Speaking slot

26 January 2018: Erik Valgaeren participates in a session on notification of personal data breach at the CDPD Conference

26 January 2018: Erik Valgaeren participates in a session on notification of personal data breach at the CDPD Conference

26 January 2018: Erik Valgaeren participates in a session on notification of personal data breach at the CDPD Conference

23.01.2018 BE law

Stibbe is a long standing partner of the International Computers, Privacy and Data Protection Conference (CPDP) which takes place in Brussels between 24 and 26 January 2018.

The theme of this year’s edition is “The Internet of Bodies”.

Erik Valgaeren, head of our Data Protection team, participates in a panel session on notification of personal data breach.

According to the GDPR, the data controller is required to adopt certain security measures in order to prevent such breaches. Nonetheless, in case of an eventual breach, the controller is required to notify the competent authority, and under certain conditions, the data subject as well. The main criteria for notification are “as soon as the controller has become aware”, and “high risks to the rights and freedoms of natural persons”, respectively. As these criteria are vague in nature, it is not always clear when and who must be notified. Taking into account the recent opinion of the WP29, this panel will discuss the notification duties under the GDPR, their timing, raison d’etre and risk mitigation.

  • How to define the moment a controller becomes aware of the data breach?
  • When to notify the competent supervisory authority, and when the data subject? 
  • How to address personal data breaches in the DPIA process, considering they do not refer to the same “high risk”?

Click here for more information on the programme.

Related news

07.12.2018 BE law
GDPR-roundtable on practical questions encountered during implementation

Roundtable - After the success of the roundtable sessions we held before the GDPR took effect (in May this year), our TMT team is enthusiastic about the session of 7 December, focusing on the lessons we have learned from working on multiple GDPR-matters in the past year. We will tackle some practical questions that we have encountered and that are not or cannot be readily answered by the new regulation.

Read more

20.11.2018 NL law
Seminar 'Personal data from a broader perspective: overlap inside and outside the privacy domain'

Seminar - On 20 November 2018, Stibbe will host a seminar on privacy. Several Stibbe lawyers will discuss personal data from a broader perspective and the overlap that can occur inside and outside the legal privacy domain.

Read more

07.12.2018 BE law
Virtual Currency Regulation Law Review

Articles - The first edition of the Virtual Currency Regulation Law Review is intended to provide a practical, business-focused analysis of recent legal and regulatory changes and developments, and of their effects, and to look forward at expected trends in the area of virtual currencies on a country-by-country basis.

Read more

Our website uses cookies: third party analytics cookies to best adapt our website to your needs & cookies to enable social media functionalities. For more information on the use of cookies, please check our Privacy and Cookie Policy. Please note that you can change your cookie opt-ins at any time via your browser settings.

Privacy – en cookieverklaring