# Article 19 GDPR - Notification of Rectification, Erasure or Restriction — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/article-19-notification-rectification-erasure-restriction
> Sources are cited per item. Verify against the official texts before relying on them.

This specific GDPR provision addresses the controller's obligation to notify data subjects and third parties about rectification, erasure, or restriction of processing. It is a distinct procedural requirement that deserves its own dedicated topic for comprehensive coverage of notification obligations under Article 19.

## Overview

## Legal Framework

Article 19 GDPR imposes a downstream notification obligation on controllers: when personal data are rectified, erased, or restricted pursuant to Articles 16, 17(1), or 18, the controller must communicate that action to every recipient to whom the data were previously disclosed. This obligation serves the GDPR's broader coherence principle — ensuring that a data subject's rights are effective not only against the original controller but also against third parties who received the data. The provision contains two distinct duties. First, the controller must inform each recipient of the rectification, erasure, or restriction. Second, upon the data subject's request, the controller must inform the data subject about who those recipients were.

The obligation is qualified by a proportionality carve-out: notification is not required where it proves impossible or involves disproportionate effort. This mirrors the structure of Article 14(5)(b) and Article 11(2), reflecting the GDPR's recognition that absolute downstream traceability may be unfeasible in certain architectures. However, controllers bear the burden of demonstrating that the exception applies, and the threshold is high — mere inconvenience or cost does not suffice.

## Key Developments

The proportionality exception under Article 19 remains largely untested at the Court of Justice level, leaving controllers with limited judicial guidance on its boundaries. Dutch administrative case law, including the Council of State's decision in ECLI:NL:RVS:2006:AY0333, illustrates courts' reluctance to accept narrow readings of controller obligations when identity and data accuracy are at stake — a principle that extends by analogy to Article 19's notification duty.

Enforcement activity has primarily targeted controllers who fail to maintain adequate records of data recipients, making Article 19 compliance structurally impossible. The Polish DPA's enforcement actions — including fines against a housing association and a gynecological center — demonstrate that supervisory authorities treat the failure to track recipients and notify them of corrective actions as a serious compliance gap, even where the underlying processing violation itself may seem minor. The relatively modest fine amounts in these cases reflect the scale of the controllers rather than the gravity of the obligation.

The EDPB's Guidelines 3/2019 on video surveillance processing and Guidelines 10/2020 on Article 23 restrictions both touch on the practical mechanics of identifying recipients, particularly in contexts where data sharing is opaque or automated.

## Practical Guidance

- **Maintain a recipient registry for each data category**: Article 19 cannot be satisfied retroactively. Controllers must log, at the time of disclosure, the identity of each recipient and the category of data shared. Without this, the proportionality exception becomes the only defense — and it is a weak one.

- **Build notification workflows into rectification and erasure processes**: When acting on a request under Articles 16, 17(1), or 18, the system should automatically trigger downstream notifications. Manual ad hoc processes invite enforcement risk.

- **Document the proportionality assessment**: If you invoke the "impossible or disproportionate effort" exception, record the specific reasons — volume of recipients, technical barriers, cost relative to risk to the data subject. Unsupported invocations will not withstand DPA scrutiny.

- **Respond to data subject requests for recipient information promptly**: Article 19's second sentence gives data subjects a direct right to learn who received their data. Treat this as a standalone access right with its own response timeline, not as an optional add-on.

- **Account for indirect recipients**: Data disclosed to processors, joint controllers, or parties who subsequently re-share the data may fall within the scope of "each recipient." Map the full chain, not just immediate counterparties.

## Legislation (full text of key provisions)

### Notification obligation regarding rectification or erasure of personal data or restriction of processing

*Source: GDPR, gdpr-art-19-en, 2016-04-27 — https://overview.legal/posts/90457*

The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.

