The classic trap
Recital 86 sheds light on Article 34: communication to data subjects must be fast, clear and actionable, not a legal email drowned in jargon. The CNPD and CNIL regularly sanction organisations that notified the authority but forgot or delayed informing data subjects, or sent a message so vague that the person could take no concrete precaution. A frequent trap: waiting until everything is understood before communicating, while the recital requires alerting as soon as an immediate risk exists, even if details are completed later.
The practical test: does your communication let the person act?
The CNPD and EDPB (Guidelines 9/2022 on personal data breach notification) expect a communication that concretely answers four questions:
- What is the nature of the breach and which of my data are affected (identity, contact, financial, health, credentials)?
- What concrete consequences should I fear (targeted phishing, identity theft, banking fraud, doxxing)?
- What immediate measures should I take (change password, block card, watch emails, credit freeze)?
- Who do I contact for questions (DPO, dedicated hotline, breach support email)?
The recital permits a sequencing: immediate communication if damage risk is imminent (active banking credentials stolen), justifiable delay if premature communication would prevent containment (for example on instruction from law enforcement investigating the attacker). This nuance must be documented in your breach register, not improvised.
How Luxgap automates this risk
Our Luxgap Breach Communication Orchestrator turns breach communication into a controlled industrial workflow: from the moment your security team qualifies an incident as "high risk", the tool generates in under 15 minutes personalised messages to each category of data subject, in their language, with the right recommendations based on the type of data exposed. No more panic drafting at 10pm, no more generic message exposing the organisation to an Article 34 sanction.
- Automatically classifies each qualified incident via your SIEM (Sentinel, Splunk, Wazuh) using the EDPB 9/2022 grid and triggers the Article 34 workflow once the "high risk" threshold is met.
- Generates multilingual communications (FR, EN, DE, LU, PT) from legally validated templates, personalised by data category affected and subject profile.
- Syncs delivery with your CRM (Salesforce, HubSpot, Odoo) and directory (Active Directory, Workday) to target only the actually affected persons, with timestamped proof of receipt.
- Offers an AI agent that suggests concrete recommendations adapted to the scenario (stolen credentials, health data exfiltration, contact leak) based on ANSSI, ENISA and CNPD guides.
- Documents the full timeline (detection, qualification, CNPD notification, data subject communication) in a timestamped PDF report, admissible during an inspection.
- Allows justifying a deferred communication by recording the authority's instruction (law enforcement, CNPD) behind it, as explicitly permitted by Recital 86.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on a realistic incident scenario for your sector, with a free 48-hour blind audit of your current breach communication setup.