A board asks the privacy team for ‘EDPB-aligned’ scoring when deciding whether a breach requires supervisory-authority or individual notification. How should EDPB materials factor into that assessment?
Select an answer to reveal the explanation.
Short Explanation
Use the EDPB’s breach playbooks as a compass next to the GDPR text—not as scrap paper and not as a full rewrite of the Articles. Risk scoring for who to notify gets clearer with that guidance. Internal spreadsheets still need that legal north star.
Full Explanation
Articles 33 and 34 establish risk-based thresholds for notifying supervisory authorities and data subjects. EDPB guidelines and opinions provide authoritative interpretive assistance on assessing those risks in concrete breach scenarios. They complement rather than replace the Regulation, and ignoring them without justification weakens a defensible, aligned assessment process.