Compare with different regulatory event:

Description

Adopted Version 2 of Guidelines on personal data breach notification under GDPR

On 28 March 2023, the European Data Protection Board (EDPB) adopted the Version 2 of the Guidelines 09/2022 on personal data breach notification under GDPR, amending the guidelines to specify the obligations of data controllers concerning data breach notifications at non-EU establishments. The Guidelines specify that the presence of a data controller representative in a Member State does not trigger the one-stop-shop system, which allows reporting a data breach only to the EU lead supervisory authority. The data controllers not established in the EU will have to report the breach to every authority where the affected data subjects reside. The amendment to the Guidelines clarifies that the data controller is responsible for reporting data breaches and removes the section specifying that the reporting should be done in accordance with the mandate given to the representative of the data controller in the EU.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
supranational
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2022-10-10
adopted

On 10 October 2022, the European Data Protection Board (EDPB) adopted the "Guidelines 09/2022 on pe…

2022-10-18
in consultation

On 18 October 2022, the European Data Protection Board (EDPB) opened a consultation on the updated …

2022-10-29
in consultation

On 29 November 2022, the public consultation on the European Data Protection Board (EDPB) updated "…

2023-03-28
adopted

On 28 March 2023, the European Data Protection Board (EDPB) adopted the Version 2 of the Guidelines…