Certified Cloud Security Professional (CCSP)Legal, Risk and ComplianceMedium

An organization is migrating its customer database to a public cloud. The database contains sensitive personal data, and the organization is concerned about the implications of a data breach under GDPR (General Data Protection Regulation). If a data breach occurs at the cloud service provider (CSP) impacting this data, what is the MOST immediate and critical obligation of the organization (as the data controller) under GDPR?

  1. ATo immediately terminate the contract with the CSP.
  2. BTo conduct a full forensic investigation on its own internal systems.
  3. CTo notify the relevant supervisory authority without undue delay, and where feasible, not later than 72 hours after becoming aware of it.
  4. DTo re-negotiate the Service Level Agreement (SLA) with the CSP for higher penalties.
Show answer & explanation

Correct answer: C. To notify the relevant supervisory authority without undue delay, and where feasible, not later than 72 hours after becoming aware of it.

Under GDPR Article 33, a data controller (the organization) is obligated to notify the competent supervisory authority of a data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.

Why the other options are wrong

  • A. Contract termination is a business decision and not the immediate, legally mandated response to a breach.
  • B. A forensic investigation is important, but the immediate and critical obligation is the notification to the supervisory authority.
  • D. Contract re-negotiation is a commercial action, not an immediate regulatory obligation following a breach.

GDPR Data Breach Notification

The legal requirement under GDPR for data controllers to notify supervisory authorities and, in some cases, affected individuals, of personal data breaches within specific timelines.

  • Notification to supervisory authority within 72 hours (if feasible).
  • Notification to data subjects if high risk to their rights/freedoms.
  • Applies to data controllers, even if breach occurs at processor.

Memory trick: GDPR breach: 72 hours, notify the authority, no undue delays.

More Legal, Risk and Compliance questions