meta_pixel
Tapesearch Logo
Hear GDPR

Article 33

Hear GDPR

Hear GDPR

Government

51 Ratings

🗓️ 9 March 2021

⏱️ 2 minutes

🧾️ Download transcript

Summary

This episode is also available as a blog post: https://heargdpr.wordpress.com/2021/03/10/article-33/

Transcript

Click on a timestamp to play from that location

0:00.0

Article 33. Notification of a personal data breach to the supervisory authority.

0:09.4

In the case of a personal data breach, the controller shall without undue delay and, were feasible,

0:15.8

not later than 72 hours after having become aware of it.

0:19.3

Notify the personal data breach to the supervisory

0:21.8

authority competent in accordance with Article 55, unless the personal data breach is unlikely

0:27.0

to result in a risk to the rights and freedoms of natural persons. Where the notification to the

0:32.3

supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.

0:38.7

2. The processor shall notify the controller without undue delay after becoming aware of a personal

0:44.2

data breach. 3. The notification referred to in paragraph 1 shall at least. A. Describe the nature

0:51.8

of the personal data breach including where possible, the categories in approximate number of data subjects concerned and the nature of the personal data breach including where possible, the categories

0:55.1

in approximate number of data subjects concerned and the categories and approximate number

0:59.4

of personal data records concerned.

1:02.2

V, communicate the name and contact details of the data protection officer or other contact

1:07.1

point where more information can be obtained.

1:10.1

C, describe the likely consequences of the personal data obtained. C. Describe the likely consequences of the

1:12.5

personal data breach. D. Describe the measures taken or proposed to be taken by the controller

1:17.8

to address the personal data breach, including, where appropriate, measures to mitigate its

1:23.1

possible adverse effects. Four. Where, and insofar as, it is not possible to provide the information at the

1:30.4

same time, the information may be provided in phases without undue further delay.

1:35.8

5. The controller shall document any personal data breaches, comprising the facts relating to the

1:41.8

personal data breach, its effects and the remedial action taken.

1:46.0

That documentation shall enable the supervisory authority to verify compliance with this article.

...

Transcript will be available on the free plan in -1480 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from Hear GDPR, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Hear GDPR and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.