Ch.10 Protecting Personal Data and Privacy Fact 244 words

72-hour data breach clock: start of the countdown

Notify without undue delay and, where feasible, within 72 hours of becoming aware. The trap: 'becoming aware' means when you have reasonable certainty, not when you confirm every detail.

Аудио

Слушай тази страница (бета)

Субтитри

The 72-hour breach clock starts ticking the moment you have reasonable certainty that a personal-data breach has occurred. This is not the same as confirming every last detail. If you suspect a breach but wait until you have a full forensic report, you have already missed the deadline. The GDPR says 'without undue delay' first, then adds the 72-hour outer limit. So even if you cannot finish your investigation, you must notify the supervisory authority within three days of first knowing something is wrong.

To avoid falling into the trap, remember that 'becoming aware' is a low bar. If a system alert flags unusual access to a database containing personal data, that is enough to start the clock. You do not need proof that data was actually exfiltrated. A useful trick: think of the 72-hour window as a countdown that begins when you have a reasonable suspicion, not when you have a confirmed incident. Another hint: if a question describes a breach discovered on a Friday afternoon, the clock still runs over the weekend. Weekends and bank holidays do not pause the 72 hours.

To lock in this point, pair the number 72 with the phrase 'reasonable certainty'. Picture a security analyst saying 'I'm reasonably certain we have a breach' and immediately setting a 72-hour timer. If you see a scenario where the controller waits for a full investigation before notifying, that is a clear violation. The clock starts at suspicion, not at certainty.

Свързана флашкарта

When must a controller notify a personal-data breach to the authority?

Without undue delay and, where feasible, within 72 hours after becoming aware.

Обратно към флашкартата Виж всички флашкарти