Article 34 of the GDPR: Notification to the Data Subject of a Personal Data Breach
Article 34 of the GDPR Explained
The data controller must inform the data subjects:
- When the breach is likely to result in a high risk (e.g., identity theft, financial loss, infringement of privacy, etc.);
- Through a clear and understandable communication;
- By specifying the nature of the breach, the possible consequences, and the measures taken.
This obligation does not apply if:
- Effective protection measures (e.g., encryption) have been implemented;
- Subsequent measures have eliminated the high risk;
- The communication would require disproportionate efforts (in which case, a public announcement may be used).
Why This Article is Important for Your GDPR Compliance
Informing data subjects in the event of a serious risk is essential to enable them to protect their rights (e.g. changing a password, monitoring their bank account...). This contributes to an approach of transparency and trust, which is at the heart of GDPR principles.
Examples of GDPR Article 34 Application
- A bank informs its customers after a hack of sensitive banking data;
- A company alerts its employees after the loss of a USB drive containing unencrypted payslips;
- A public authority issues an official notice after a vulnerability in its online services portal.
Related Resources
Accelerate your compliance in a few clicks
With our all-in-one solution, you can easily accelerate and ensure your compliance:
- Automate your compliance with our GDPR software
- Supported or outsourced by our DPO experts
- Raise your teams' awareness with our GDPR e-learning training
Assess your situation in 15 minutes with our free, no-obligation GDPR self-diagnostic.
How to Comply with Article 34 of the GDPR?