Home Privacy Law GDPR Article 34 GDPR (Communication of A Personal Data Breach To The Data...

Article 34 GDPR (Communication of A Personal Data Breach To The Data Subject)

Article 34 of GDPR: Data breach notification to data subjects

Article 32 of GDPR imposes further data breach notification obligations on the data controller, this time directly notifying the data subjects concerned with the data breach in the event there may be a high risk of adverse consequence on them.

Data breach notification obligation to data subjects (Article 34(1) GDPR)

When a company suffers a data breach and where there may be a high level of risk of adverse consequence on the data subjects, in addition to notifying the supervisory authorities, companies must report the same directly to the data subjects concerned.

The controller must notify the data subjects as soon as possible.

Content of data breach notification to data subjects (Article 34(2) GDPR)

An organization must inform the individuals impacted by the data breach in simple and clear terms.

The notification should contain:

  1. The nature of the data breach 
  2. Name and contact details of the data controller’s data protection officer or point of contact 
  3. The possible consequences of the data breach
  4. What measures have been taken to address the data breach and how is the adverse consequence on data subjects being handled 

Instances when a data breach notification to data subjects is not required (Article 34(3) GDPR)

In some cases, GDPR exempts companies from notifying data subjects of a personal data breach.

Here are the instances where data notification to data subjects are not required:

  1. When the data was encrypted and the data could not be used even in the context of a data breach (Article 34(3)(a) GDPR)
  2. The company has taken necessary measures so as to prevent any important risk of adverse consequence to the individuals concerned (Article 34(3)(b) GDPR)
  3. The effort to notify to directly notify the data subjects would result in a disproportionate effort although the company should consider making a public communication or take other measures to notify the data subjects (Article 34(3)(c) GDPR)

Supervisory authority imposing notification to data subjects (Article 34(4) GDPR)

Should the supervisory authorities consider that a data breach could result in an important risk to data subjects, it may require the data controller to notify the data subjects in accordance with the terms of Article 34 of GDPR.

The supervisory authority also has the power to determine that a data controller is exempt from notifying the data subjects based on Article 34(3).

Recitals applicable to Article 34 of GDPR

Relevant Recitals: 86, 87, 88

GDPR Regulation article-by-article overview

Read our comprehensive overview of the GDPR Regulation, article by article, where we summarize each of the 99 articles contained in GDPR to give you a complete understanding of its content.

Cited Legislation in Article 34 or relevant recitals

None

GDPR Text: Article 34 of GDPR and Relevant Recitals

GDPR Text Source: EUR-Lex

Official GDPR Text: General Data Protection Regulation 

Official GDPR Title: REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), corrected by Corrigendum, OJL 127, 23.5.2018, p. 2 ((EU) 2016/679)

Editorial Staff
Hello Nation! I'm a lawyer by trade and an entrepreneur by spirit. I specialize in law, business, marketing, and technology (and love it!). I'm an expert SEO and content marketer where I deeply enjoy writing content in highly competitive fields. On this blog, I share my experiences, knowledge, and provide you with golden nuggets of useful information. Enjoy!

Most Popular

What Is A Special Purpose Entity (All You Need To Know)

What Is A Special Purpose Entity (Explained: All You Need To Know)

What Is Corporate Raiding (Explained: All You Need To Know)

What Is Corporate Raiding (Explained: All You Need To Know)

What Are Golden Shares (Explained: All You Need To Know)

What Are Golden Shares (Explained: All You Need To Know)

What Is A Targeted Repurchase (Explained: All You Need To Know)

What Is A Targeted Repurchase (Explained: All You Need To Know)

What Is A Friendly Takeover (Explained: All You Need To Know)

What Is A Friendly Takeover (Explained: All You Need To Know)

Editor's Picks

How To Start A Business In Nebraska [Step-By-Step Ultimate Guide]

How To Start A Business In Nebraska [Step-By-Step Ultimate Guide]

Net Operating Working Capital (What It Is And How To Calculate It)

Net Operating Working Capital (What It Is And How To Calculate It)

How Much Money Do You Need To Start A Business (Best Overview)

How Much Money Do You Need To Start A Business (Best Overview)

Inc Versus Corp (Overview: Difference Between INC And CORP)

Inc Versus Corp (Overview: Difference Between INC And CORP)

Address Line 1 (What Does It Mean And How To Fill It Out)

Address Line 1 (What Does It Mean And How To Fill It Out)