A ransomware attack, a client list sent to the wrong recipient or a database leak can put an organisation on the clock within hours. Under Article 33 GDPR, a personal data breach must be notified to Poland’s data protection authority, the President of the Personal Data Protection Office (UODO), without undue delay and, where feasible, within 72 hours of the controller becoming aware of it….
By: Dudkowiak & Putyra
By: Dudkowiak & Putyra
