In the event of a personal data security breach, the controller is obliged to notify the Commission for Personal Data Protection (КЗЛД).
A "personal data breach" is an event leading to:
- Unlawful destruction or damage of the data, rendering it unusable or incomplete;
- Loss of control over or access to the data. Example: a device containing a database is lost or encrypted by malicious software;
- Alteration of the data;
- Unauthorised access to the data, leading to its disclosure to persons who have no right of access.
Types of security breach
- Breach of confidentiality – unauthorised disclosure of or access to the data.
- Breach of integrity – unauthorised alteration of the data.
- Breach of availability – loss of access to or destruction of the data. Example: accidental deletion of data or encryption without the possibility of recovery.
A single breach may simultaneously affect the confidentiality, integrity and availability of the data.
Even the temporary loss of availability of data is regarded as a security breach, but it does not always require notification of the КЗЛД. If, for example, the controller is subject to malicious software that temporarily encrypts the data and it can be restored from a backup copy, notification may not be required.
When is notification of the КЗЛД mandatory?
If the breach is likely to result in physical, material or non-material damage to the data subjects, the controller must notify the КЗЛД. Such damage may include:
- Loss of control over personal data;
- Restriction of the rights of the data subjects;
- Discrimination, identity theft, financial loss;
- Breach of professional secrecy.
The controller is obliged to notify the КЗЛД within 72 hours of becoming aware of the breach. If this deadline is not met, the reasons for the delay must be stated.
Establishing "awareness" of the breach: The controller is deemed to have "become aware" of the breach when it has a reasonable degree of certainty that an incident affecting personal data has occurred.
The role of the data processor
A processor that establishes a breach must notify the controller without undue delay, and no later than 72 hours. The processor does not assess whether there is a risk to the data subjects – that assessment is the responsibility of the controller. It is advisable for the contract between the controller and the processor to contain provisions for prompt notification, so that the 72-hour deadline for notifying the КЗЛД is met.
Content of the notification to the КЗЛД
The notification must include:
- A description of the breach and, where possible, the categories and number of affected persons and records;
- The contact details of the data protection officer (DPO);
- A description of the likely consequences – e.g. identity theft, financial loss;
- A description of the measures taken to limit the consequences of the breach.
If the processor is the source of the breach, the controller may also include the processor's details in the notification. The controller is entitled to supplement the information at a later stage if it does not have all the data at the time of notification.
Keeping a register of breaches
The controller must maintain an internal register of breaches. It includes information on both notified and non-notified cases. The register records:
- A description of the breach;
- The causes of the breach;
- The data affected;
- The consequences of the breach;
- The actions taken and the reasons for not notifying the КЗЛД where such notification was unnecessary.
The register of breaches may form part of the record of processing activities (Article 30 of the GDPR), provided that the information on breaches can be easily extracted upon request by the КЗЛД.
The role of the data protection officer (DPO)
If the controller has a DPO, it must inform the DPO of the breach immediately. The DPO assists in ensuring compliance with the requirements and in coordinating the notification to the КЗЛД, and also participates in any investigation by the КЗЛД and in the entire incident management process.
Sanctions for failure to comply with the notification obligation
In the event of failure to comply with the notification obligation, the КЗЛД may impose a corrective measure or a fine of up to EUR 10,000,000 or up to 2% of the total annual worldwide turnover of the undertaking for the preceding year, whichever is the greater.
A statement establishing the infringement is drawn up by a member of the КЗЛД or by authorised persons. The controller has the right to submit written objections within 3 days. Penal decrees are issued by the chairperson of the КЗЛД and may be appealed before the district court within 7 days of their service. The appeal is filed through the КЗЛД.
Should you need assistance in preparing documents or a consultation in the field of personal data protection, please contact us on tel.: 02 851 72 59 or by e-mail:

