Notifications to the CNIL of personal data breaches

Description

The General Data Protection Regulation (GDPR) has made it mandatory **to notify the CNIL of any personal data breach that creates a risk to the rights and freedoms of data subjects**. A data breach is _"a breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed"_. This notification to the CNIL must be made within 72 hours, by the body responsible for processing or by its representative. For more information on data breaches and the CNIL’s follow-up to notifications: https://www.cnil.fr/notify-a-violation-of-personal-donations **Disclaimer 1:** The data published are those transmitted to the CNIL as part of the notifications (excluding those received in the three months preceding the production of the datasets for reasons of confidentiality of the files being processed or recently processed). They may not reflect the Commission's assessment of the situation described. **Warning 2:** Each notification in the dataset corresponds to a specific case, which may have led to several subsequent exchanges with the organization concerned or its representative.

Resources

Name Format Description Link
54 https://www.data.gouv.fr/api/1/datasets/r/df0e0dad-11f6-4569-99cd-8f6250a3c89a
8 https://www.data.gouv.fr/api/1/datasets/r/4c176588-a444-4dc7-b6bf-60390ae7e5be

Tags

  • violations
  • violation
  • notifications
  • cnil
  • donnees-personnelles
  • notification

Topics

Categories