An incident response plan lists technical containment steps but never assigns who assesses high risk to data subjects for notification decisions. Which organisational gap does this reveal?
Select an answer to reveal the explanation.
Short Explanation
Someone has to own the 'how bad is this for people?' call—not just the 'reboot the server' checklist. Breach notification turns on risk to humans; if nobody is assigned that judgment, the plan is half-built. Put a name next to the decision.
Full Explanation
GDPR breach notification hinges on assessing likelihood and severity of risk to natural persons. Effective organisational measures include defined roles for that assessment and for escalating notification decisions within statutory timeframes. An IR plan that covers only technical containment without decision ownership is incomplete for personal-data incidents.