Basic information about the regulation

Name of regulation
Situation where the notification obligation shall not apply
Citation
The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met:
(a) the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;
(b) the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects referred to in paragraph 1 is no longer likely to materialise;
(c) it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.
Legislative localisation Chapter IV, Section 2, Article 34, Paragraph 3
Regulation's subject matter Communicating the personal data breach with the data subject (Article 34, Section 2, Chapter IV)
Regulation category Right
Regulation subcategory Permission
Actors concerned
Right Controller
Related actors Data subject
Knowww link https://knowww.eu/nodes/5a0595ea4b5b5f00019038ba