CompTIA CySA+ (CS0-003)Reporting and CommunicationHard

A security analyst is preparing a compliance report for GDPR. The organization experienced a data breach involving personal identifiable information (PII) of EU citizens. The report needs to detail the breach and the organization's response. Which of the following is a MANDATORY reporting requirement under GDPR that MUST be included in the report?

  1. AA comprehensive list of all affected systems and their operating systems.
  2. BEvidence of internal disciplinary actions taken against employees.
  3. CThe contact details of the Data Protection Officer (DPO).
  4. DA detailed financial impact assessment of the breach.
Show answer & explanation

Correct answer: C. The contact details of the Data Protection Officer (DPO).

GDPR Article 33 mandates that a data breach notification to the supervisory authority must, among other things, include the name and contact details of the Data Protection Officer (DPO) or other contact point where more information can be obtained.

Why the other options are wrong

  • A. While useful for internal investigation and sometimes requested, a comprehensive list of *all* affected systems and OS is not explicitly a mandatory *initial* reporting element under GDPR Article 33 or 34, unlike the DPO's contact details.
  • B. Internal disciplinary actions are an internal HR matter and not a mandatory component of the breach notification to supervisory authorities or affected data subjects under GDPR.
  • D. A financial impact assessment is important for internal decision-making and might be part of an overall incident report, but it is not a mandatory element of the immediate breach notification required by GDPR Article 33 or 34.

GDPR Breach Notification

A legally mandated process under the General Data Protection Regulation (GDPR) for organizations to report personal data breaches to supervisory authorities and, in some cases, to affected data subjects.

  • Must be reported to the supervisory authority within 72 hours of becoming aware.
  • Must include nature of the breach, categories of data, approximate number of data subjects, likely consequences, and measures taken/proposed.
  • Crucially, includes contact details of the DPO or other contact point.

Memory trick: GDPR breach reports need 'Who, What, How Bad, and Who to Ask'.

More Reporting and Communication questions