- Article 32Security of processing
1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of…
- Article 33Notification of a personal data breach to the Commission
1. In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of…
- Article 34Communication of a personal data breach to the data subject
1. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal…
https://uk-gdpr.digiphile.law/chapter/chapter-IV-section-2.html
Text as at 17 September 2026.
This is an unofficial convenience version of the UK GDPR (Regulation (EU) 2016/679 as retained in UK law). It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.