A school discovers that an unencrypted USB stick with pupil personal data was lost three weeks earlier; staff only now become aware of the loss. How should breach-handling duties be timed?
Select an answer to reveal the explanation.
Short Explanation
Late discovery does not mean ‘too late to care.’ The GDPR clock for controllers runs from awareness—when you find out—not from the day the stick vanished into a sofa. Delayed notice of the loss still triggers handling steps.
Full Explanation
Controller obligations under Articles 33 and 34 are triggered by becoming aware of a personal data breach. Delayed discovery does not erase those duties; it sets the awareness moment from which without-undue-delay notification timelines are measured. Removable media containing personal data remain within GDPR security and breach frameworks.