The controller must notify the Commissioner of a personal data breach under Article 29. Where the breach may present a significant risk to rights and freedoms it must communicate it to the data subject immediately in clear and plain language with at least the contact point, likely consequences and measures taken, unless the data were rendered unintelligible for example by encryption, later measures remove the risk, or a public notice replaces disproportionate individual communication; the Commissioner may require communication, and it may be delayed, restricted or refused on Article 55(3) grounds. Paragraphs 2, 3 and 5 enter into force on 17 January 2027.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.