Recital 87

Recital 87

General Data Protection Regulation · UE 2016/679

(87)

It should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data breach has taken place and to inform promptly the supervisory authority and the data subject. The fact that the notification was made without undue delay should be established taking into account in particular the nature and gravity of the personal data breach and its consequences and adverse effects for the data subject. Such notification may result in an intervention of the supervisory authority in accordance with its tasks and powers laid down in this Regulation.

Luxembourg specificity
CNPD - lignes directrices sur la notification des violations de données (portail cnpd.public.lu)

In Luxembourg, breach notifications are submitted via the CNPD dedicated online form (not by post or email). The CNPD has published internal guidance specifying that breaches involving banking data, health data or Luxembourg national identifiers (matricule) are presumed high-risk by default, triggering Article 34 communication to data subjects.

Luxgap practice: configure your detection tool to auto-fill the CNPD format and keep a log of both qualified and non-qualified incidents, as the CNPD systematically requests traceability of non-notification decisions.