The most important facts at a glance
- An unreported data breach can result in fines of up to 10 million euros or 2% of annual global turnover
- Companies must report data breaches to the competent supervisory authority within 72 hours
- With professional support and the right immediate measures, fines can often be avoided or significantly reduced
The challenge: handling data breaches correctly
In the digitalized business world, data breaches are unfortunately no longer a rarity. Whether due to hacker attacks, technical errors or human error - the loss or unauthorized disclosure of personal data can have far-reaching consequences. The fact that the GDPR provides for severe fines for breaches of the reporting obligation is particularly critical. As a company, you are faced with the challenge of acting quickly and in a legally compliant manner in an emergency. An experienced Lawyer for data protection can help you to take the right measures and avoid possible fines.
What is a reportable data breach?
A data breach within the meaning of Art. 33 GDPR occurs when the security of personal data is compromised. This can occur through the unintentional sending of emails with personal data to the wrong recipients, through the loss or theft of data carriers or through hacker attacks with access to customer data. Misconfigurations that make data publicly accessible are also included. The decisive factor for the reporting obligation is the potential risk to the rights and freedoms of the data subjects.
Deadlines and obligations in the event of data breaches
The law leaves no leeway here: data breaches must be reported to the responsible supervisory authority immediately, but at the latest within 72 hours of becoming known. In addition, Section 65 BDSG requires a report to the Federal Commissioner for Data Protection. The report must contain a detailed description of the incident, the type of data affected, the estimated number of people affected and the measures already taken.
The consequences of not reporting
The consequences of an unreported data breach can be serious. In addition to fines of up to 10 million euros or 2% of global annual turnover, there is the threat of considerable reputational damage due to late disclosure. Added to this are stricter audits by supervisory authorities and possible claims for damages by those affected. Our experience shows that a professional and prompt response can significantly minimize these risks.
Our expertise in data breaches
Having successfully handled numerous data breach cases, our law firm has extensive experience in this sensitive area. We support you in containing the damage immediately, reporting it to all relevant bodies in accordance with the law and communicating professionally with the authorities and those affected. We also help you to develop preventive measures to avoid future incidents.
Frequently asked questions
The legal responsibility for compliance with data protection generally lies with the company management. Although certain tasks can be delegated, for example to a data protection officer or the IT department, the final responsibility remains with the management. This also applies to the timely reporting of data breaches and the implementation of appropriate protective measures.
All mishaps that pose a risk to the rights and freedoms of those affected must be reported. A careful case-by-case assessment is essential here. We support you in this assessment.
The GDPR provides for fines of up to 10 million euros or 2% of annual global turnover. The specific amount depends on various factors, such as the severity of the breach and the behavior after the breach was discovered.
After the report, the supervisory authority examines the incident and may request further information or measures. Professional monitoring of this communication is important for the further course of events.
The notification must include the type and scope of the data concerned, the number of data subjects, possible consequences and measures already taken.
The notification must be made within 72 hours of becoming known. If this is not possible, the delay must be justified.
Yes, if the data breach is likely to result in a high risk to the personal rights and freedoms of the data subjects. The information must be provided in clear and simple language and contain specific information on how the data subjects can protect themselves. We support you in the legally compliant formulation of this sensitive communication.
Most data breaches are caused by human error, such as incorrectly addressed emails or the loss of data storage media. Technical vulnerabilities, hacker attacks and inadequate access controls are also common causes. Targeted preventative measures and employee training can minimize many of these risks.
A well-prepared emergency plan is crucial. This should define clear responsibilities, reporting channels and immediate measures.
Complete documentation is required by law and is essential for communication with supervisory authorities. You must be able to prove when and how you found out about the data breach, what measures you have taken and how you intend to prevent future incidents.