After a ransomware incident, a city restores systems from backups and leadership says there is no personal-data breach because availability was recovered. What should privacy counsel emphasize?
Select an answer to reveal the explanation.
Short Explanation
Getting the lights back on is not the same as proving nobody peeked. If attackers had a window into personal data, that confidentiality hit still counts as a breach idea—even after a clean restore. Availability recovery and breach assessment are different questions.
Full Explanation
GDPR defines a personal-data breach as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Restoring availability addresses one CIA facet; unauthorised access or disclosure during the incident can still constitute a confidentiality breach requiring risk assessment and possible notification.