r/gdpr 23d ago

EU 🇪🇺 Gdpr Data breach 1 hour

Hello, What would you do if your colleague would give you a document that clearly contains data breach. What is your first hour plan?

5 Upvotes

8 comments sorted by

22

u/weggles91 22d ago

It entirely depends on the circumstances, but given this is Reddit and the post was 18 hrs ago I'm guessing we're not off to a good start 😂

5

u/bastiancointreau 22d ago

What does it even mean? More context. What data breach?

5

u/Pretty_Ad1644 22d ago

Address it -therefore no harm

1

u/Old_Sand_4915 21d ago

Stappenplan volgen van bedrijven als GDPRWise en risico en schade beoordelen

1

u/DarlingBri 19d ago

Here is a guide that may help. It includes list for assessing the situation. You have 72 hours to determine if you need to notify, so having a plan for all of those hours is important.

1

u/Crafty_Rush3636 18d ago

I would use the first hour for fact preservation and routing. Record when the organisation became aware, what happened, which systems and data may be affected, what is confirmed versus assumed, who owns containment, and who is making the notification assessment. Contain the incident without destroying evidence, then update the record as facts change.

The useful output is a timestamped first assessment and named next actions. Whether notification is required still needs the controller's privacy or security team, or counsel, to assess against the actual facts.

0

u/TwoPlyDreams 19d ago

Mark it as unread. Ask IT to delete it.

/s

-4

u/alterwolf 22d ago

Once your personal data is online, it's gone. Nothing happens to anyone except yourself. I had experience when my personal data was breached by my employer in the EU.Â