Data Breach Notification
What is Data Breach Notification?
The legal obligation to inform affected individuals and regulatory authorities when personal data is compromised in a security incident within specified timeframes.
Terms that appear alongside data breach notification
Each of these is named in at least one of the same controls as data breach notification. The number is how many controls name both.
- data breach 60 shared controls
- breach notification 60 shared controls
- incident response 19 shared controls
- encryption 17 shared controls
- gdpr 17 shared controls
- cybersecurity 13 shared controls
- audit 13 shared controls
- data protection 12 shared controls
Frameworks that govern data breach notification
What the standards actually require on data breach notification
Requirements naming data breach notification across 6 standards, quoted from the control text.
Sections 16-17 of DPDP Act 2023 address cross-border transfer + breach notification. Section 16 Processing of Personal Data Outside India: Central Government may by notification restrict the transfer of personal data by a Data Fiduciary for processing to such...
DPDP-CrossBorder-Transfer-Breach-Notification-Sec16-Sec17-DPBI-72Hour-IT-Act-Coord · DPDP Act Sections 16-17 + Cross-Border Personal Data Transfer + Negative List Approach + Personal Data Breach Notification to DPBI 72 Hours + Cooperation with Adjudication + Coord with CERT-In + IT Act 43A Repeal →AAIP Resolution 47/2018 recommends notification of personal data breaches to AAIP and affected data subjects when the breach poses risks to rights. Modernization Bill would make notification mandatory with defined timelines.
AR-25326-AAIP-BREACH · Personal Data Breach Notification →Notify the System Operator and the OAIC (and affected individuals where required) of unauthorised access to, or loss of, information in the My Health Record system, as soon as practicable.
MYHR-ENF-1 · Mandatory data breach notification →Data breach notification requirements. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Security.
BH-PDPL-16 · Data breach notification requirements →s.16: where a personal data breach occurs, the data controller must, without undue delay and in any event within 5 days of becoming aware, notify the Ombudsman and any affected data subject.
CAYDPA-s16 · Personal Data Breach Notification (s.16) →Article 4(1) requires the provider of a publicly available electronic communications service to take appropriate technical and organisational measures to safeguard the security of its services, in conjunction with the network provider where necessary, with the...
ePD-Art.4 · Security of services and personal-data-breach notification (Article 4) →Questions people ask about data breach notification
What is Data Breach Notification?
Why is Data Breach Notification important for compliance?
Which compliance frameworks address Data Breach Notification?
Where can I learn more about Data Breach Notification?
See how Data Breach Notification applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.