GDPR
Chapter IV - Controller and Processor

GDPR GDPR-Art.34: Communication of a personal data breach to the data subject

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, communicate the breach to the affected data subjects without undue delay, describing in clear and plain language the nature of the breach and giving at least the contact point, the likely consequences and the measures taken or proposed including mitigation. Communication is not required where the controller had implemented appropriate technical and organisational protection measures and applied them to the affected data, in particular measures such as encryption rendering the data unintelligible to anyone unauthorised, where the controller has since taken measures making the high risk no longer likely to materialise, or where individual communication would involve disproportionate effort, in which case a public communication or similar equally effective measure must be made instead. The supervisory authority may require communication or decide that one of the exemptions applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 28 controls across 25 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 2 controls

  • 6.13.1 Management of information security incidents and improvements
  • 8.2.1 Customer agreement

NIST SP 800-53 Rev 5 · 2 controls

  • PMF-M.4 Privacy Incident Management

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

Canadian PIPEDA · 1 control

  • CAYDPA-s16 Personal Data Breach Notification (s.16)
  • PIPL-Art57 Breach Remediation and Notification

DORA · 1 control

  • UAE-PDPL-Art.9 Data breach notification (UAE PDPL Article 9)
  • s66 s 66 Tell data subjects of breaches likely to pose a substantial risk

NIS2 Directive · 1 control

  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients
  • 42 Art. 42 Rely on the exemption from notifying data subjects of breaches only as a financial undertaking
  • NDB Notifiable Data Breaches scheme

Privacy Act 2020 · 1 control

  • NZPRV-7 Notifiable Privacy Breach Scheme
  • RO-LAW190-014 Personal Data Breach Notification

SOC 2 · 1 control

  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • UZB-DPL-16 Incident Notification

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV - Controller and Processor

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.34 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 28 it maps to, and the evidence behind each claim, over MCP and REST.