A processor detects unauthorised access to personal data it processes for a controller and plans to mention it only at the next monthly quarterly business review. What timing obligation applies?
Select an answer to reveal the explanation.
Short Explanation
Waiting for the monthly slide deck is not ‘without undue delay.’ When a processor spots a breach, it rings the controller promptly—not on the next tea-and-metrics calendar invite. Remediation plans do not buy a polite delay.
Full Explanation
Article 33(2) GDPR requires the processor to notify the controller without undue delay after becoming aware of a personal data breach. Periodic commercial meetings such as a monthly QBR do not redefine that timing standard. Prompt notice enables the controller to meet its own supervisory-authority and data-subject notification duties.