Notifications to the CNIL of personal data breaches
Description
The General Data Protection Regulation (GDPR) has made it mandatory **to notify the CNIL of any personal data breach that creates a risk to the rights and freedoms of data subjects**. A data breach is _"a breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed"_.
This notification to the CNIL must be made within 72 hours, by the body responsible for processing or by its representative.
For more information on data breaches and the CNIL’s follow-up to notifications: https://www.cnil.fr/notify-a-violation-of-personal-donations
**Disclaimer 1:** The data published are those transmitted to the CNIL as part of the notifications (excluding those received in the three months preceding the production of the datasets for reasons of confidentiality of the files being processed or recently processed). They may not reflect the Commission's assessment of the situation described.
**Warning 2:** Each notification in the dataset corresponds to a specific case, which may have led to several subsequent exchanges with the organization concerned or its representative.
Resources
| Name |
Format |
Description |
Link |
|
54 |
|
https://www.data.gouv.fr/api/1/datasets/r/df0e0dad-11f6-4569-99cd-8f6250a3c89a |
|
8 |
|
https://www.data.gouv.fr/api/1/datasets/r/4c176588-a444-4dc7-b6bf-60390ae7e5be |
Tags
- violations
- violation
- notifications
- cnil
- donnees-personnelles
- notification