Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: SV

Artikel 33 Anmälan av en personuppgiftsincident till tillsynsmyndigheten


Summary What does Article 33 of the GDPR regulation say?

This article sets out the notification obligations that apply following a personal data breach.

It is closely linked to Article 34, which deals with communicating breaches directly to data subjects, while this article focuses on the duty to notify the supervisory authority.

The core requirement is that controllers must report a breach to the competent supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.

The article also brings processors into the picture, requiring them to alert the controller without undue delay upon discovering a breach.

Beyond the timing requirements, the article specifies the minimum content of the notification and adds a documentation obligation, ensuring there is a verifiable record of every breach and the response taken.

Important points:

  • Notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to pose a risk to individuals' rights and freedoms. If the 72-hour deadline is missed, reasons for the delay must be provided.
  • Processors are required to notify the controller without undue delay upon becoming aware of a personal data breach.
  • Document all personal data breaches, including the facts, effects, and remedial action taken, in a manner that allows the supervisory authority to verify compliance.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Vid en personuppgiftsincident ska den personuppgiftsansvarige utan onödigt dröjsmål och, om så är möjligt, inte senare än 72 timmar efter att ha fått vetskap om den, anmäla personuppgiftsincidenten till den tillsynsmyndighet som är behörig i enlighet med artikel 55, såvida det inte är osannolikt att personuppgiftsincidenten medför en risk för fysiska personers rättigheter och friheter. Om anmälan till tillsynsmyndigheten inte görs inom 72 timmar ska den åtföljas av en motivering till förseningen.

    1. Personuppgiftsbiträdet ska underrätta den personuppgiftsansvarige utan onödigt dröjsmål efter att ha fått vetskap om en personuppgiftsincident.

    1. Den anmälan som avses i punkt 1 ska åtminstone

      1. beskriva personuppgiftsincidentens art, inbegripet, om så är möjligt, de kategorier av och det ungefärliga antalet registrerade som berörs samt de kategorier av och det ungefärliga antalet personuppgiftsposter som berörs,

      2. förmedla namnet på och kontaktuppgifterna för dataskyddsombudet eller andra kontaktpunkter där mer information kan erhållas,

      3. beskriva de sannolika konsekvenserna av personuppgiftsincidenten, och

      4. beskriva de åtgärder som den personuppgiftsansvarige har vidtagit eller föreslagit för att åtgärda personuppgiftsincidenten, inbegripet, när så är lämpligt, åtgärder för att mildra dess potentiella negativa effekter.

    1. Om och i den utsträckning det inte är möjligt att tillhandahålla informationen samtidigt, får informationen tillhandahållas i omgångar utan onödigt ytterligare dröjsmål.

    1. Den personuppgiftsansvarige ska dokumentera alla personuppgiftsincidenter, inbegripet omständigheterna kring personuppgiftsincidenten, dess effekter och de korrigerande åtgärder som vidtagits. Dokumentationen ska göra det möjligt för tillsynsmyndigheten att kontrollera efterlevnaden av denna artikel.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod