# Notified Body Reporting and Notification Obligations — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/notified-body-reporting-obligations
> Sources are cited per item. Verify against the official texts before relying on them.

The content addresses specific reporting and notification obligations of notified bodies to authorities and other stakeholders, which is a distinct operational requirement deserving separate coverage.

## Overview

## Legal Framework

Article 19 GDPR establishes a downstream notification obligation: when a controller rectifies, erases, or restricts processing of personal data under Articles 16, 17(1), or 18, it must communicate that change to every recipient to whom the data were previously disclosed. This obligation is subject to a proportionality carve-out — the controller need not comply where notification proves impossible or involves disproportionate effort — but must, upon request, inform the data subject of those recipients. Article 51 GDPR complements this by requiring each Member State to designate one or more independent supervisory authorities responsible for monitoring GDPR application. The doctrinal commentary confirms that the Netherlands has designated the Autoriteit Persoonsgegevens as its sole supervisory authority, declining the GDPR's option to establish additional sector-specific authorities.

Beyond GDPR, NIS2 Recital 116 introduces representative and reporting obligations for non-EU service providers offering services within the Union — including cloud computing, data centre, managed service, and DNS providers — creating an overlapping notification regime for entities that may also process personal data. Recital 28 clarifies that the Digital Operational Resilience Act (DORA) governs ICT-related incident reporting for financial entities, displacing NIS2 provisions in that sector.

## Key Developments

Enforcement practice demonstrates that supervisory authorities treat breach notification failures as standalone violations warranting independent fines. The Polish DPA (UODO) imposed a €9,450 fine on a Gynecological Center that suffered a data breach but failed to report it to the DPO — establishing that the notification obligation runs to the supervisory authority regardless of whether the underlying breach itself is contested. In a separate action, UODO fined a Housing Association €2,350 for insufficient fulfilment of data breach notification duties, indicating that partial or deficient notification — not merely total omission — triggers liability.

The EDPB's Guidelines 04/2022 on administrative fine calculation provide the methodology supervisory authorities apply when assessing these violations, ensuring harmonised treatment across Member States. The EDPB also issued version 2.0 of its Guidelines 9/2022 on personal data breach notification, refining the practical standards for what constitutes a notifiable breach.

Dutch case law reinforces that institutional obligations cannot be deflected through procedural limitations. The Council of State's 2006 ruling (ECLI:NL:RVS:2006:AY0333) confirmed that municipal authorities bear full responsibility for properly establishing identity under the GBA, and the Gerechtshof Den Haag's 2026 decision demonstrated that operational failures — including late filing of annual accounts — can constitute serious professional misconduct, signalling that systemic administrative failures carry consequences beyond their immediate context.

## Practical Guidance

- **Map all recipients before notification becomes necessary.** Article 19 requires communication to each recipient of disclosed data. Controllers who cannot identify recipients ex ante will struggle to meet the proportionality threshold and should maintain disclosure logs as a matter of course.
- **Establish a dual-track breach notification procedure.** Notifications must reach both the supervisory authority (Article 33) and, where applicable, affected data subjects (Article 34). The Polish enforcement actions confirm that failure on either track constitutes an independent violation.
- **Assess NIS2 overlap for cross-regime entities.** Cloud providers, managed service providers, and data centre operators offering services in the Union must evaluate whether NIS2 incident reporting obligations run parallel to GDPR breach notification — and designate an EU representative where not established in the Union.
- **Document the proportionality analysis for Article 19.** When deciding that downstream notification involves disproportionate effort, record the reasoning contemporaneously. The burden of justifying non-notification rests with the controller.
- **Verify sector-specific displacement.** Financial entities should confirm whether DORA's ICT incident reporting regime has fully displaced NIS2 obligations for their operations, as Recital 28 contemplates, to avoid duplicate reporting or gaps.

## Legislation (full text of key provisions)

### Notification obligation regarding rectification or erasure of personal data or restriction of processing

*Source: GDPR, gdpr-art-19-en, 2016-04-27 — https://overview.legal/posts/90457*

The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.