### Recital 89 — abolition of general notification obligation

*Source: GDPR, gdpr-rec-89-en, 2016-04-27 — https://overview.legal/posts/91693*

Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. While that obligation produces administrative and financial burdens, it did not in all cases contribute to improving the protection of personal data. Such indiscriminate general notification obligations should therefore be abolished, and replaced by effective procedures and mechanisms which focus instead on those types of processing operations which are likely to result in a high risk to the rights and freedoms of natural persons by virtue of their nature, scope, context and purposes. Such types of processing operations may be those which in, particular, involve using new technologies, or are of a new kind and where no data protection impact assessment has been carried out before by the controller, or where they become necessary in the light of the time that has elapsed since the initial processing.

### Recital 54 — hosting service content restriction notification obligations

*Source: DSA, dsa-rec-54-en, 2022-10-19 — https://overview.legal/posts/95505*

Where a provider of hosting services decides, on the ground that the information provided by the recipients is illegal content or is incompatible with its terms and conditions, to remove or disable access to information provided by a recipient of the service or to otherwise restrict its visibility or monetisation, for instance following receipt of a notice or acting on its own initiative, including exclusively by automated means, that provider should inform in a clear and easily comprehensible way the recipient of its decision, the reasons for its decision and the available possibilities for redress to contest the decision, in view of the negative consequences that such decisions may have for the recipient, including as regards the exercise of its fundamental right to freedom of expression. That obligation should apply irrespective of the reasons for the decision, in particular whether the action has been taken because the information notified is considered to be illegal content or incompatible with the applicable terms and conditions. Where the decision was taken following receipt of a notice, the provider of hosting services should only reveal the identity of the person or entity who submitted the notice to the recipient of the service where this information is necessary to identify the illegality of the content, such as in cases of infringements of intellectual property rights.

## Case law

### German Supreme Court: No GDPR basis for debt transmission to credit agency; €500 damages

*Source: German Supreme Court, 2026-05-12 — https://overview.legal/posts/53895 — original: https://gdprhub.eu/index.php?title=BGH_-_VI_ZR_375/2*

Facts — A debt collection agency (the controller) sent reminders to a customer (the data subject) for delayed installment payments related to a terminated electricity contract in November 2019. The data subject considered the claimed sums to be excessive and refused to pay. The controller transmitted the information on outstanding debts of €795 and €817 to a credit information agency, which in turn made negative entries in its database. This lowered the credit score assigned to the data subject by the credit information agency. The data subject sued the controller for disclosing outstanding receivables to the credit information agency. The court of first instance ordered the controller to revoke the negative entries contained in the credit ranking database and awarded the data subject €500 in damages. The controller appealed this decision. The appellate court held that there had been no legal basis for the transmission of personal data, as the data subject had not consented to the processing and the requirements for legitimate interests pursuant to Article 6(1)(f) GDPR were not met. However, the court considered that the data subject had not suffered any non-material damage within the meaning of Article 82 GDPR. The controller appealed the case further to the Federal Court of Justice. Holding — The Federal Court of Justice dismissed the controller’s appeal and referred the case back to the appellate court. First, the court held transmitting the personal data to the credit information agency had been unlawful due to the lack of a legal basis. It pointed out that the requirements for processing based on legitimate interests laid down in Article 6(1)(f) GDPR were not met. As such, legitimate public interests in preventing the granting of credit to those who are unable or unwilling to pay could justify the transfer of data to credit information agencies. However, no meaningful indications regarding the data subject’s ability or willingness to pay could be derived from the credit information entries at issue: the controller had failed to demonstrate the debts existed in the amount claimed. Therefore, it could not rely on legitimate interests as a legal basis. Second, the court held that the data subject was entitled to the revocation of the disputed credit information entries due to the unlawful disclosure of their personal data. According to the court, this claim could be based on 1) the application of Article 19 GDPR in conjunction with Article 17(1) (d) GDPR, 2) Article 19 GDPR in conjunction with Articles 5(1)(a), 5(2), and 24(1) GDPR, or 3) national law by analogy. Third, the court held that the data subject had suffered non-material damage within the meaning of Article 82 GDPR due to the harm caused to their economic reputation. The fact that the credit reports adversely affected the data subject’s credit score, which could then be taken into account by potential contractual partners, was enough to give rise to a claim for damages. The court pointed out that the transmission of personal data to one recipient and the risk of further transmissions to third parties already constituted loss of control; the data subject did not need to prove a feeling of helplessness, fear, or anxiety to be entitled to damages.

