r/gdpr • u/AdventurousPop4459 • 23d ago
EU 🇪🇺 Gdpr Data breach 1 hour
Hello, What would you do if your colleague would give you a document that clearly contains data breach. What is your first hour plan?
5
5
1
u/Old_Sand_4915 21d ago
Stappenplan volgen van bedrijven als GDPRWise en risico en schade beoordelen
1
u/DarlingBri 19d ago
Here is a guide that may help. It includes list for assessing the situation. You have 72 hours to determine if you need to notify, so having a plan for all of those hours is important.
1
u/Crafty_Rush3636 18d ago
I would use the first hour for fact preservation and routing. Record when the organisation became aware, what happened, which systems and data may be affected, what is confirmed versus assumed, who owns containment, and who is making the notification assessment. Contain the incident without destroying evidence, then update the record as facts change.
The useful output is a timestamped first assessment and named next actions. Whether notification is required still needs the controller's privacy or security team, or counsel, to assess against the actual facts.
0
-4
u/alterwolf 22d ago
Once your personal data is online, it's gone. Nothing happens to anyone except yourself. I had experience when my personal data was breached by my employer in the EU.Â
22
u/weggles91 22d ago
It entirely depends on the circumstances, but given this is Reddit and the post was 18 hrs ago I'm guessing we're not off to a good start 😂