It should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data breach has taken place and to inform promptly the supervisory authority and the data subject. The fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject. Such notification may result in an intervention of the supervisory authority in accordance with its tasks and powers laid down in this Regulation.
GDPR Recital EN
Recital 87
Related across sources
News The Italian SA fined Poste Vita for data breach Guidance Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement Guidance Version history Guidance Guidelines 9/2022 on personal data breach notification under GDPR News UODO (Poland) - DKN.5131.34.2023 News CNIL (France) - SAN-2025-014