### Tax data sharing from FIOD criminal probe to Tax Authority not GDPR erasure violation

*Source: Rb. Midden-Nederland, 2022-05-09 — https://overview.legal/posts/125666 — original: https://gdprhub.eu/index.php?title=Rb._Midden-Nederland_-_UTR_21/3403*

Facts — The controller is the Minister of Finance. The data subject’s personal data was processed by the Tax Authority because it suspected him of not fulfilling his tax obligations. This suspicion was raised after the Fiscal Information and Investigation Service (FIOD) had carried out a criminal investigation into the data subject’s tax consultant. As a result of the Tax Authority’s investigation, the data subject had to pay additional taxes. The data subject claimed that the processing was unlawful requested the controller to erase his personal data pursuant to Articles 17(1)(d) GDPR, Article 17(2) GDPR, and Article 19 GDPR. The controller rejected this request. The data subject objected to the rejection. The controller declared the objection to be unfounded. The data subject then brought the case before the Court. The data subject argued that there were two instances of processing: (1) the selection of the personal data by the Tax Authority of the data collected by the FIOD, and (2) the transfer of personal data from the FIOD to the Tax Authority. The data subject claimed that the Tax Authority processed his personal data without a legal basis, and for a different purpose than it was initially collected for (by the FIOD). The controller, claimed that the selection and collection of the personal data did not fall within the scope of the GDPR, because the Tax Authority acted in the context of assistance to criminal investigations under the Police Information Act at that time. Moreover, the controller stated that there was a legal basis since the Authority had to process for the fulfilment of a statutory obligation, and the performance of a task in the public interest, even though the transfer of the personal data to the Tax Authority did fall within the scope of the GDPR, Holding — The Court rejected the data subject’s claim and held that the processing by the Tax Authority had been lawful. First, the Court stated that the FIOD’s processing of personal data falls within the scope of the Law Enforcement Directive 2016/680 (LED), which has been transposed into the Police Information Act. Moreover, Articles 18 and 19 of the Police Information Act provide a legal basis for the structural and incidental provision of police data to particular persons or bodies for specifically defined purposes (such as the Tax Authority). The Court further stated that the Tax Authority selected (and therefore processed) the personal data for the purpose of checking whether the data subject was obligated to pay additional taxes. Since this purpose is not a purpose that is covered by the purposes as covered by the Police Information Act, it falls without of its scope, and within the scope of the GDPR. Second, the Court stated that both the selection of personal data by the Tax Authority, as well as the transfer to Authority, falls under the legal basis of Article 6(1)(e) GDPR, since the Tax Authority processes this personal data to fulfil a public interest, and this obligation is laid down in Article 6(1)(c) AWR (General Act on State Taxation). Lastly, the Court stated that the processing also falls within the scope of Article 23(1)(e) GDPR, and thus the processing does not violate Article 6(4) GDPR. Hence, the Court concluded that all of the requirements as set out in Article 6 GDPR had been fulfilled.

## Guidance

### Opinion 2/2018 on the draft list of the competent supervisory authority of Belgium regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-22018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126274 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-22018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 2 /2018 on the draft list of the competent supervisory authority of Belgium regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 14/2018 on the draft list of the competent supervisory authority of Latvia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-142018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126270 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-142018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 14 /2018 on the draft list of the competent supervisory authority of Latvia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 10/2018 on the draft list of the competent supervisory authority of Hungary regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-102018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126282 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-102018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 10 /2018 on the draft list of the competent supervisory authority of Hungary regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 5/2018 on the draft list of the competent supervisory authorities of Germany regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-52018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126311 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-52018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 5 /2018 on the draft list of the competent supervisory authorit ies of Germany regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 21/2018 on the draft list of the competent supervisory authority of Slovakia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-212018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126305 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-212018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 21 /2018 on the draft list of the competent supervisory authority of Slovakia regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Opinion 22/2018 on the draft list of the competent supervisory authority of the United Kingdom regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-222018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126295 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-222018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 22 /2018 on the draft list of the competent supervisory authority of the United Kingdom regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................…

