Link to home
Start Free TrialLog in
Avatar of Alan Dala
Alan Dala

asked on

Breach notification

While my current org does not fall under the GDPR umbrella, who knows in the future...I know the policy requires a breach notification within 72 hours but I'm not clear who should be notified within this period of time.

Thank you for your help!
Avatar of Madison Perkins
Madison Perkins
Flag of United States of America image

I am not an attorney and not providing any legal advise.

The data protection officer.  This role would fall under the cio or cto.  See articles 33, 35 and 55 of the dgpr.  

https://en.m.wikipedia.org/wiki/General_Data_Protection_Regulation
http://www.privacy-regulation.eu/en/
https://www.itgovernance.co.uk/blog/how-to-write-a-gdpr-compliant-personal-data-breach-notification-procedure/
ASKER CERTIFIED SOLUTION
Avatar of Adrian McGarry
Adrian McGarry
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
no response.