CIPP-E · Question #105
In the event of a data breach, which type of information are data controllers NOT required to provide to either the supervisory authorities or the data subjects?
The correct answer is A. The predicted consequences of the breach. According to the CIPP/E study guide, Article 33 of the GDPR requires data controllers to notify the supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to…
Question
In the event of a data breach, which type of information are data controllers NOT required to provide to either the supervisory authorities or the data subjects?
Options
- AThe predicted consequences of the breach.
- BThe measures being taken to address the breach.
- CThe type of security safeguards used to protect the data.
- DThe contact details of the appropriate data protection officer.
How the community answered
(45 responses)- A76% (34)
- B2% (1)
- C16% (7)
- D7% (3)
Explanation
According to the CIPP/E study guide, Article 33 of the GDPR requires data controllers to notify the supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Article 34 of the GDPR requires data controllers to communicate the personal data breach to the data subject without undue delay when the breach is likely to result in a high risk to the rights and freedoms of natural persons. Both articles specify the minimum information that the data controller must provide to the supervisory authority and the data subject, which includes: the nature of the breach, the categories and approximate number of data subjects and personal data records concerned, the name and contact details of the data protection officer or other contact point, the likely consequences of the breach, and the measures taken or proposed to address the breach and mitigate its possible adverse effects. However, neither article requires the data controller to disclose the type of security safeguards used to protect the data, as this information is not relevant for the purposes of notification and may even compromise the security of the data further.
Topics
Community Discussion
No community discussion yet for this question.