### Opinion 1/2018 on the draft list of the competent supervisory authority of Austria regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

*Source: EDPB, opinion-12018-on-the-draft-list-of-the-competent-supervisory-en, 2018-10-03 — https://overview.legal/posts/126293 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-12018-on-the-draft-list-of-the-competent-supervisory_en*

Opinion 1/2018 on the draft list of the competent supervisory authority of Austria regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 25th September 2018 2 Contents 1. Summary of the Facts ................................ ................................ ................................ ........ 4 2. Assessment ................................ ................................ ................................…

### Statement 1/2025 on Age Assurance

*Source: EDPB, statement-12025-on-age-assurance-en, 2025-02-12 — https://overview.legal/posts/125696 — original: https://www.edpb.europa.eu/documents/statement/statement-12025-on-age-assurance_en*

1 Statement 1/2025 on Age Assurance Adopted on 11 February 2025 1 The European Data Protection Board has adopted the following statement: 1. BACKGROUND AND PURPOSE OF THIS STATEMENT 1. The European regulatory framework calls for the increased protection of children in the digital environment. For example, the Audiovisual Media Services Directive 2 , which Member States have transposed into their national laws, highlights the possibility to implement age verification measures (Articles 6a and…

## Enforcement decisions

### AEPD (Spain) - EXP202203606

*Source: AEPD (Spain), 2022-04-22 — https://overview.legal/posts/125657 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202203606*

Facts — Resolution No. R/00665/2022 is highlighted by a case concerning a claimant (namely A.A.A) and a respondent party (namely Securitas Direct España, S.A). The claimant filed against the respondent party for not having been duly attended to his right of access and deletion enshrined in Articles 15 to 22 GDPR, Articles 13 to 18 LOPDGDD and Article 17 GDPR respectively. The conflict of law arose in this case when a sufficiently legally established response was not generated by the respondent to the claimants request. Furthermore, the claim was transferred to the respondent so that the entity could proceed with its analysis and provide a response to the claimant within a period of one month. The Director of the Spanish Data Protection Agency agreed to admit the claim for processing and the parties concerned were informed of the maximum term for resolution, that being six months. The competence of the Spanish Data Protection Agency is refined by Article 55 GDPR in the promotion of an obligation between controllers and processors to deal with complaints issued by data subjects. The result of the said transfer did not allow the claimants issues to be understood as satisfied. Consequently, due to the lack of attention delegated to the claimants rights further set forth in Article 15 GDPR, Article 16 GDPR, Article 17 GDPR, Article 18 GDPR, Article 19 GDPR, Article 20 GDPR, Article 21 GDPR and Article 22 GDPR, an agreement to admit for processing was initiated. Holding — The Director of the Spanish Data Protection Agency went on to note that considering the purpose of the outlined procedure was to ensure that the rights of affected parties were fully restored, the complaint that gave rise to this procedure should be upheld on formal grounds due to the fact that the right of access had been complied with and the right of erasure had been duly denied (on the applicable grounds of Article 17 GDPR).

### Court Bailiff: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2025-10-23 — https://overview.legal/posts/49055 — original: https://www.enforcementtracker.com/ETid-2940*

The Polish DPA has imposed a fine of EUR 5,000 on a court bailiff. The controller forwarded a letter containing personal data to the wrong person, failing to inform either the affected data subjects or the DPA.

