Germany Federal Data Protection Act (BDSG)
Part 3: processing by competent authorities for law enforcement (Directive (EU) 2016/680) – Germany Federal Data Protection Act (BDSG)

Germany Federal Data Protection Act (BDSG) s66: s 66 Tell data subjects of breaches likely to pose a substantial risk

Where a breach probably creates a substantial risk for individuals' protected interests, the controller notifies the data subjects without delay in clear and plain language with at least the contact point, likely consequences and measures. This is not required where effective protection such as encryption applied, subsequent measures remove the substantial risk, or it would take disproportionate effort (then a public communication or equally effective measure is used). The Federal Commissioner may find the conditions not met; notification may be deferred, restricted or omitted on the s 56(2) grounds unless the data subjects' interests prevail given the high risk.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 1 control

  • GDPR-Art.34 Communication of a personal data breach to the data subject

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Part 3: processing by competent authorities for law enforcement (Directive (EU) 2016/680) – Germany Federal Data Protection Act (BDSG)

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.