When must a controller notify a personal-data breach to the authority?
Atingeți pentru a afișa răspunsul
Răspuns
Without undue delay and, where feasible, within 72 hours after becoming aware.
The 72-hour clock is a common EPSO number.
GDPR, Regulation (EU) 2016/679
Analiză aprofundată
72-hour data breach clock: start of the countdown
Notify without undue delay and, where feasible, within 72 hours of becoming aware. The trap: 'becoming aware' means when you have reasonable certainty, not when you confirm every detail.
Utilizăm cookie-uri esențiale pentru funcționarea site-ului și, cu acordul dumneavoastră, cookie-uri opționale de analiză. Aflați mai multe în
Politica de confidențialitate.