If a data breach is detected, the GDPR always requires that the incident be documented and in certain cases even reported to the supervisory authority. This requires a detailed risk assessment by the data protection officer, who decides on the reporting obligation. The management to whom the incident is submitted for review is responsible for data protection breaches under the GDPR and is therefore ultimately responsible for deciding whether to report the incident.
At the same time, technical and organizational countermeasures must always be introduced to limit the damage in order to prevent such incidents in the future. Ideally, such an incident should never occur due to the technical and organizational measures already installed in the company.