### Notification of a personal data breach to the supervisory authority

*Source: GDPR, gdpr-art-33-en, 2016-04-27 — https://overview.legal/posts/90633*

### Recital 101 — multiple-stage significant incident reporting

*Source: NIS2, nis2-rec-101-en, 2022-12-14 — https://overview.legal/posts/96730*

This Directive lays down a multiple-stage approach to the reporting of significant incidents in order to strike the right balance between, on the one hand, swift reporting that helps mitigate the potential spread of significant incidents and allows essential and important entities to seek assistance, and, on the other, in-depth reporting that draws valuable lessons from individual incidents and improves over time the cyber resilience of individual entities and entire sectors. In that regard, this Directive should include the reporting of incidents that, based on an initial assessment carried out by the entity concerned, could cause severe operational disruption of the services or financial loss for that entity or affect other natural or legal persons by causing considerable material or non-material damage. Such initial assessment should take into account, inter alia, the affected network and information systems, in particular their importance in the provision of the entity’s services, the severity and technical characteristics of a cyber threat and any underlying vulnerabilities that are being exploited as well as the entity’s experience with similar incidents. Indicators such as the extent to which the functioning of the service is affected, the duration of an incident or the number of affected recipients of services could play an important role in identifying whether the operational disruption of the service is severe.

### Recital 89 — abolition of general notification obligation

*Source: GDPR, gdpr-rec-89-en, 2016-04-27 — https://overview.legal/posts/91693*

Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. While that obligation produces administrative and financial burdens, it did not in all cases contribute to improving the protection of personal data. Such indiscriminate general notification obligations should therefore be abolished, and replaced by effective procedures and mechanisms which focus instead on those types of processing operations which are likely to result in a high risk to the rights and freedoms of natural persons by virtue of their nature, scope, context and purposes. Such types of processing operations may be those which in, particular, involve using new technologies, or are of a new kind and where no data protection impact assessment has been carried out before by the controller, or where they become necessary in the light of the time that has elapsed since the initial processing.

### Recital 56 — hosting service criminal threat reporting obligation

*Source: DSA, dsa-rec-56-en, 2022-10-19 — https://overview.legal/posts/95509*

A provider of hosting services may in some instances become aware, such as through a notice by a notifying party or through its own voluntary measures, of information relating to certain activity of a recipient of the service, such as the provision of certain types of illegal content, that reasonably justify, having regard to all relevant circumstances of which the provider of hosting services is aware, the suspicion that that recipient may have committed, may be committing or is likely to commit a criminal offence involving a threat to the life or safety of person or persons, such as offences specified in Directive 2011/36/EU of the European Parliament and of the Council (27), Directive 2011/93/EU or Directive (EU) 2017/541 of the European Parliament and of the Council (28). For example, specific items of content could give rise to a suspicion of a threat to the public, such as incitement to terrorism within the meaning of Article 21 of Directive (EU) 2017/541. In such instances, the provider of hosting services should inform without delay the competent law enforcement authorities of such suspicion. The provider of hosting services should provide all relevant information available to it, including, where relevant, the content in question and, if available, the time when the content was published, including the designated time zone, an explanation of its suspicion and the information necessary to locate and identify the relevant recipient of the service. This Regulation does not provide the legal basis for profiling of recipients of the services with a view to the possible identification of criminal offences by providers of hosting services. Providers of hosting services should also respect other applicable rules of Union or national law for the protection of the rights and freedoms of individuals when informing law enforcement authorities.

### Recital 102 — significant incident notification timelines and reporting

*Source: NIS2, nis2-rec-102-en, 2022-12-14 — https://overview.legal/posts/96732*

Where essential or important entities become aware of a significant incident, they should be required to submit an early warning without undue delay and in any event within 24 hours. That early warning should be followed by an incident notification. The entities concerned should submit an incident notification without undue delay and in any event within 72 hours of becoming aware of the significant incident, with the aim, in particular, of updating information submitted through the early warning and indicating an initial assessment of the significant incident, including its severity and impact, as well as indicators of compromise, where available. A final report should be submitted not later than one month after the incident notification. The early warning should only include the information necessary to make the CSIRT, or where applicable the competent authority, aware of the significant incident and allow the entity concerned to seek assistance, if required. Such early warning, where applicable, should indicate whether the significant incident is suspected of being caused by unlawful or malicious acts, and whether it is likely to have a cross-border impact. Member States should ensure that the obligation to submit that early warning, or the subsequent incident notification, does not divert the notifying entity’s resources from activities related to incident handling that should be prioritised, in order to prevent incident reporting obligations from either diverting resources from significant incident response handling or otherwise compromising the entity’s efforts in that respect. In the event of an ongoing incident at the time of the submission of the final report, Member States should ensure that entities concerned provide a progress report at that time, and a final report within one month of their handling of the significant incident.

### Recital 94 — competent authorities trust services cooperation

*Source: NIS2, nis2-rec-94-en, 2022-12-14 — https://overview.legal/posts/96716*

Member States can assign the role of the competent authorities for trust services to the supervisory bodies under Regulation (EU) No 910/2014 in order to ensure the continuation of current practices and to build on the knowledge and experience gained in the application of that Regulation. In such a case, the competent authorities under this Directive should cooperate closely and in a timely manner with those supervisory bodies by exchanging relevant information in order to ensure effective supervision and compliance of trust service providers with the requirements laid down in this Directive and in Regulation (EU) No 910/2014. Where applicable, the CSIRT or the competent authority under this Directive should immediately inform the supervisory body under Regulation (EU) No 910/2014 about any notified significant cyber threat or incident affecting trust services as well as about any infringements by a trust service provider of this Directive. For the purpose of reporting, Member States can, where applicable, use the single entry point established to achieve a common and automatic incident reporting to both the supervisory body under Regulation (EU) No 910/2014 and the CSIRT or the competent authority under this Directive.

### Recital 116 — non-EU digital service provider EU representative

*Source: NIS2, nis2-rec-116-en, 2022-12-14 — https://overview.legal/posts/96760*

Where a DNS service provider, a TLD name registry, an entity providing domain name registration services, a cloud computing service provider, a data centre service provider, a content delivery network provider, a managed service provider, a managed security service provider or a provider of an online marketplace, of an online search engine or of a social networking services platform, which is not established in the Union, offers services within the Union, it should designate a representative in the Union. In order to determine whether such an entity is offering services within the Union, it should be ascertained whether the entity is planning to offer services to persons in one or more Member States. The mere accessibility in the Union of the entity’s or an intermediary’s website or of an email address or other contact details, or the use of a language generally used in the third country where the entity is established, should be considered to be insufficient to ascertain such an intention. However, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering services in that language, or the mentioning of customers or users who are in the Union, could make it apparent that the entity is planning to offer services within the Union. The representative should act on behalf of the entity and it should be possible for the competent authorities or the CSIRTs to address the representative. The representative should be explicitly designated by a written mandate of the entity to act on the latter’s behalf with regard to the latter’s obligations laid down in this Directive, including incident reporting.

### Recital 155 — high-risk AI post-market monitoring systems

*Source: AI Act, aiact-rec-155-en, 2024-06-12 — https://overview.legal/posts/93992*

In order to ensure that providers of high-risk AI systems can take into account the experience on the use of high-risk AI systems for improving their systems and the design and development process or can take any possible corrective action in a timely manner, all providers should have a post-market monitoring system in place. Where relevant, post-market monitoring should include an analysis of the interaction with other AI systems including other devices and software. Post-market monitoring should not cover sensitive operational data of deployers which are law enforcement authorities. This system is also key to ensure that the possible risks emerging from AI systems which continue to ‘learn’ after being placed on the market or put into service can be more efficiently and timely addressed. In this context, providers should also be required to have a system in place to report to the relevant authorities any serious incidents resulting from the use of their AI systems, meaning incident or malfunctioning leading to death or serious damage to health, serious and irreversible disruption of the management and operation of critical infrastructure, infringements of obligations under Union law intended to protect fundamental rights or serious damage to property or the environment.

### Recital 4 — internal market cybersecurity requirements harmonization

*Source: NIS2, nis2-rec-4-en, 2022-12-14 — https://overview.legal/posts/96536*

The legal basis of Directive (EU) 2016/1148 was Article 114 of the Treaty on the Functioning of the European Union (TFEU), the objective of which is the establishment and functioning of the internal market by enhancing measures for the approximation of national rules. The cybersecurity requirements imposed on entities providing services or carrying out activities which are economically significant vary considerably among Member States in terms of type of requirement, their level of detail and the method of supervision. Those disparities entail additional costs and create difficulties for entities that offer goods or services across borders. Requirements imposed by one Member State that are different from, or even in conflict with, those imposed by another Member State, may substantially affect such cross-border activities. Furthermore, the possibility of the inadequate design or implementation of cybersecurity requirements in one Member State is likely to have repercussions at the level of cybersecurity of other Member States, in particular given the intensity of cross-border exchanges. The review of Directive (EU) 2016/1148 has shown a wide divergence in its implementation by Member States, including in relation to its scope, the delimitation of which was very largely left to the discretion of the Member States. Directive (EU) 2016/1148 also provided the Member States with very wide discretion as regards the implementation of the security and incident reporting obligations laid down therein. Those obligations were therefore implemented in significantly different ways at national level. There are similar divergences in the implementation of the provisions of Directive (EU) 2016/1148 on supervision and enforcement.

