1. In the event of a personal data breach, Europol shall without undue delay notify the EDPS, as well as the competent authorities of the Member States concerned, of that breach, in accordance with the conditions laid down in Article 7(5),as well as the provider of the data concerned.
2. The notification referred to in paragraph 1 shall, as a minimum:
(a)
describe the nature of the personal data breach including, where possible and appropriate, the categories and number of data subjects concerned and the categories and number of data records concerned;
(b)
describe the likely consequences of the personal data breach;
(c)
describe the measures proposed or taken by Europol to address the personal data breach; and
(d)
where appropriate, recommend measures to mitigate the possible adverse effects of the personal data breach.
3. Europol shall document any personal data breaches, including the facts surrounding the breach, its effects and the remedial action taken, thereby enabling the EDPS to verify compliance with this Article.
Home› Justice & Home Affairs› Europol Regulation
Chapter VI · DATA PROTECTION SAFEGUARDS › Article 34
Notification of a personal data breach to the authorities concerned
←→ also move between articles