A data breach under GDPR is not something a company can easily fix and move on from. If personal data is exposed, lost changed or accessed by the person the rules start to apply fast. Yes time is important.
The 72-Hour Rule
This is the part that people usually remember. If a personal data breach is likely to cause a risk to peoples rights and freedoms the organization must tell the data protection authority quickly. If possible, within 72 hours after finding out about it.
This does not mean every small mistake needs to be reported to the regulator. If someone sends an email to the internal address and the data is quickly secured with little or no risk reporting may not be necessary. The main question is whether there is a risk to people.
What Happens in Those 72 Hours?
The first hours are usually confusing. Someone notices activity on an account. Another person looks at the logs. Then someone starts to ask if the information was actually seen. The organization needs to check the situation while also deciding if the regulator should be informed.
If reporting is needed GDPR expects information about the breach. The organization should explain what occurred and describe the effects along with the actions being taken to handle the issue. If all the details are not ready within 72 hours the organization can provide the information in parts.
What About the People Affected?
This is where GDPR becomes more strict. If the breach is likely to cause a risk to individuals the organization usually has to tell those people as quickly as possible.
Imagine a company loses a database that contains information that could be used for identity theft. Telling the affected customers weeks later will not look good. People need a chance to protect themselves while the situation is still fresh.
Breaches Must Be Recorded Too
Even if a breach does not need to be reported to the regulator GDPR requires organizations to keep a record of data breaches. This record should show what happened what effects it had and what the organization did to respond.
The Cost of Getting It Wrong
GDPR gives regulators power to enforce the rules. Serious violations can result in fines of up to €20 million or 4% of the company’s worldwide annual income from the previous year whichever is higher.
So What Should a Company Do?
The best way is simple in theory even if the actual work is not. Have a plan in place before any problem happens. Know who is responsible, for investigating. Know who makes the decision to report. Keep records.
Do not wait for perfect information before taking action. GDPR allows organizations to update a report as more facts come in. The key is to act without making up details.