A Controller must notify a qualifying personal-data breach to the Commissioner without undue delay and, where feasible, within 72 hours. Processors must notify Controllers without undue delay and breaches must be documented.
Interpretation and application must be checked against the official text and current version.
