SummaryFinal

EDPB 9/2022 & 01/2021 (Summary)

Personal data breaches: how to respond (EDPB summary of Guidelines 9/2022 and 01/2021)

This document condenses the full document.

What it covers

This is a short quick-reference summary of the EDPB guidelines on personal data breach notification, covering how to identify, document and assess a breach, and when to notify the competent data protection authority and affected individuals, illustrated with simplified examples; the full guidelines carry the detailed analysis.

Why it matters

It offers a fast overview of the breach-notification decision process for practitioners who need a quick answer before consulting the fuller guidelines for detailed examples.

Refer to it when

  • needing a quick checklist after discovering a data breach
  • deciding at a glance whether a DPA notification is required
  • briefing non-specialist staff on breach response steps

Questions this document addresses

  • What counts as a personal data breach?
  • When must a breach be notified to the DPA and within what timeframe?
  • When must affected individuals be notified?
  • What must be documented for every breach?

Topics

  • Personal data breaches
  • Security of processing
  • Supervisory authorities

Official EDPB page for this document

Plain-language EDPB summary of breach response duties, drawing together the breach notification guidelines and the case-based examples guidance.

Inline PDF preview is not supported in this browser. Open the PDF instead.

Mapped GDPR Articles

Reproduced from official EDPB publications for reference. Not legal advice.