A DPO relies on EDPB breach guidelines when deciding whether individuals must be informed after a personal-data breach. Which threshold correctly drives data-subject notification?
Select an answer to reveal the explanation.
Short Explanation
Tell people when the mess is likely a high risk to their rights—not for every blip on a log. EDPB thinking tracks that high-risk threshold. Board briefings are fine; they do not replace individual notice when the risk is high.
Full Explanation
Article 34 GDPR requires communication of a personal data breach to the data subject when the breach is likely to result in a high risk to the rights and freedoms of natural persons, subject to limited exceptions such as effective technical protection that renders the data unintelligible. EDPB breach guidelines help assess that risk threshold in practice. Routine anomalies without personal-data impact, or internal board reporting alone, do not satisfy or redefine the legal trigger.