Home

Some companies that have chosen us

Privacy Officer and Privacy Consultant
CDP Scheme according to ISO/IEC 17024:2012
European Privacy Auditor
ISDP©10003 Certification Scheme according to ISO/IEC 17065:2012
Auditor
According to standard UNI 11697:2017
Lead Auditor ISO/IEC 27001:2022
According to standard ISO/IEC 17024:2012
Data Protection Officer
According to standard ISO/IEC 17024:2012
Anti-Bribery Lead Auditor Expert
According to standard ISO/IEC 17024:2012
ICT Security Manager
According to standard UNI 11506:2017
IT Service Management (ITSM)
According to the ITIL Foundation
Ethical Hacker (CEH)
According to the EC-Council
Network Defender (CND)
According to the EC-Council
Computer Hacking Forensics Investigator (CHFI)
According to the EC-Council
Penetration Testing Professional (CPENT)
According to the EC-Council

Professional qualifications

Stay up-to-date with world news!

Select your topics of interest:

News

Home / News
/
SPANISH SUPERVISORY AUTHORITY: new form of notification for personal data gaps

SPANISH SUPERVISORY AUTHORITY: new form of notification for personal data gaps

The Agency has updated the form which permits to data controller to fulfil the obligation to report some gaps. This new system simplifies the notification of some personal data gaps by guiding data controllers with concrete questions, in order that they shall be aware of points that shall be processed into this system.

The new form facilitates also the gradual notification of personal data gaps, by establishing two types of notifications: new or modification of a previous notification, this last one for cases in which not all the relevant information are available within 72 hours required by the General Data Protection Regulation. Regarding the execution of a new notification, the system permits to data controller to carry out a new notification with relevant information without providing additional documents in this moment, because where appropriate, the Agency shall ask the necessary information.

The Agency uses a communication channel with data controllers by the enable electronic address. Data controllers receives both communications with information on the personal data breach status or both any other type of notification.

The notification to the Supervisory Authority of a personal data breach is part of the proactive responsibility required into the GDPR and the notification does not imply the begin of an administrative processing. Actually, the notification in time is a proof of diligence of the organization, meanwhile the lack of the respect of this obligation is classified as a breach.

This new form for the notification to the Personal Data Protection Agency is added to the instrument “Comunica-Brecha RGPD”, which helps companies and organization to decide if communicate or not a personal data breach to data subjects.

guia-brechas-seguridad (2)

SOURCE: AUTORITA’ PER LA PROTEZIONE DEI DATI DELLA SPAGNA – AEPD

Recommended to you

Advanced Research