## Case law

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

## Guidance

### Opinion 14/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR

*Source: EDPB, opinion-142026-on-the-europrivacy-certification-criteria-en, 2026-04-16 — https://overview.legal/posts/125682 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-142026-on-the-europrivacy-certification-criteria_en*

Opinion 14 / 2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR Adopted on 15 April 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64 (2) and Article 42 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free…

### Guidelines 04/2022 on the calculation of administrative fines under the GDPR

*Source: EDPB, edpb-guidelines-on-the-calculation-of-administrative-fines-under-the-gdpr, 2023-05-24 — https://overview.legal/posts/38068 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042022-on-the-calculation-of-administrative-fines-under-the-gdpr_en*

The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory  authorities use  when calculating of the amount of the fine. These Guidelines complement the previously  adopted Guidelines on the application and setting of administrative fines  for the purpose  of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine. The calculation of the amount of the fine is at the discretion of the supervisory  authority, ...

### Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-032023-on-the-draft-decision-of-the-competent-en, 2023-02-17 — https://overview.legal/posts/125871 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-032023-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 03/2023 on the draft decision of the competent supervisory authority of Romania regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 3 February 2023 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3)-(8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 28/2022 on the Europrivacy criteria of certification regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 (GDPR)

*Source: EDPB, opinion-282022-on-the-europrivacy-criteria-of-certification-en, 2022-10-10 — https://overview.legal/posts/125889 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282022-on-the-europrivacy-criteria-of-certification_en*

Adopted 1 Opinion 28/2022 on the Europrivacy criteria of certification regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 (GDPR) Adopted on 10 October 2022 Adopted 2 The European Data Protection Board Having regard to Article 63, Article 64( 2 ) and Article 42 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free…

### Guidelines 01/2021

*Source: EDPB, edpb-guidelines-on-examples-regarding-personal-data-breach-notification, 2022-01-03 — https://overview.legal/posts/38047 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012021-on-examples-regarding-personal-data-breach-notification_en*

The European Data Protection Board (EDPB) adopted Guidelines 01/2021 on December 14, 2021, providing practical examples and analysis regarding personal data breach notification obligations under Articles 33 and 34 of the GDPR. The guidelines present hypothetical scenarios covering ransomware attacks and data exfiltration incidents, illustrating how controllers should assess risk to determine whether notification to supervisory authorities and communication to data subjects are required. The document serves as interpretive guidance for controllers evaluating breach severity, appropriate mitigation measures, and notification decisions, and does not impose any fines or sanctions.

### Opinion 38/2021 on the draft decision of the competent supervisory authority of Latvia regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR)

*Source: EDPB, opinion-382021-on-the-draft-decision-of-the-competent-en, 2021-11-20 — https://overview.legal/posts/125980 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-382021-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 38 /2021 on the draft decision of the competent supervisory authority of Latvia regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) Adopted on 20 November 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1c), (3) - (8) and Article 43 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural…

### Opinion 11/2021 on the draft decision of the competent supervisory authority of Norway regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-112021-on-the-draft-decision-of-the-competent-en, 2021-03-23 — https://overview.legal/posts/126044 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-112021-on-the-draft-decision-of-the-competent_en*

1 Adopted Opinion 11 / 202 1 on the draft decision of the competent supervisory authority of Norway regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 23 March 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of…

### Opinion 3/2020 on the France data protection supervisory authority draft accreditation requirements for a code of conduct monitoring body pursuant to article 41 GDPR

*Source: EDPB, opinion-32020-on-the-france-data-protection-supervisory-en, 2020-01-28 — https://overview.legal/posts/126194 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-32020-on-the-france-data-protection-supervisory_en*

Adopted Opinion 3 / 2020 on the F rance data protection supervisory authority draft accreditation requirements for a code of conduct monitoring body pursuant to article 41 GDPR Adopted on 28 January 2020 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64 (1)(c), (3) - (8) and Article 41 (3) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of…

## Enforcement decisions

### Association: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2024-04-30 — https://overview.legal/posts/48441 — original: https://www.enforcementtracker.com/ETid-2326*

The Polish DPA has fined an association EUR 210 for failing to report a data breach to the DPA in a timely manner.

### Tusla Child and Family Agency: Insufficient fulfilment of data breach notification obligations

*Source: Data Protection Authority of Ireland, 2020-06-30 — https://overview.legal/posts/46435 — original: https://www.enforcementtracker.com/ETid-320*

The organization sent a letter with abuse allegations to a third party who then uploaded it to social networks.

