Speaking slot

26 January 2018: Erik Valgaeren participates in a session on notification of personal data breach at the CDPD Conference

26 January 2018: Erik Valgaeren participates in a session on notification of personal data breach at the CDPD Conference

26 January 2018: Erik Valgaeren participates in a session on notification of personal data breach at the CDPD Conference

23.01.2018 BE law

Stibbe is a long standing partner of the International Computers, Privacy and Data Protection Conference (CPDP) which takes place in Brussels between 24 and 26 January 2018.

The theme of this year’s edition is “The Internet of Bodies”.

Erik Valgaeren, head of our Data Protection team, participates in a panel session on notification of personal data breach.

According to the GDPR, the data controller is required to adopt certain security measures in order to prevent such breaches. Nonetheless, in case of an eventual breach, the controller is required to notify the competent authority, and under certain conditions, the data subject as well. The main criteria for notification are “as soon as the controller has become aware”, and “high risks to the rights and freedoms of natural persons”, respectively. As these criteria are vague in nature, it is not always clear when and who must be notified. Taking into account the recent opinion of the WP29, this panel will discuss the notification duties under the GDPR, their timing, raison d’etre and risk mitigation.

  • How to define the moment a controller becomes aware of the data breach?
  • When to notify the competent supervisory authority, and when the data subject? 
  • How to address personal data breaches in the DPIA process, considering they do not refer to the same “high risk”?

Click here for more information on the programme.

Related news

27.07.2020 NL law
Outsourcing laws and Regulation in the Netherlands – 2020

Articles - Are there any additional legal or regulatory requirements for outsourcing transactions undertaken by government or public sector bodies? What formalities are required to transfer, lease or license assets on an outsourcing transaction? Or, What are the most material legal or regulatory requirements and issues concerning data security and data protection that may arise on an outsourcing transaction?

Read more

29.07.2020 NL law
Over temperaturen ten tijde van corona

Articles - Met haar standpunt ten aanzien van het meten van temperaturen van werknemers, geeft de Autoriteit Persoonsgegevens (AP) verduidelijking over de reikwijdte van haar toezicht. Deze nuancering houdt in dat, als er geen sprake is van verwerking van persoonsgegevens, de AVG niet geldt en de AP dus niet handhavend kan optreden.

Read more

03.07.2020 NL law
E-book NOW-2: Second Temporary Emergency Bridging Measure Work Retention

Articles - On 17 March 2020, the Dutch cabinet announced the first emergency package of support measures to alleviate the economic consequences of the corona crisis. This emergency package inter alia comprised the First Temporary Emergency Bridging Measure for the purpose of Work Retention (“NOW-1”) and the Temporary Bridging Measure for Self-Employed Persons (“Tozo-1”).

Read more