Question

Difficulty: MediumRegulatory Compliance and Legal Requirements Management

A university based in the United States operates an online portal for international exchange programs, collecting personal identification details and financial records from European Union residents. Following a confirmed security incident involving unauthorized access to the application database, the compliance officer is determining legal breach notification duties. Which of the following obligations MUST the institution fulfill to satisfy regulatory compliance mandates? (Select TWO.)

  1. Notify the relevant supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach if it poses a risk to individuals.Answer
  2. Communicate the personal data breach to affected data subjects without undue delay when the incident is likely to result in a high risk to their rights and freedoms.Answer
  3. C
    Enforce an immediate technical lockout of all database service accounts for a mandatory 30-day statutory forensic cooling period.
  4. D
    Reclassify all stored student financial records as Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA).

Answer

The organization must notify the competent supervisory authority within 72 hours of awareness if a risk exists, and communicate the breach to affected individuals without undue delay if a high risk to rights and freedoms is present.
Under international privacy frameworks like GDPR, organizations processing personal data of EU residents must fulfill dual notification obligations upon experiencing a qualifying breach. Data controllers must notify the supervisory authority within 72 hours if a risk to individuals exists, and directly inform affected data subjects without undue delay if the incident poses a high risk to their rights and freedoms.

Step-by-Step Solution

1
Identify the territorial and material scope of applicable regulations based on data subject residency.
The university processes personal data of EU residents, bringing breach notifications under GDPR jurisdiction.
GDPR applies extra-territorially to non-EU entities offering services to or monitoring data subjects in the EU.
2
Determine the legal timeframes and thresholds for supervisory authority notification.
Supervisory notification is required within 72 hours of awareness if the breach poses a risk to individuals.
Article 33 of GDPR establishes the 72-hour reporting rule for data controllers.
3
Determine the conditions required for notifying impacted data subjects.
Individual notification is required without undue delay when a high risk to rights and freedoms is present.
Article 34 of GDPR establishes communication duties directly to individuals when breach severity passes the high-risk threshold.

Key Concept

GDPR Breach Notification Rules and Timelines
Estimated Time:1m 30s
Rate this question