During a ransomware tabletop exercise, citizen records are encrypted by an attacker. Leadership asks when GDPR personal-data breach notification clocks start for the controller. Which timing rule is correct?
Select an answer to reveal the explanation.
Short Explanation
The stopwatch starts when you know you have a problem—not when the ransom invoice clears. Controllers work from awareness, then decide who must hear about it based on risk. Pretending encrypted-by-attacker equals anonymous is wishful thinking.
Full Explanation
Articles 33 and 34 GDPR frame controller breach-notification obligations by reference to becoming aware of a personal data breach, with supervisory-authority notice generally without undue delay and, where feasible, within 72 hours of awareness unless the breach is unlikely to result in a risk. Whether individuals must also be informed depends on whether the breach is likely to result in a high risk to rights and freedoms. Ransomware affecting personal data is not presumed anonymous merely because ciphertext is involved.