The controller must notify the Commissioner of a personal data breach as soon as possible and no later than 72 hours after becoming aware of it, unless it is unlikely to endanger data subjects' rights and freedoms, giving reasons for any delay. The notification must at least describe the nature of the breach with, where possible, the categories and approximate numbers of data subjects and records; give the DPO's or another contact point's details; describe likely consequences; and describe measures taken or proposed, including mitigation; information may follow in phases. The processor must notify the controller immediately after becoming aware of a breach. The controller must document every breach, its facts, effects and remedial action so the Commissioner can verify compliance, and the Commissioner may order communication to data subjects where the risk is high. Paragraph 3, the duty to inform data subjects of a breach likely to present a high risk (not needed where the data were protected for example by encryption, later measures make the risk low, or a public notice replaces disproportionate individual notices), enters into force on 17 January 2027.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.