An international e-commerce organization headquartered in the United States discovers an unauthorized database export containing names, email addresses, and behavioral tracking logs of customers residing in the European Union. Which regulatory framework explicitly mandates that the data controller notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of the personal data breach?
- General Data Protection Regulation (GDPR)Answer
- BPayment Card Industry Data Security Standard (PCI-DSS)
- CHealth Insurance Portability and Accountability Act (HIPAA)
- DSarbanes-Oxley Act (SOX)
Answer
The General Data Protection Regulation (GDPR) mandates notification to the supervisory authority within 72 hours of becoming aware of a personal data breach involving EU residents.
The General Data Protection Regulation (GDPR) applies extraterritorially to any entity processing the personal data of data subjects located within the European Union. Under GDPR Article 33, when a breach occurs that poses a risk to individuals' rights and freedoms, the organization acting as the data controller must report the breach to its supervisory authority within 72 hours of discovery.
Step-by-Step Solution
Key Concept
GDPR Data Breach Notification Obligations
Estimated Time:1m 15s