Art. 55 - (vetoed)Art. 56 - (vetoed)Art. 57 - (vetoed)Art. 58 - (vetoed)Art. 59 - (vetoed)
The controller must communicate to the national authority and to the data subject the occurrence of a security incident that may create risk or relevant damage to the data subjects.
IV – the risks related to the incident;
§2 The national authority shall verify the seriousness of the incident and may, if necessary to safeguard the data subjects’ rights, order the controller to adopt measures, such as:
I – broad disclosure of the event in communications media; and II – measures to reverse or mitigate the effects of the incident.
§3 When judging the severity of the incident, eventual demonstration that adequate technical measures were adopted to render the affected personal data unintelligible will be analysed, within the scope and the technical limits of the services, to third parties who were not authorised to access them.
g) have plans for response to incidents and solution; and