### Court Bailiff: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2025-10-23 — https://overview.legal/posts/49055 — original: https://www.enforcementtracker.com/ETid-2940*

The Polish DPA has imposed a fine of EUR 5,000 on a court bailiff. The controller forwarded a letter containing personal data to the wrong person, failing to inform either the affected data subjects or the DPA.

### Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2021-06-30 — https://overview.legal/posts/46884 — original: https://www.enforcementtracker.com/ETid-769*

The Polish DPA (UODO) has imposed a fine of EUR 3,000 on the Fundację Promocji Mediacji i Edukacji Prawnej Lex Nostra Foundation for the promotion of mediation and legal education. The controller had not immediately informed the DPA and the data subjects about a personal data breach. Several folders containing personal data had been stolen from the controller in early 2020. These included the names, addresses and telephone numbers, and in 3 to 4 cases also the PESEL numbers (Polish identificatio

### Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A.: Insufficient fulfilment of data breach notification obligations

*Source: Polish National Personal Data Protection Office (UODO), 2020-12-28 — https://overview.legal/posts/46616 — original: https://www.enforcementtracker.com/ETid-501*

The Polish DPA (UODO) fined Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. EUR 18,930 for a breach of Art. 33 (1) GDPR and Art. 34 (1) GDPR. In May 2020, the DPA received a notification from a third party about a personal data breach involving an insurance agent acting as a processing agent for Towarzystwo Ubezpieczeń i Reasekuracji WARTA S.A. who sent an insurance policy to an unauthorized addressee by email. The document contained personal data concerning, among others, surnames, first name

### HUNGARY DPA: Insufficient fulfilment of data breach notification obligations

*Source: Hungarian National Authority for Data Protection and the Freedom of Information (NAIH), 2019-06-25 — https://overview.legal/posts/46189 — original: https://www.enforcementtracker.com/ETid-74*

The data controller did not fulfil its data breach notification obligations when a flash memory with personal data was lost.

### Directorate of Social and Child Welfare Institutions of the Ferencvaros District of Budapest: Insufficient fulfilment of data breach notification obligations

*Source: Hungarian National Authority for Data Protection and the Freedom of Information (NAIH), 2019-05-21 — https://overview.legal/posts/46366 — original: https://www.enforcementtracker.com/ETid-251*

The employee of the Directorate sent by mistake 9 letters to the wrong recipient, which contained personal data of 18 data subjects (including data of children, criminal data and data related to the private life of the data subjects). The recipient informed the Directorate by telephone 5 days after the posting that it received certain letters by mistake. The Directorate notified NAIH on the data breach only weeks later.

### GERMANY DPA: Insufficient fulfilment of data breach notification obligations

*Source: Data Protection Authority of Hamburg, 2018-01-01 — https://overview.legal/posts/46144 — original: https://www.enforcementtracker.com/ETid-29*

Late notification of a data breach and failure to notify the data subjects.

## Recent developments

### “Social media profiles and phone contacts” used as proof of identity for deportations

*Source: European Digital Rights, 2023-03-29 — https://overview.legal/posts/6226 — original: https://edri.org/our-work/social-media-profiles-and-phone-contacts-used-as-proof-of-identity-for-deportations/#entry-4248*

> 
					Thirteen non-EU countries sometimes accept “social media profiles and phone contacts” as evidence of identity for the purpose of deportations, according to an internal European Commission assessment of third country cooperation on readmission.

## Literature

### REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT

*Source: AFMN Biomedicine, 2026-07-13 — https://overview.legal/posts/132435 — original: https://doi.org/10.65641/afmnai-2026-075*

lt;p style= quot;text-align: justify; quot; gt; lt;span class= quot;a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none quot; gt;Artificial intelligence (AI) represents a global phenomenon changing all spheres of human life. Biomedical engineering is no exception, as many AI systems are applied to biomedical engineering inventions. The European Union has enacted the new EU AI Act, one of the world amp;rsquo;s first laws on AI. The

## Related topics

- **Article 19 GDPR - Notification of Rectification, Erasure or Restriction** — https://overview.legal/topics/article-19-notification-rectification-erasure-restriction
  This specific GDPR provision addresses the controller's obligation to notify data subjects and third parties about rectification, erasure, or restriction of pro
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Data Breaches** — https://overview.legal/topics/datalekken
  Security incidents involving unauthorized access to personal data
- **Notification Obligation** — https://overview.legal/topics/meldplicht
  Duty to report data breaches to authorities and affected individuals
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

---
Generated by overview.legal · https://overview.legal/topics/notified-body-reporting-obligations · 2026-08-22
