A controller confirms on a Monday morning that an attacker copied a file containing the names and bank details of several thousand customers, and assesses the incident as likely to result in a high risk to those individuals. The security team is still establishing the full scope of the records affected. Which statements correctly describe the controller's breach-notification obligations under the GDPR and EDPB guidelines? (Select TWO.)
- ABecause the full scope is not yet known, the controller may delay all notification until its investigation is complete and the exact number of affected records is confirmed.
- BThe controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Correct
- CNotifying the supervisory authority within 72 hours automatically discharges any duty owed to the affected individuals, who need not be separately contacted.
- DIf notification to the supervisory authority is made after 72 hours, the controller may submit it without any explanation, since the deadline is merely advisory.
- EBecause the breach is likely to result in a high risk to individuals, the controller must also communicate the breach to the affected data subjects without undue delay. Correct
Why A is wrong: This is tempting because complete information seems preferable, but it is wrong: Article 33(4) allows information to be provided in phases, so the controller must still notify on time and supply further detail later rather than wait for a finished investigation.
Why B is correct: Correct: Article 33(1) requires notification to the supervisory authority without undue delay and, where feasible, within 72 hours of the controller becoming aware, which is the headline timeline for the regulator notification.
Why C is wrong: This conflates two distinct duties: Article 33 notification to the authority and Article 34 communication to individuals are separate obligations with different thresholds, so notifying the regulator does not remove the high-risk duty to inform data subjects.
Why D is wrong: This is wrong because Article 33(1) requires that a notification not made within 72 hours be accompanied by reasons for the delay, so a late notification must be justified rather than treated as optional timing.
Why E is correct: Correct: Article 34(1) requires communication to affected individuals without undue delay where a breach is likely to result in a high risk, and the high-risk assessment here triggers that separate duty alongside the regulator notification.