SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

EU GDPR Readiness Assessment - Supervisory Authority

  Quote
Guest
Guest user Created:   May 27, 2020 Last commented:   May 27, 2020

EU GDPR Readiness Assessment - Supervisory Authority

1. In Q23, of EU GDPR Readiness Assessment
23) Is a process in place to ensure the appropriate supervisory authority is notified within 72 hours of a confirmed data breach?
Who would the "Supervisory Authority" be? If in the US, who? If in the EU who?

2. Basically, who is to be notified within 72 hours of a confirmed data breach? 

0 0

Assign topic to the user

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

EU GDPR DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Alessandra Nisticò May 27, 2020

"On Q23, of EU GDPR Readiness Assessment

23) Is a process in place to ensure the appropriate supervisory authority is notified within 72 hours of a confirmed data breach?

Who would the "Supervisory Authority" be? If in US, who? If in EU who?

Supervisory Authority is your own country Data Protection Authority as established in article 51 GDPR.

You can find the full list of Data Protection Authorities in the following link.

If you are based in the US, you may have a representative in the EU and therefore you will notify the Data Protection Authority of the country where your EU representative under article 27 GDPR is located.

If you do not have an EU representative (i.e. your data processing is occasional), and you are based in the US, you should, in any case, follow the Federal Trade Commission’s guidelines on data breach: https://www.ftc.gov/tips-advice/business-center/guidance/data-breach-response-guide-business

Useful resources for complying with EU GDPR: https://advisera.com/eugdpracademy/knowledgebase/useful-links/

 

Basically, who is to be notified within 72 hours of confirmed data breach?"

According to article 33 GDPR, the data controller must notify the data breach to its own country data protection authority without undue delay and within 72 hours. If there is a risk for freedom and rights of data subjects, it may be requested to notify the data breach to data subjects in order to allow them to take precautions. Paragraph 86 of the Preamble of GDPR states that such notification shall be made without undue delay within 72 hours or in accordance with the Supervisory Authority instructions.

Here you can find some useful resources about Data protection Authorities:

You may also consider enrolling in this online EU GDPR Foundations Course: https://advisera.com/training/eu-gdpr-foundations-course//

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 27, 2020

May 27, 2020

Suggested Topics

Guest user Created:   Aug 06, 2023 EU GDPR
Replies: 1
0 0

Do we need VPN to comply with GDPR?

Guest user Created:   Jul 12, 2023 EU GDPR
Replies: 1
0 0

Business Continuity Plan and GDPR

Guest user Created:   Jun 19, 2023 EU GDPR
Replies: 1
0 0

TIA/TRA assessment tools