Certified Cloud Security Professional (CCSP)Legal, Risk and ComplianceMedium
An organization is migrating its customer database to a public cloud. The database contains sensitive personal data, and the organization is concerned about the implications of a data breach under GDPR (General Data Protection Regulation). If a data breach occurs at the cloud service provider (CSP) impacting this data, what is the MOST immediate and critical obligation of the organization (as the data controller) under GDPR?
- ATo immediately terminate the contract with the CSP.
- BTo conduct a full forensic investigation on its own internal systems.
- CTo notify the relevant supervisory authority without undue delay, and where feasible, not later than 72 hours after becoming aware of it.
- DTo re-negotiate the Service Level Agreement (SLA) with the CSP for higher penalties.
Show answer & explanationAnswer & explanation
Correct answer: C. To notify the relevant supervisory authority without undue delay, and where feasible, not later than 72 hours after becoming aware of it.
Under GDPR Article 33, a data controller (the organization) is obligated to notify the competent supervisory authority of a data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
Why the other options are wrong
- A. Contract termination is a business decision and not the immediate, legally mandated response to a breach.
- B. A forensic investigation is important, but the immediate and critical obligation is the notification to the supervisory authority.
- D. Contract re-negotiation is a commercial action, not an immediate regulatory obligation following a breach.
GDPR Data Breach Notification
The legal requirement under GDPR for data controllers to notify supervisory authorities and, in some cases, affected individuals, of personal data breaches within specific timelines.
- Notification to supervisory authority within 72 hours (if feasible).
- Notification to data subjects if high risk to their rights/freedoms.
- Applies to data controllers, even if breach occurs at processor.
Memory trick: GDPR breach: 72 hours, notify the authority, no undue delays.