meta_pixel
Tapesearch Logo
Log in
Hear GDPR

Article 34

Hear GDPR

Hear GDPR

Government

51 Ratings

🗓️ 9 March 2021

⏱️ 2 minutes

🧾️ Download transcript

Summary

This episode is also available as a blog post: https://heargdpr.wordpress.com/2021/03/10/article-34/

Transcript

Click on a timestamp to play from that location

0:00.0

Article 34. Communication of a personal data breach to the data subject.

0:09.0

1. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons,

0:15.3

the controller shall communicate the personal data breach to the data subject without undue delay.

0:20.7

2. The communication to the data subject without undue delay. 2. The communication to the

0:22.8

data subject referred to in paragraph 1 of this article shall describe in clear and plain

0:27.3

language the nature of the personal data breach and contain at least the information and measures

0:31.8

referred to in points B, C, and, D, of Article 33.3.

0:44.1

3. The communication to the data subject referred to in paragraph 1 shall not be required if any of the following conditions are met. A, the controller has implemented appropriate technical and

0:49.4

organizational protection measures, and those measures were applied to the personal data

0:53.7

affected by the personal data breach, in particular those that to the personal data affected by the personal

0:54.8

data breach, in particular those that render the personal data unintelligible to any person who is

1:00.0

not authorized to access it, such as encryption. B, the controller has taken subsequent measures

1:05.9

which ensure that the high risk to the rights and freedoms of data subjects referred to in paragraph

1:10.4

one is no

1:11.1

longer likely to materialize. See, it would involve disproportionate effort. In such a case,

1:17.7

there shall instead be a public communication or similar measure whereby the data subjects are

1:21.9

informed in an equally effective manner. Four, if the controller has not already communicated the personal data breach to the data

1:29.7

subject, the supervisory authority, having considered the likelihood of the personal data breach

1:34.8

resulting in a high risk, may require it to do so or may decide that any of the conditions

1:39.4

referred to in paragraph 3 are met.

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from Hear GDPR, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of Hear GDPR and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.