Short Reads

Countdown 7 weeks until GDPR : Will entities be required to report any contraventions of the GDPR to the regulators?

Stibbe - Will entities be required to report any serious contravention

Countdown 7 weeks until GDPR : Will entities be required to report any contraventions of the GDPR to the regulators?

05.04.2018 EU law

Only 7 more weeks to go before the GDPR becomes fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. Each week, we highlight one particular misconception regarding the interpretation of the GDPR.

Will entities be required to report any serious contraventions of the GDPR to the regulators and to data subjects affected?

According to Article 33.1 of the GDPR reporting those contraventions will not be required in all cases, but only if the breach in question implies a risk to the rights and freedoms of the individuals whose data have been affected by the contravention.

The Article 29 Working Party has clarified that there is a “risk to the rights and freedoms” if the breach can lead to physical, material, or non-material damage to the individuals whose data have been breached. Any such risk should appear to be related to a third party’s non-authorized access to the individual’s information, leading to the violation of that individual’s rights to privacy or any other relevant right (e.g., economic loss derived from the use of a credit card number of an individual whose data have been unduly accessed). When evaluating this risk, one should do so on the basis of an objective assessment while taking into account criteria such as the type of breach, the nature, sensitivity, and volume of personal data concerned, the ease of identification, the severity of consequences for individuals, etc.

Hence, according to this approach, incidents that have no consequences on the rights and freedoms of individuals (e.g., loss of information, without any third party having accessed to such data) should not be reported under the GDPR.

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

08.08.2019 BE law
Regulating online platforms: piece of the puzzle

Articles - The new Regulation no. 2019/1150 of the European Parliament and of the Council of 20 June 2019 on promoting fairness and transparency for business users of online intermediation services, applicable as of 12 July 2020, is another piece of the puzzle regulating online platforms, this time focussing on the supply side of the platforms.

Read more

19.08.2019 EU law
Enable “likes” and bear joint-controllership

Articles - The Court of Justice of the European Union recently ruled, in Case C-40/14 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV,  that a website operator that features “Like” social-media plugin from Facebook likely qualifies as joint-controller with Facebook for its website visitors’ personal data collection and transmission to Facebook.

Read more

23.07.2019 LU law
The Revised CSSF Cloud Circular

Articles - On 27 March 2019, the Luxembourg supervisory authority for the financial sector (the Commission de surveillance du secteur financier or CSSF) published the long-awaited CSSF Circular 19/714 amending the CSSF Circular 17/654 on IT outsourcing relying on a cloud computing infrastructure (the Revised Cloud Circular).

Read more

22.07.2019 NL law
HagaZiekenhuis beboet voor datalek

Short Reads - Enkele maanden geleden vierden we de eerste verjaardag van de Algemene Verordening Gegevensbescherming (AVG) met een uitgebreide beschouwing  over de belangrijkste  ontwikkelingen uit  het eerste jaar van de verordening. We concludeerden daarin onder meer dat de door sommigen voorspelde hoge bestuurlijke boetes voor overtredingen van de AVG tot dan toe  - zowel in Nederland als in de andere EU-lidstaten - grotendeels waren uitgebleven.

Read more

Our website uses functional cookies for the functioning of the website and analytic cookies that enable us to generate aggregated visitor data. We also use other cookies, such as third party tracking cookies - please indicate whether you agree to the use of these other cookies:

Privacy – en cookieverklaring