QuestionQ9

Compliance with European Data Protection Law and Regulation

An unexpected power outage leaves company Z unable to access customer data for six hours. Under Article 32 of the GDPR, this is considered a breach. Based on the WP 29 guidance from February 2018, what should company Z do?

  • A Notify affected individuals that their data was unavailable for a period of time.
  • B Document the loss of availability to demonstrate accountability
  • C Notify the supervisory authority about the loss of availability
  • D Conduct a thorough audit of all security systems
Explanation

Controllers must document every personal data breach, including the relevant facts, effects, and remedial action, so that compliance can be demonstrated. Notification to a supervisory authority depends on likely risk to individuals’ rights and freedoms, and communication to affected individuals depends on high risk; neither threshold is established here.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!