4 ms·
With a bit of searching I found "Guidelines on Personal data breach notification under Regulation 2016/679"[1] which states: > Although the GDPR introduces the
by Rafert 8y ago
With a bit of searching I found "Guidelines on Personal data breach notification under Regulation 2016/679"[1] which states:
> Although the GDPR introduces the obligation to notify a breach, it is not a requirement to do so in all circumstances:
> - Notification to the competent supervisory authority is only triggered where a breach is likely to result in a risk to the rights and freedoms of individuals.
> - Communication of a breach to the individual is only triggered where it is likely to result in a high risk to their rights and freedoms.
After some clarification, it also states:
> Regardless of whether or not a breach needs to be notified to the supervisory authority, the controller must keep documentation of all breaches, as Article 33(5) explains:
> “The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with this Article.”
> This is linked to the accountability principle of the GDPR, contained in Article 5(2). Controllers are therefore encouraged to establish an internal register of breaches, regardless of whether they are required to notify or not.
So the answer seems to be "it depends". But when Google says "We made Google+ with privacy in mind and therefore keep this API’s log data for only two weeks. That means we cannot confirm which users were impacted by this bug." I'd argue it's better to err on the side of caution and report it.
[1]: http://ec.europa.eu/newsroom/document.cfm?doc_id=47741 http://ec.europa.eu/newsroom/document.cfm?doc_id=47741
- tptacek 8y agoAll of those excerpts refer to breaches, not vulnerabilities. Vulnerabilities aren't breaches, either in common parlance or as a term of art. The distinction the GDPR is making here is between intrusions that don't include exfiltration of data (ie, what happens when most teenager hackers break into something for the sport of it) and those that do.