← į akto dosjė

GDPR — 33 straipsnis

Straipsnio tekstas

33 straipsnis Pranešimas priežiūros institucijai apie asmens duomenų saugumo pažeidimą 1. Asmens duomenų saugumo pažeidimo atveju duomenų valdytojas nepagrįstai nedelsdamas ir, jei įmanoma, praėjus ne daugiau kaip 72 valandoms nuo tada, kai jis sužino apie asmens duomenų saugumo pažeidimą, apie tai praneša priežiūros institucijai, kuri yra kompetentinga pagal 55 straipsnį, nebent asmens duomenų saugumo pažeidimas neturėtų kelti pavojaus fizinių asmenų teisėms ir laisvėms. Jeigu priežiūros institucijai apie asmens duomenų saugumo pažeidimą nepranešama per 72 valandas, prie pranešimo pridedamos vėlavimo priežastys. 2. Duomenų tvarkytojas, sužinojęs apie asmens duomenų saugumo pažeidimą, nepagrįstai nedelsdamas apie tai praneša duomenų valdytojui. sužinojęs apie asmens duomenų saugumo pažeidimą, nepagrįstai nedelsdamas apie tai praneša duomenų valdytojui. 3. 1 dalyje nurodytame pranešime turi būti bent: a) aprašytas asmens duomenų saugumo pažeidimo pobūdis, įskaitant, jeigu įmanoma, atitinkamų duomenų subjektų kategorijas ir apytikslį skaičių, taip pat atitinkamų asmens duomenų įrašų kategorijas ir apytikslį skaičių; b) nurodyta duomenų apsaugos pareigūno arba kito kontaktinio asmen
visas tekstas
s, galinčio suteikti daugiau informacijos, vardas bei pavardė (pavadinimas) ir kontaktiniai duomenys; c) aprašytos tikėtinos asmens duomenų saugumo pažeidimo pasekmės; d) aprašytos priemonės, kurių ėmėsi arba pasiūlė imtis duomenų valdytojas, kad būtų pašalintas asmens duomenų saugumo pažeidimas, įskaitant, kai tinkama, priemones galimoms neigiamoms jo pasekmėms sumažinti. asmens duomenų saugumo pažeidimas, įskaitant, kai tinkama, priemones galimoms neigiamoms jo pasekmėms sumažinti. 4. Kai ir jeigu informacijos neįmanoma pateikti tuo pačiu metu, informacija toliau nepagrįstai nedelsiant gali būti teikiama etapais. 5. Duomenų valdytojas dokumentuoja visus asmens duomenų saugumo pažeidimus, įskaitant su asmens duomenų saugumo pažeidimu susijusius faktus, jo poveikį ir taisomuosius veiksmus, kurių buvo imtasi. Remdamasi tais dokumentais, priežiūros institucija turi galėti patikrinti, ar laikomasi šio straipsnio.

Kas dėl šio straipsnio rašė konsultacijose

Teikėjai, kurie savo tekste tiesiogiai nurodė būtent šį straipsnio numerį. Tai citata iš jų pačių teksto — ne mūsų vertinimas ir ne priežastinis ryšys.

