Vai al contenuto

Data breach: what a company should do

The clock starts when you become aware, not when it happened. And not every breach has to be notified.

In breve

A personal data breach must be notified to the supervisory authority within seventy-two hours of becoming aware of it, but only where it poses a risk to individuals: a lost laptop with an encrypted disk may end differently. The assessment still has to be made and documented, and the breach register is kept even for the episodes you decide not to notify.

It is not only cyber attacks

An email to the wrong address, a lost laptop, an attachment copied to everyone. These are breaches and they have to be assessed.

Seventy-two hours from when you notice

Not from when it happened. And it is a deadline to notify, not to have solved everything: information can be added later.

Encryption changes the outcome

A lost device with an encrypted disk makes the data unintelligible, and that weighs decisively in the risk assessment.

It is not only cyber attacks

This is the misunderstanding that wastes most time at the worst moment. “Personal data breach” means destruction, loss, alteration or unauthorised disclosure of personal data — and in real casework a substantial share of episodes has nothing to do with an attack.

All of these have to be assessed by the same standard as a cyber attack. What makes the difference is the risk to individuals, not how dramatic the event was.

Encryption genuinely changes the outcome

This is one of the few cases where a simple technical measure directly reduces an obligation.

A company laptop lost without encryption is a breach with a concrete risk: whoever finds it can read the data. The same laptop with an encrypted disk makes that data unintelligible, and this weighs decisively in the risk assessment.

It is worth saying explicitly because it is a more persuasive practical argument than most: encrypting devices is not one more box to tick, it is what turns the loss of an object into a notification you can avoid.

The seventy-two hours, explained without alarm

The clock starts from becoming aware, not from when it happened. And it is a deadline to notify, not to have resolved: notification can be staged, adding information as the picture is reconstructed.

The real problem is not the deadline: it is arriving at it with enough information. Without preparation, the first seventy-two hours are spent working out what happened, and the notification is made incomplete or not at all.

Three things make it manageable, and they are prepared while nothing is happening:

Knowing which data sits where. That is exactly what is needed to say whether the breach involves personal data and which. It is also the practical reason the record of processing activities should be kept current rather than compiled once and filed away.

Having logs enabled. Without traces the event cannot be reconstructed, and without reconstruction nobody can honestly say which data was involved.

Knowing who decides. Who assesses the risk, who signs the notification, who speaks to the people affected. Without those names settled beforehand, time is lost exactly when there is none.

Not everything is notified, but everything is assessed

What has to be notified to the authority is a breach posing a risk to the rights and freedoms of individuals. Where that risk is unlikely, notification may not be required.

But the assessment has to be made and documented, because accountability requires being able to demonstrate the decisions, not merely to have taken them. This is where the document almost no company keeps comes in: the breach register, which records every episode — including the ones not notified — with the reasoning behind the decision taken.

It is the first thing asked for if a related problem emerges later, and it is also what distinguishes a company that assessed the situation from one that never noticed.

When the individuals have to be told as well

When the risk is high, the people affected have to be informed alongside the authority, without undue delay. It is the step with the greatest reputational impact, and it should be prepared in advance: the text of that communication is written badly under pressure, at a moment when the company has ten urgent problems at once.

The rest

See also incident response for the technical sequence of the first hours, GDPR consulting for the obligations upstream, and GAPOFF, where the breach register is a module rather than a file nobody reopens.

The first step

If a breach is under way, call us before touching the systems. If instead you want to be ready for one, the assessment of what is missing — logs, inventory, procedure, names — is free and without obligation.

Frequently asked questions

What counts as a personal data breach?

Destruction, loss, alteration or unauthorised disclosure of personal data. The phrase brings cyber attacks to mind, but in real casework a substantial share of episodes is far more mundane: an email with the client list sent to the wrong address, an attachment sent with visible rather than blind copy, a lost laptop, a paper archive left accessible, a mislaid backup disk.

When do the seventy-two hours start?

From becoming aware of the breach, not from when it happened. And it is a deadline to notify, not to have resolved everything: notification can be staged, adding information as the picture is reconstructed. The practical problem is not the deadline but arriving at it with enough information, and that depends on what was prepared beforehand.

Does every breach have to be notified?

No. What has to be notified to the authority is a breach posing a risk to the rights and freedoms of individuals. Where that risk is unlikely - the classic case being a lost device with an encrypted disk - notification may not be required. But the assessment still has to be made and documented, because accountability requires being able to demonstrate the decisions, not only to have taken them.

When do the individuals themselves have to be informed?

When the breach poses a high risk to their rights, and in that case the communication must be made without undue delay. It is the step with the greatest reputational impact and the one most worth preparing in advance, because it has to be written at a moment when the company has other urgent problems.

Do we need a register even if we do not notify?

Yes, and it is the part almost nobody keeps. The breach register has to be maintained for every episode, including those you decide not to notify, with the reasoning behind the decision. It is the document that shows an assessment was made, and it is the first thing asked for if a related problem emerges later.

If it is happening now, write to us straight away

In the first hours the decisions matter more than the tools: what to isolate, what to preserve as evidence, who to notify and by when. Tell us what is going on.