Security incident and reporting

A security incident in the field of personal data is a breach of protection that leads to unauthorised access, disclosure, alteration or loss of data – ranging from sending a bulk email with visible addresses, through a lost laptop, to a system attack. If the incident poses a risk to individuals' rights, the company must report it to the supervisory authority, generally within seventy-two hours of becoming aware of it. In the case of high risk, it also has an obligation to inform the data subjects themselves, clearly and without undue delay. Every incident is also recorded internally, even when it is not reported. Meeting such a deadline without a prepared procedure is unrealistic, so it is worth having decided in advance who assesses the incident, who reports it, and where the supporting information comes from.

See also: Privacy policy, NIS2 and cybersecurity, Corporate crisis communication.