General Data Protection Regulation: Difference between revisions

Content deleted Content added
Steeler2 (talk | contribs)
No edit summary
Steeler2 (talk | contribs)
No edit summary
Line 23:
The data controller has to notify the DPA without undue delay and, where feasible, not later than 24 hours after having become aware of the data breach (Article 31). Individuals have to be notified if adverse impact is determined (Article 32).
=== Fines ===
The following fines ''shall''can be imposed
* Up to €250K or up to 0.5% of the annual global sales for intentionally or negligently not responding to requests by the data subject or the DPA,
* Up to €500K or up to 1% of annual global sales for intentionally or negligently not complying with GDPR