9
verslo asociacija
4
įmonė
2
kita
2
NVO
2
ACADEMIC_RESEARCH_INSTITTUTION
KasŠalisKą parašė
European Association of Public Banks and funding agencies (EAPB)BEThese should serve as guidelines to avoid overwhelming independent assessments. • Reporting of data breaches (Art. 33 GDPR): To prevent excessive reporting and legal uncertainties, the regulation should consider the existence of a foreseeable high risk to righ
BSA | The Software AllianceBEMember States. Categorization of GDPR infringements by Member States is irregular, i.e. failure to notify a data breach on time (Article 33(1) of the GDPR) or to internally document a breach (Article 33(5) of the 7 62014CJ0582 (europa.eu) Page 5 of 14 Avenue
Centre for European PolicyDEeate a simplified RPA. 2. On the notification of personal data breaches to the competent supervisory authority in accordance with Art. 33 of the GDPR • According to Art.
BDI e.V. (Federation of German Industries)DEdeadlines (with regards to the statutory holidays, Saturdays, and Sundays). The notification period of data breaches according to Art. 33 GDPR is not practical and shall be extended to up to five working days regardless of current initiatives to exclude the we
Council of the Notariats of the EUBEconcept. - In the event of a data breach, it is difficult to define what constitutes a "recording" (Article 33(3)(a)). 2. Exercise of data subject rights a. From the individuals’ perspective: please provide information on the exercise of the data subject right
Confederation of Swedish EnterpriseSEller shall assess whether the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons (Art. 33 GDPR). Only then is such personal data breach non-notifiable to the DPA. As for what information that should be provided i
Gesellschaft für Datenschutz und Datensicherheit (GDD) e.V.DEsanktioniert werden kann. 5. Meldung von Datenpannen Die Meldung einer Verletzung des Schutzes personenbezogener Daten muss nach Art. 33 Abs. 1 S. 1 DS-GVO innerhalb von 72 Stunden, nachdem dem Verantwortlichen die Verletzung bekannt wurde, erfolgen. In der R
ZKI e.V.DEte geprüft werden, ob die Ausnahmetatbestände des Art. 14 Abs. 5 DSGVO auch in Art. 13 Abs. 4 DSGVO verankert werden können.  In Art. 33 DSGVO sollte klargestellt werden, dass nicht jedes Risiko für die Rechte und Freiheiten natürlicher Personen eine Meldepfl
Die Deutsche KreditwirtschaftDEive measures must be based on the risk of data processing. - We would like to see simpler procedures for reporting data breaches (Art. 33, 34 GDPR). The obligation to notify should only apply where there is likely to be a high risk to rights and freedom. s. Th
Délégué à la Protection des Données (ancien et formateur)FR(au titre de l’article 34 du RGPD), pour validation. 6 Proposition : L’article 33.2 du règlement est ainsi modifié : 2. Le sous-traitant notifie au responsable de traitement toute violation de données dans les meilleurs délais après en avoir pris connaissance,
Anonos Inc.USan incident would not qualify as a data breach under GDPR and thus would not have to be notified to a supervisory authority under Article 33. c. Pseudonymization helps to ensure that data breaches are not “likely to result in a high risk to the rights and free
noybATof its Member State for such a corrective power would not be met. Chapter IX – Final provisions Article 33 - Deadlines 1. Regulation 1182/71 of the Council of 3 June 1971 determining the rules applicable to periods, dates and time limits shall apply to this R
Gesamtverband der Deutschen Versicherungswirtschaft e.V.DErecipient There is also uncertainty about how to determine the notification period of usually 72 hours, which is stipulated under Article 33(1) GDPR. In particu- lar, it is unclear whether Article 3(5) of Regulation (EEC, EURATOM) No.
the period for the notification of a personal data breach to the supervisory authority of 72 hours according to Art. 33 subsection 1 sentence 1 GDPR should be longer and should not continue to run on weekends and public holidays. b) Reasoning: There are massiv
U.S. Chamber of CommerceUSe GDPR’s aim of achieving a harmonized data protection framework for the Union. Relatedly, the stringent requirement contained in Article 33 to provide notice to authorities within 72 hours of gaining awareness of a personal data breach poses significant chall
AFME - Association for Financial Markets in EuropeBEnterpretations with regard to Article 9 (on the conditions for processing special categories of personal data) and with regard to Article 33 (on the notification threshold of a personal data breach to the supervisory authorities). This creates additional compl
E.ONDEatement from the relevant authorities on the permissibility of such actions would be welcome. 3. 72-hour breach notification (Art. 33): the GDPR stipulates that in the case of a personal data breach the data controller has 72 hours after having become awar
Insurance EuropeBEthe obligations described in Article 33.5 GDPR. The recommendation “to reason” should be removed from the Guidelines. Guidelines requirements to (i) communicate personal data breaches and (ii) to document breaches: The Guidelines establish requirements that go
innogy SEDEatement from the relevant authorities on the permissibility of such actions would be welcome. 3. 72-hour breach notification (Art. 33): the GDPR stipulates that in the case of a personal data breach the data controller has 72 hours after having become awar
McAfeeBEtent authority, and the EBA guidelines specify that such notification should be done within four hours. By comparison, the GDPR’s Article 33 requires notification within 72 hours of becoming aware of the breach.

Šaltinis: viešų konsultacijų atsiliepimai ir pozicijų dokumentai. n = 20 paminėjimų; skaičiuojama pažodinė nuoroda į straipsnio numerį.

Klausti apie šį straipsnį →