CyberTRIZPEDIA

Maintain 72-Hour Data Breach Notification Process to APD/GBA

Control
GDPR-BREACH-001
Regulation
GDPR
Category
operational
Priority
critical
Frequency
annually
Type
operational

What this control requires

Implement breach response procedures covering: detection triggers, initial assessment, containment, notification decision (meets 72-hour threshold?), APD/GBA notification, affected individual notification where required, and post-breach remediation. Maintain a breach register including all breaches regardless of notification status.

Other GDPR controls