emergency management in the event of data breaches

Data breach?
The 72-hour clock is ticking. We help immediately.

Whether it’s an email to the wrong distribution list, a lost laptop, or a ransomware attack—mistakes happen everywhere people work. The key is that you deal with it properly now. Our emergency team first assesses the incident and then, if necessary, reports it to the regulatory authority and notifies the affected individuals.

the first three steps in an emergency:
1

Stop the incident

Blocking access, disconnecting devices, recalling faulty shipments – curbing damage, but not deleting anything.

2

Note the time

When did the problem occur and when did you find out about it?

3

Contact us

We assess the risk with you.

+49 30 20 88 999 0

Emergency hotline for data breaches or by email sofortdatenschutz@mip-consult.de

ISO 9001
BvD member
GDD member
Made in Germany
20 years of experience
  • Federal Office for Information Security
  • Compliant with GDPR
  • BvD member
  • GDD member
  • Made in Germany
✓ Available on short notice ✓ Data protection officer and lawyers ✓ From Berlin, active worldwide
The definition

What is a data breach within the meaning of the GDPR?

A data breach, described GDPR as a „breach of the protection of personal data“, occurs when personal data is unintentionally or unlawfully destroyed, altered, disclosed or made accessible, or lost (Article 4, GDPR No. 12). A hacker attack is just one of many cases. Most data breaches occur in the workplace.

Email sent to the wrong recipient

A wrong recipient address, an open distribution list with CC instead of BCC, or an attachment with extraneous data. This is the most common case in practice.

Lost or stolen devices

Laptops forgotten on trains, work phones stolen, USB sticks gone missing, especially critical without encryption.

Ransomware and hacker attacks

Encrypted systems, leaked customer data, extortion. Here, every hour counts for reporting and communication.

Documents sent to the wrong recipient

Mail to the wrong address, files in old paper, documents in the waiting room. Analogous incidents can also be data protection violations, but are not automatically subject to reporting. Whether a report to the supervisory authority is required also depends here GDPR on the risk assessment pursuant to Art. 33.

Unauthorized access

Disqualified employees retain access, or employee rights are granted too widely.

Misconfiguration and data leak

Open cloud storage, incorrectly set permissions, forms with publicly viewable entries, often unnoticed for months.

The process

The first 72 hours:
What happens now in what order

Hour 0

Detect and contain

Block access, isolate systems, recall faulty shipments. Document the moment of knowledge, and from now on, the deadline counts.

After that

Document and remediate

Any data breach is documented (Article 33(5) GDPR). We evaluate the incident and close the gap so that it does not happen again.

Hour 0–24

Inform affected persons

In cases of expected high risk, those affected must be notified in accordance with Article 34 of the GDPR. We formulate the notification clearly, correctly, and without panic.

Until hour 72

Assess the risk

What data, how many people affected, what consequences? We are examining whether there is a risk to the affected individuals and therefore whether a report must be submitted.

Hour 0

Detect and contain

Blocking access, isolating systems, recalling incorrect shipments. Document the moment of knowledge of the incident – the deadline starts now.

After that

Document and remediate

Any data breach is documented (Article 33(5) GDPR). We evaluate the incident and close the gap so that it does not happen again.

Immediately

Inform affected persons

In cases of a likely high risk, individuals must be notified in accordance with Article 34 of the GDPR. We will communicate the information in a clear, accurate and non-panic-inducing manner.

Until hour 72

Assess the risk

What data, how many people affected, what consequences? We are examining whether there is a risk to the affected individuals – and therefore whether a report must be submitted.

Missed the deadline? Still report it – with justification.

If a required notification is not made within 72 hours, the delay must be explained. The obligation to report immediately remains in effect. Failing to report immediately is the most costly mistake. Therefore, please call us even if the 72-hour deadline has already passed.

Our performance

In an emergency and even before that at your side

Emergency team for data breaches

Immediately

Reactive support with expertise and operational experience in non-standard situations. From the first call to the final documentation.

  • Immediate initial assessment by phone: What happened, what should be done now?
  • Risk assessment under Articles 33 and 34 of the GDPR – mandatory or not?
  • Preparation and submission of the notification to the relevant supervisory authority
  • Forming the notification to the affected parties
  • Communication with regulatory authorities, service providers and management

Prevention: Escalation process and simulation

We develop defined escalation processes for data breaches with you and simulate incidents so that every action is taken in the event of an emergency.

  • Reporting process for data breaches: Who reports to whom, when, with what information?
  • Templates for incident documentation, government notification, and information for affected parties
  • Simulation of realistic incidents, e.g. phishing or incorrect delivery
  • Training of employees: Recognizing data errors and reporting them immediately
  • Review of technical and organizational measures (TOM)
  • On request, combined with our external data protection officer
72 hours

Deadline for reporting to the supervisory authority – upon becoming aware of the data breach (Art. 33 GDPR).

10 million €

or 2 % of the worldwide annual turnover: fine for violations of the reporting and notification obligation (Art. 83(4) GDPR).

1 call

that's enough.

Frequently asked questions about data breaches

Does every data breach have to be reported to the supervisory authority?

No. The notification under Article 33 GDPR is not required if the breach is not likely to result in a risk to the rights and freedoms of the data subjects, for example in the case of a lost, securely encrypted laptop. However, every data breach, even the non-reportable ones, must be documented. Assessing whether there is a risk is the crucial step, and it is here that we can help you.


When does the 72-hour deadline start?

From the moment the responsible person becomes aware of the data breach, that is, as soon as it is reasonably certain that a security incident involves personal data. The deadline also applies on weekends and public holidays. If there is still no information, the notification can be made in stages: first the essential information, and details will be provided later.


When must those affected be informed?

If the data breach is expected to pose a high risk to those affected, for example in the case of compromised access data, health data or bank details, the affected individuals must be informed immediately in accordance with Article 34 GDPR. The notification must explain in clear and simple language what has happened and what the affected individuals can do.

What happens if we don't report it or report it too late?

Violations of the reporting and notification obligation can be punished with fines of up to 10 million euros or 2 % % of the worldwide annual turnover (Art. 83, para. 4). GDPR Furthermore, affected parties may be entitled to compensation for damages and reputational damage. Compensation claims do not automatically arise from a failure to report or a late report; they are subject to GDPR the requirements of Art. 82. A reputational damage also does not necessarily occur.


Our service provider had the breach – who has to report it?

The processor must report the incident to you as the controller immediately (Article 33(2) GDPR). The reporting to the supervisory authority and informing the data subjects remain your responsibility. Therefore, check whether your processor agreements include clear reporting procedures and deadlines for service providers.


What must be included in the report to the supervisory authority?

At least the nature of the breach with categories and approximate number of affected individuals and data sets, the contact details of the data protection officer, the likely consequences, and the measures taken or proposed (Article 33(3) GDPR).

Jan Käding • Senior Consultant

Data breach?
Call us.

Non-binding · 15 minutes · Free

more SERVICES

Data protection services that are available
It fits your company.