Ride the Lightning

Cybersecurity and Future of Law Practice Blog
by Sharon D. Nelson Esq., President of Sensei Enterprises, Inc.

BakerHostetler EU GDPR Data Breach Notification Resource Map

March 7, 2019

While overall compliance with the GDPR is challenging, one aspect of the EU data protection and privacy law that is especially daunting for companies is Article 33, which requires notification to supervisory authorities within 72 hours of a data breach that may result in a risk to the rights and freedoms of individuals.

This requires companies to devote resources not only to investigating and remediating a breach, but also to drafting a report to the appropriate agency where the breach could have an impact. For breaches that are not confined to one country (or one country’s residents), companies will be required to file a separate report for each respective supervisory agency – with different language, reporting format and procedural requirements for each country. And for companies not established in the European Economic Area (EEA) or those that have not identified a lead supervisory authority, notification will need to be made to every country in the EEA with affected individuals.

To help companies with the notification process, the Privacy and Data Protection team at BakerHostetler has created an interactive EU GDPR Data Breach Notification Resource Map.

Using the map, a company can proactively identify the EEA countries where they may be required to report, familiarize themselves with the reporting process and translate any required forms or portals. Clicking on a country in the map generates a pop-up that provides contact information for the supervisory authority in that country and a link to its website, information on and links to the country’s breach notification form or online breach notification portal, and information (where applicable) on how the notification is submitted to the supervisory authority in that country.

BakerHostetler has a similar map with the specific state data breach notification laws in the US. Both maps are very valuable resources.

E-mail:    Phone: 703-359-0700
Digital Forensics/Information Security/Information Technology
https://www.senseient.com
https://twitter.com/sharonnelsonesq
https://www.linkedin.com/in/sharondnelson
https://amazon.com/author/sharonnelson