CompTIA CySA+ (CS0-003)Reporting and CommunicationHard
A security analyst is preparing a compliance report for the General Data Protection Regulation (GDPR). The organization experienced a data breach involving personal data of EU citizens. The analyst needs to ensure the report includes all mandatory information for the supervisory authority. Which of the following pieces of information is NOT explicitly required by GDPR Article 33 for breach notification?
- AA detailed financial impact assessment of the breach on the organization.
- BThe nature of the personal data breach including categories and approximate number of data subjects and records concerned.
- CThe measures taken or proposed to be taken by the controller to address the personal data breach.
- DThe likely consequences of the personal data breach.
Show answer & explanationAnswer & explanation
Correct answer: A. A detailed financial impact assessment of the breach on the organization.
GDPR Article 33 (Notification of a personal data breach to the supervisory authority) mandates specific information, including the nature of the breach, likely consequences, and measures taken. While financial impact is important for internal assessment, it is not an explicit requirement for the notification to the supervisory authority under Article 33.
Why the other options are wrong
- B. This is explicitly required by GDPR Article 33(3)(b).
- C. This is explicitly required by GDPR Article 33(3)(d).
- D. This is explicitly required by GDPR Article 33(3)(c).
GDPR Article 33 Notification
GDPR Article 33 outlines the mandatory information required when notifying a supervisory authority of a personal data breach, focusing on the breach's nature, impact, and remediation.
- Mandatory information for supervisory authority notification.
- Must be provided without undue delay, within 72 hours.
- Focuses on data subjects, consequences, and mitigation measures.
Memory trick: GDPR 33: Tell the 'What, Who, Why, How-to-Fix' but not the 'Cost'.