This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
| 1 minute read

A Guide to Data Breach Reporting Obligations

All too often, data breaches are a result of preventable, internal errors. These mistakes and the reputational damage that follow them are increasingly keeping business leaders up at night. What is often most concerning is that it’s not only the financial damage that can cause catastrophe. When the personal data of thousands of customers and partners are affected by a data breach, organisations can also face significant legal ramifications in the form of litigation and GDPR violations. 

A data breach notification must contain at least the following information:

  • a description of the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects, the categories concerned and the approximate number of personal data sets concerned;
  • the name and contact details of the Data Protection Officer or other contact point for further information;
  • a description of the likely consequences of the personal data breach;
  • a description of the measures taken or proposed by the controller to address the personal data breach and, where appropriate, measures to mitigate its possible adverse effects.

The views expressed herein are those of the author(s) and not necessarily the views of FTI Consulting, Inc., its management, its subsidiaries, its affiliates, or its other professionals. 

FTI Consulting, Inc., including its subsidiaries and affiliates, is a consulting firm and is not a certified public accounting firm or a law firm.

Organisations that do not comply with the legal requirements for reporting data breaches face heavy fines. For the particularly serious violations listed in the Data Protection Act under Article 83(5), the fine range is up to 20 million euros or, up to 4% of the organisation’s total annual turnover achieved worldwide in the previous financial year — whichever is the higher.

Tags

data, data protection, data breach, data protection act, gdpr, reputational damage, data protection officer, violations, data & analytics, e-discovery & managed review, information governance privacy & security