parlement européen a adopté un nouveau Règlement visant à c...

Géoblocage : aperçu des nouveautés du Règlement européen Read more

European Commission imposes fine of €254 million on capacitor cartel

On 21 March 2018, the European Commission fined eight Japanese capacitor suppliers €254 million for their participati...

European Commission imposes fine of €254 million on capacitor cartel Read more

New EU Regulation to ban unjustified geo-blocking in the internal mark

Regulation 2018/302 of the European Parliament and of the Council of 28 February 2018 on addressing unjusti ed geo-blockin...

Read more

Advertising in Relation to Plastic Surgery: ECJ Clears Prohibition

By order of 26 October 2017, the Court of Justice of the European Union (the “ECJ”) ruled that the Belgian pro...

Advertising in Relation to Plastic Surgery: ECJ Clears Prohibition Read more

LexGO Network