### Association: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2024-04-30 — https://overview.legal/posts/48441 — original: https://www.enforcementtracker.com/ETid-2326*

The Polish DPA has fined an association EUR 210 for failing to report a data breach to the DPA in a timely manner.

### Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2021-06-30 — https://overview.legal/posts/46884 — original: https://www.enforcementtracker.com/ETid-769*

The Polish DPA (UODO) has imposed a fine of EUR 3,000 on the Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra Foundation for the promotion of mediation and legal education. The controller had not immediately informed the DPA and the data subjects about a personal data breach. Several folders containing personal data had been stolen from the controller in early 2020. These included the names, addresses and telephone numbers, and in 3 to 4 cases also the PESEL numbers (Polish identificatio

### Tusla Child and Family Agency: Insufficient fulfilment of data breach notification obligations

*Source: Data Protection Authority of Ireland, 2020-06-30 — https://overview.legal/posts/46435 — original: https://www.enforcementtracker.com/ETid-320*

The organization sent a letter with abuse allegations to a third party who then uploaded it to social networks.

### Housing association: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2023-02-07 — https://overview.legal/posts/47847 — original: https://www.enforcementtracker.com/ETid-1732*

The Polish DPA has imposed a fine of EUR 321 on a housing association. The controller had suffered a data breach involving the theft of documents, including a copy of a notarial deed. During its investigation, the DPA found that the controller had both failed to report the data breach to the DPA in a timely manner and to notify the data subjects affected by the incident. Further, the DPA found that the controller had not adequately checked if the processor provided sufficient guarantees to imple

### Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2020-12-28 — https://overview.legal/posts/46616 — original: https://www.enforcementtracker.com/ETid-501*

The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a notification from a third party about a personal data breach involving an insurance agent acting as a processing agent for Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. who sent an insurance policy to an unauthorized addressee by email. The document contained personal data concerning, among others, surnames, first name

### PVV Overijssel: Insufficient fulfilment of data breach notification obligations

*Source: Autoriteit Persoonsgegevens, 2020-06-16 — https://overview.legal/posts/46787 — original: https://www.enforcementtracker.com/ETid-672*

The Dutch DPA (AP) fined the Overijssel local branch of the PVV party EUR 7,500 for failing to notify the AP of a personal data breach, in violation of Art. 33 GDPR. An email regarding the convening of a meeting had been sent via an open distribution list due to a human error. Since the total of 101 recipients were addressed as 'Friends of the PVV' in the email, the political beliefs of the data subjects were thus disclosed to all addressees.

## Recent developments

### Decision to amend the "Decision on Notification Procedures and Data Processing in the Shipping Sector" in connection with the implementation of the Maritime National Single Window.

*Source: Legislation, 2025-09-23 — https://overview.legal/posts/52122*

Decision to amend the "Decision on Notification Procedures and Data Processing in Shipping" in connection with the implementation of the Maritime National Single Window.

## Literature

### REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT

*Source: AFMN Biomedicine, 2026-07-13 — https://overview.legal/posts/132435 — original: https://doi.org/10.65641/afmnai-2026-075*

lt;p style= quot;text-align: justify; quot; gt; lt;span class= quot;a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none quot; gt;Artificial intelligence (AI) represents a global phenomenon changing all spheres of human life. Biomedical engineering is no exception, as many AI systems are applied to biomedical engineering inventions. The European Union has enacted the new EU AI Act, one of the world amp;rsquo;s first laws on AI. The

## Related topics

- **Notified Body Reporting and Notification Obligations** — https://overview.legal/topics/notified-body-reporting-obligations
  The content addresses specific reporting and notification obligations of notified bodies to authorities and other stakeholders, which is a distinct operational 
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Data Breaches** — https://overview.legal/topics/datalekken
  Security incidents involving unauthorized access to personal data
- **Notification Obligation** — https://overview.legal/topics/meldplicht
  Duty to report data breaches to authorities and affected individuals
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

---
Generated by overview.legal · https://overview.legal/topics/article-19-notification-rectification-erasure-restriction · 2026-08-22
