Introduction
When a personal data breach occurs, time is critical. GDPR requires notification to the authority within 72 hours. This guide presents the essential steps.
First 24 Hours
Hour 0-4: Detection and Containment
- Confirm the incident - verify if it's a real breach
- Contain the threat - isolate affected systems
- Preserve evidence - don't delete logs
- Activate response team - contact responsible parties
Hour 4-12: Initial Assessment
- Identify affected data - what categories?
- Estimate number of subjects - how many people?
- Assess risk - what's the probability of harm?
- Document everything - create chronological record
Hour 12-24: Impact Analysis
- Classify the breach - low, medium or high risk
- Determine obligations - notify CNPD? Data subjects?
- Prepare communications - notification drafts
- Consult legal counsel - validate strategy
24-48 Hours
Notification to CNPD
When to notify:
- Whenever there's risk to rights and freedoms
- When in doubt, notify
Notification content:
- Nature of the breach
- Categories and number of subjects
- DPO or responsible contact
- Likely consequences
- Measures adopted or proposed
Communication to Data Subjects
When to communicate:
- If there's high risk to rights and freedoms
- Clear and accessible language
Content:
- What happened (without excessive technical details)
- What data was affected
- What we're doing
- What the subject can do
- Contact for questions
48-72 Hours
Final Documentation
- Complete incident record
- Archive evidence
- Prepare internal report
- Identify lessons learned
Corrective Measures
- Fix vulnerabilities
- Update procedures
- Reinforce training
- Review vendor contracts
After 72 Hours
Follow-up
- Monitor ongoing impact
- Respond to data subject requests
- Cooperate with CNPD if necessary
- Update notification if there are new developments
Future Prevention
- Review incident response plan
- Conduct security tests
- Update impact assessment
- Consider cyber insurance
Conclusion
Preparation is the best defense. Have an incident response plan before you need it.