ŷޱͶע

Print

Data Breach

The Regulation 1725/2018 introduces a duty on all EU Institutions and bodies to report certain types of personal data breach to the ŷޱͶע. They must do this within 72 hours of becoming aware of the breach, where feasible.
If the breach is likely to result in a high risk of adversely affecting individuals’ rights and freedoms, they must also inform those individuals without undue delay. All EU institutions and bodies should ensure that they have the procedures that enable them  to detect a  breach, investigate, take the necessary corrective measures and report. They must keep a record of any personal data breaches, regardless of whether they are required to notify the ŷޱͶע.

 

Filters

5
Jun
2025

PATRICIA II - Personal dATa bReach awareness in Cybersecurity Incident Handling

The ŷޱͶע organises the second edition of PATRICIA - Personal dATa bReach awareness in Cybersecurity Incident Handling, a table-top exercise focusing on personal data breach management. The cyber exercise takes place on 5 June 2025 from 08:45 to 16:00 at the ŷޱͶע premises and will bring together key stakeholders from selected EUIs to enhance incident response and collaboration.

Topics
12
Dec
2024

PATRICIA Exercise 2024 - Personal dATa bReach awareness In Cybersecurity Incident hAndling

On 3 October 2024, the European Union Agency for Cybersecurity (ENISA) and the European Data Protection Supervisor (ŷޱͶע) jointly organised a table-top exercise titled “Personal Data Breach Awareness In Cybersecurity Incident Handling” (PATRICIA). The event, hosted at the ŷޱͶע premises in Brussels, aimed to raise awareness among staff from European Union Institutions, Bodies, and Agencies (EUIs) on managing personal data breaches.

Available languages: English
3
Oct
2024

PATRICIA - Personal dATa bReach awareness in Cybersecurity Incident Handling

ŷޱͶע and ENISA are co-organising the cyber exercise PATRICIA - Personal dATa bReach awareness in Cybersecurity Incident Handling, a table-top exercise focusing on personal data breach management. This initiative is organised in the framework of the ŷޱͶע 20th-anniversary activities and European Cybersecurity Month Campaign on 3 October 2024 from 08:45 to 16:00 in the ŷޱͶע premises.

24
May
2024

Vacancy Notice ŷޱͶע 02/2024

Data Breach Notification and Investigation Officer- CA (1 year renewable) FGIV - Technology and Privacy Unit - Deadline for submitting the applications via the is June 7th, 2024, (Brussels time GMT+1) at 12:00 (midday).

Vacancy Notice
Available languages: English
Data Protection Notice
Available languages: English