PDPF · Question #53
After notifying the supervisory authority, what should be the first action the controller must take when it finds a security breach where unauthorized people have accessed personal data?
The correct answer is B. Analyze whether sensitive data has been accessed. It is necessary to check the extent of this personal data breach, what data has been accessed and what is the risk to his or her. Depending on this extension, in addition to notifying the supervisory authority, it will also be mandatory to notify the owners of the breached data.
Question
After notifying the supervisory authority, what should be the first action the controller must take when it finds a security breach where unauthorized people have accessed personal data?
Options
- AContact the DPO for formal notification to the Supervisory Authority.
- BAnalyze whether sensitive data has been accessed.
- CRegister a Police Report at the cybercrime station.
- DNotify data subjects that have been subject to a security breach.
How the community answered
(22 responses)- A9% (2)
- B68% (15)
- C5% (1)
- D18% (4)
Explanation
It is necessary to check the extent of this personal data breach, what data has been accessed and what is the risk to his or her. Depending on this extension, in addition to notifying the supervisory authority, it will also be mandatory to notify the owners of the breached data.
Topics
Community Discussion
No community discussion yet for this question.