When the GDPR took effect in 2018, it required notification within 72 hours to supervisory authorities in the EU of a data breach likely to result in a risk to the rights and freedoms of individuals, and subsequent notification to the individuals themselves if the breach could give rise to such a “high” risk. Unlike laws in the United States which specifically prescribe data elements that, if exposed, could meet this standard (e.g., social security numbers, driver’s license numbers, financial account information, etc.), the GDPR’s broad definition of personal data left many data controllers and legal experts alike struggling to identify the circumstances under which notification would be required. Given the stiff penalties for non-compliance with the GDPR, supervisory authorities were flooded with reports of data security incidents, notwithstanding that many such events posed no real risk to data subjects.

At long last, the European Data Protection Board (EDPB) has issued practical guidance on specific types of common security incidents to provide clarity around what constitutes a reportable event. The guidance reminds controllers that a data breach includes not only a compromise to the confidentiality of information – the standard by which U.S. laws judge incidents – but also the availability and integrity of personal data. Given this broader scope, it is possible to have a security breach that requires reporting in the EU but not in the U.S., for example, if data is encrypted by ransomware malware, but there is no indication it was viewed or exfiltrated.

The EDPB addresses the following common scenarios:

  • Ransomware
  • Malware
  • Credential stuff
  • Inadvertent disclosure
  • Lost or stolen laptop
  • Lost paper files
  • Email Compromise
  • Preventative security measures

Click here to view the EDPB Guidelines.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Jena M. Valdetero Jena M. Valdetero

Jena M. Valdetero serves as Co-Chair of the firm’s U.S. Data Privacy and Cybersecurity Practice, and is a trusted advisor to clients facing complex and high-stakes data privacy and security challenges. With a track record of leading thousands of data breach investigations for…

Jena M. Valdetero serves as Co-Chair of the firm’s U.S. Data Privacy and Cybersecurity Practice, and is a trusted advisor to clients facing complex and high-stakes data privacy and security challenges. With a track record of leading thousands of data breach investigations for more than 20 years, Jena combines her broad litigation experience with a deep understanding of the evolving privacy landscape to protect her clients’ interests. She is highly skilled in defending companies in privacy and data breach litigation, particularly class actions, and is proactive in helping clients prepare for incidents by designing and facilitating customized tabletop exercises.

Jena offers practical, results-driven counsel on data privacy and security compliance programs and guides clients through privacy and cyber risk considerations in mergers, acquisitions, venture capital, and securities transactions. Her experience spans a wide range of privacy laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Gramm Leach Bliley Act (GLBA), and the Health Insurance Portability and Accountability Act (HIPAA). Certified as a privacy professional through the International Association of Privacy Professionals (CIPP/US),  Jena provides clients with actionable insights on both current and emerging privacy regulations. She previously served as KnowledgeNet Co-Chair for the International Association of Privacy Professionals, further reflecting her leadership in the field. Jena is a founding board member of the Chicago Compassion Project, a nonprofit supporting low-income families in Chicago.

Jena has been recognized by Chambers USA as a leading privacy and data security lawyer, with clients praising her “very deep knowledge of subject matter” and calling her “extremely responsive and business-minded.” She is trusted for her “great strategic advice” and practical approach to complex data privacy issues, with one client saying, “I’d unequivocally recommend her to anybody with any kind of privacy or data breach concerns.”