Privacy incident

If a data breach is detected, the GDPR always requires that the incident be documented and in certain cases even reported to the supervisory authority. This requires a detailed risk assessment by the data protection officer, who decides on the reporting obligation. The management to whom the incident is submitted for review is responsible for data protection breaches under the GDPR and is therefore ultimately responsible for deciding whether to report the incident.

At the same time, technical and organizational countermeasures must always be introduced to limit the damage in order to prevent such incidents in the future. Ideally, such an incident should never occur due to the technical and organizational measures already installed in the company.

CRM standard schema

Note: Your company should already have a documented process in place with your data protection officer for dealing with notifiable data protection incidents.

For capturing data protection inci­dents, a corresponding type of data protection case is available. If the incident is reported via one of the usual channels (phone, email, etc.), please create the corresponding activity. In the case of an email, directly use the Create case/Privacy incident function in the email connector to create the data protection case of the Privacy incident type.

The underlying process in the CRM standard guides you through the most important steps and thus documents the process of the entire incident.

Incoming privacy incident

For all other channels, you should create the data protection case directly at the person concerned using the GDPR Pri­vacy incident function. If there are several data subjects involved, all of them must be included as contacts in the case.

Creating a privacy incident at a person

Include all information relating to the incident in the case, also as descriptive text. Distinguish between the data subjects concerned and the person forwarding the information (Forwarded by...).