Speaking slot

26 January 2018: Erik Valgaeren participates in a session on notification of personal data breach at the CDPD Conference

26 January 2018: Erik Valgaeren participates in a session on notification of personal data breach at the CDPD Conference

26 January 2018: Erik Valgaeren participates in a session on notification of personal data breach at the CDPD Conference

23.01.2018 BE law

Stibbe is a long standing partner of the International Computers, Privacy and Data Protection Conference (CPDP) which takes place in Brussels between 24 and 26 January 2018.

The theme of this year’s edition is “The Internet of Bodies”.

Erik Valgaeren, head of our Data Protection team, participates in a panel session on notification of personal data breach.

According to the GDPR, the data controller is required to adopt certain security measures in order to prevent such breaches. Nonetheless, in case of an eventual breach, the controller is required to notify the competent authority, and under certain conditions, the data subject as well. The main criteria for notification are “as soon as the controller has become aware”, and “high risks to the rights and freedoms of natural persons”, respectively. As these criteria are vague in nature, it is not always clear when and who must be notified. Taking into account the recent opinion of the WP29, this panel will discuss the notification duties under the GDPR, their timing, raison d’etre and risk mitigation.

  • How to define the moment a controller becomes aware of the data breach?
  • When to notify the competent supervisory authority, and when the data subject? 
  • How to address personal data breaches in the DPIA process, considering they do not refer to the same “high risk”?

Click here for more information on the programme.

Related news

12.03.2020 EU law
Stibbe sets up corona team

Inside Stibbe - The coronavirus (COVID-19) may have legal consequences for your business. We have set up a team of specialists who can provide insight into the legal implications of the virus.

Read more

10.03.2020 NL law
De AVG staat niet in de weg aan de verwerking van persoonsgegevens door een toezichthouder tijdens een bedrijfsbezoek

Short Reads - Bedrijven die met toezicht worden geconfronteerd, zijn gehouden op verzoek van een toezichthouder in beginsel alle informatie te verstrekken. Met de komst van de Algemene verordening gegevensbescherming (AVG) is in de praktijk de vraag opgekomen of een toezichthouder bevoegd is om persoonsgegevens die onderdeel uitmaken van de gevraagde informatie te verwerken.

Read more

18.03.2020 EU law
Stibbe: COVID-19

Short Reads - In view of the developments concerning the coronavirus, we hereby inform you of our business operations and the measures we take to ensure the continuity of our services to you.

Read more

26.02.2020 BE law
18 March 2020: Erik Valgaeren sheds a light on the legal perspectives of industrial data during a Beltug conference

Speaking slot - In this era of digitisation, data is often called the 'new gold' or 'oil'.  In our aim to gain more insights that will lead us to higher revenue, new market opportunities or new regions, we are analysing data at full throttle. But it needs to be handled with care, using a data architecture that follows your general strategy while ensuring solid security, quality, etc.

Read more

This website uses cookies. Some of these cookies are essential for the technical functioning of our website and you cannot disable these cookies if you want to read our website. We also use functional cookies to ensure the website functions properly and analytical cookies to personalise content and to analyse our traffic. You can either accept or refuse these functional and analytical cookies.

Privacy – en cookieverklaring