Data Breaches & Incident Response

Confused about GDPR jargon? No problem! Our glossary breaks down all the key terms and definitions you need to understand the language of data privacy and compliance. This glossary will grow as we continue to add new terms and explanations, making it an essential reference for everyone.

Administrative Fines

Financial penalties regulators can issue for GDPR violations, up to 20 million euro or 4% of global annual turnover, whichever is higher (Article 83).

Data Breach

A security incident leading to unauthorized access, alteration, or loss (disclosure, or destruction) of personal data (Article 4(12)).

Data Breach Notification (72-Hour Rule)

The requirement to report certain personal data breaches to the supervisory authority within 72 hours of becoming aware of them (Articles 33–34).

Encryption

Converting data into a secure format to prevent unauthorized access during transmission or storage (Recital 83).

Incident Response Plan

A structured approach for managing and mitigating the impact of data breaches (not explicitly defined in GDPR but essential for compliance under Articles 33–34).